About Kyklosec

We started Kyklosec in 2022 after spending a year watching retailers discover the same thing too late.

Our founders were on an incident response team. The pattern repeated: a mid-sized retailer, a payment page, a script that had been quietly modified. Every time, the store had done the things it was told to do. It had a scanner. It had a vendor review process. It had a checklist signed off by someone.

What it did not have was any idea what was running on its own checkout at four in the afternoon on a Tuesday.

The name

Kyklos is Greek for cycle. We picked it because the argument we keep having is about frequency. Every security tool in this space will tell you it monitors your site. Almost all of them mean they crawl it on a schedule — nightly if you pay well, weekly if you do not. A schedule is a window, and a window is a thing you can wait out.

We check in the session. That is the whole product, and the name is a reminder not to quietly become a scanner.

How we work

We are 24 people in Denver. Most of us have been on the receiving end of an incident call, which shapes what we build more than any roadmap process does. We do not ship severity scores. We do not send an alert that says "anomalous activity detected". If we wake you up, the message tells you which script, whose it is, and what it started doing.

We also try to be honest about what we are not. We are not a WAF. We are not a bot-management platform. We do not scan your repositories. There are good companies doing each of those and we would rather be one clear thing than a suite of blurred ones.

What we believe

That the supply chain in front of the customer matters as much as the one behind the build, and gets a fraction of the attention. That a control you cannot evidence is a control you do not have. And that most security tooling is designed to reassure a buyer rather than to inform an operator, which is why so much of it is quiet on the day it matters.