Cyber Black Box Tamper-evident event recorder

Every event recorded.
Every change exposed.

Cyber Black Box sits alongside your servers, network and machines and keeps a sealed record of what happens on them. If anyone edits or deletes a record, it shows. If an unapproved device tries to read the logs, it is refused.

SealedTamper-evident records
ApprovedDevices only
On-siteRuns next to your systems
The platform

A flight recorder for your IT and operations.

After an incident, the first question is always "what happened?" Cyber Black Box makes sure the answer is still there, and that you can trust it.

Continuous recording

Collects event logs from the servers, network equipment and machines you connect to it.

always on

Sealed records

Each record is sealed as it is written, so a later edit, deletion or gap can't go unnoticed.

tamper-evident

Instant alerts

Signs of tampering are flagged the moment they appear, not weeks later during a review.

flag → alert

Approved access only

Only devices and people you have approved can read or export records. Everything else is refused.

unknown → refused
How it works

Record, seal, watch, retrieve.

Four things happen to every event that reaches the box, so the record you pull out later is the record that went in.

STEP 01

Record

Events from your connected systems arrive and are written to the box.

STEP 02

Seal

Each record is sealed on arrival so it can be checked for changes later.

STEP 03

Watch

The box keeps checking its own records and raises an alert if anything doesn't match.

STEP 04

Retrieve

When you need the records, an approved reader exports them and every export is logged.

Access control

It only talks to devices you trust.

Plugging something into a Cyber Black Box doesn't get you the logs. The box checks every device that connects and only answers the ones you have approved.

  • Approved readers can export records
  • Unknown devices and hosts are refused
  • Every connection attempt is itself recorded
ILLUSTRATIVE
approved readerregistered device · eth0 ALLOWED
unknown USB drivenot approved · port 2 REFUSED
unrecognized adapternot approved · port 3 REFUSED
unregistered hostnot approved · eth1 REFUSED
Use cases

Where a trustworthy record matters.

Cyber Black Box is built for companies that need to prove what happened on their systems, not just believe it.

Incident investigation

Reconstruct the timeline of a breach or outage from records an attacker couldn't quietly erase.

Audit & compliance

Hand auditors a log history with built-in proof that nobody has altered it.

Insider risk

Even administrators can't rewrite history without leaving a trace.

Remote & unattended sites

Keep a reliable record at locations where nobody is watching the equipment day to day.

Need something different? Voltroen also designs custom security hardware and software when a standard box isn't the right fit.

Custom builds
Cyber Black Box

When something goes wrong, the black box remembers.

Talk to us about where your systems run and what you need on record. We'll help you plan a Cyber Black Box deployment that fits.