Live demo  Arrow | Source code | Documentation | Contact | Blog
tirreno - Open Source Security Analytics Platform Use cases How it works Pricing About
Arrow Get tirreno
The Lac d'Émosson, Valais, Switzerland.





How tirreno
platform works

From a simple input to multi-dimensional security analytics





01.
Data
ingestion


02.
Data
enrichment


03.
Risk-based
analysis


04.
Review & 
autoblocking

tirreno receives real-time user event data from your applications through API calls.

 

User context and proprietary API enrich data, transforming it into actionable intelligence.

 

The rule engine processes data to identify positive signals, red flags, and regularities to re-evaluate user risk score.

 

Flagged accounts sent for manual review. Accounts with the lowest scores may be automatically suspended to prevent further access to your app.

‐ User ID
‐ Event type
‐ Time stamp
‐ User agent
‐ IP address
‐ Requested URI
 
‐ User activity metrics
‐ Behavioural data
‐ Device model
‐ Operating system
‐ IP geolocation*
‐ VPN/Datacenter detection*
‐ ASN information*
 
ⓘ Account takeover
ⓘ Brute-force attack
ⓘ Non-human identities abuse
ⓘ Compromised accounts
ⓘ Account sharing
ⓘ Insider threats
ⓘ Dormant accounts
ⓘ Content abuse
↳ Manual review
↳ Blacklist
* optional

tirreno is an open source
security analytics that makes
it easy to understand, monitor, and
protect your digital platform.

—  Platform

—  Use cases

—  How it works

—  Pricing

—  About

—  Download

—  Live demo

—  GitHub

—  Dockerhub

—  Documentation

—  Blog

General team@tirreno.com
Support ping@tirreno.com
Security atdt@tirreno.com

Terms & conditions
Privacy policy
Imprint | Contact

Rte des Flumeaux 48
unlimitrust campus
CH-1008 Prilly
Switzerland Switzerland

©2025, tirreno




Open-source security analytics