DataStun exists because its founding team spent four decades watching traditional monitoring miss the question that matters in a breach: where did the data actually go? The product is the answer.
Senior network-forensics practitioners with four decades in the field — Pentagon communications recovery after 9/11, six CENTCOM deployments, the founding era of packet analysis, a training practice that certified 3,500+ NetAnalysts in 27 countries, and NetQoS through its $200M acquisition by CA Technologies. We build tools the way people who’ve had to use them at 2 a.m. would build them.
Our founders’ work is the substance behind the product. The same observation runs through every chapter of it: the network is usually the witness, and the witness is rarely asked the right question.
From the early days of network diagnostics at Network General — where Sniffer invented the category of packet analysis — our team has spent four decades doing the thing most tools only summarize: actually reading what crossed the wire instead of trusting a vendor’s dashboard.
Our founders led communications recovery at the Pentagon in the days after September 11, and ran six CENTCOM deployments across Iraq, Afghanistan, Qatar, Kuwait, Bahrain, and Djibouti — diagnostic work in environments where a wrong answer was unforgiving.
A training practice that certified 3,500+ NetAnalysts in 27 countries and served a majority of the Fortune 100. The conviction behind it — complex problems can be solved — isn’t aspirational; it’s what our founders saw after walking into hundreds of engagements where everyone else had given up.
NetQoS, the network-performance company our team built to a $200M acquisition by CA Technologies, with the PhD engineers who built its TCP analysis engine. The philosophy that came out of that work — obviate the problem, don’t just react to it — is the one DataStun ships on.
Our team holds U.S. security patents for techniques that control how data moves across a network. That work underpins one of the diagnostic add-ons DataStun offers today — denial-at-the-endpoint with no middlebox and no cloud proxy.
DataStun ships the measurement layer our team spent four decades realizing was missing. Security Institute is the educator brand that distills the methodology into training. Both share a single conviction: practitioners who can read what the network is actually doing make the rest of the security stack work.
Every product decision in DataStun traces back to one of three observations our founders earned the hard way. They are not slogans — they are the rules that decide what gets built and what doesn’t.
Forty years in rooms where vendors, departments, and teams told different stories about what went wrong — and the packets told the real one. Traditional monitoring was built to report whether traffic moved; it was never built to tell you how it moved or what it experienced. That gap isn’t an engineer’s failing. It’s a measurement problem the industry hasn’t closed. DataStun closes it.
A hard-won principle, not a slogan — the observation our founders made after walking into hundreds of engagements where everyone had given up. The shift from two-dimensional symptom-chasing to three-dimensional deep-packet inspection with hypothesis testing turns intractable problems into diagnosable ones, consistently.
The philosophy our founders carried into DataStun: prevent problems, don’t just react to them. Every diagnosis should produce a system that fails less often afterward. The engineer who hires DataStun shouldn’t need to hire it again for the same category of problem.
A practitioner-anchored security platform needs a practitioner you can hear. We separated the layers deliberately so each one stays honest to what it’s for.
The shipped platform. Endpoint network observability covering security, performance, and data sovereignty in one lightweight agent. This is what you sign up for.
The training and methodology arm. Distills the diagnostic discipline our founders developed over decades of field work into curriculum and structured certifications. The product teaches the platform; the institute teaches the practice.
The voice of DataStun’s founding team. Voices the in-product information tips (about 300 of them across the dashboard), the methodology videos, and the “how the network actually behaves” explainers. Cartoon on the outside; four decades of packet-level forensics underneath.
“Pandemics spread at the speed of an airplane. Computer viruses spread at the speed of light.”
That observation is why DataStun exists. A blocklist someone updated last week can’t keep pace with a threat that moves at the speed of light — so we built protection that updates around the clock and catches new dangers the moment they appear.
Existing tools answer the wrong question. EDR tells you a process behaved suspiciously. Firewalls tell you traffic was permitted or denied. SIEMs tell you what the other tools said. None of them answer the question that defines a breach response: where did the data actually go?
The endpoint is the only vantage point that can answer it — the place where the encrypted session is being opened, where the executable behind it lives on disk, where the bytes are being counted. The agent runs there. We chose metadata-only as a deliberate constraint: destination, program, byte counts, timing — small enough that nobody has to trust us with content, rich enough to find a Trojan beaconing out of a temporary directory to a destination half a world away.
That constraint is the product’s permanent shape. We will never inspect content. We will never auto-upload your binaries. We will never merge your fleet’s observations across customer boundaries. Those aren’t marketing positions — they are the rules that decide what is allowed into the codebase. Read the trust posture →
“Managed service” usually means a third party runs it. DataStun flips that: it is a managed service you can run yourself — you can be your own M. You stand up a tenant, name your own admins, and they manage every agent in your fleet. An agent is simply an endpoint — one of your computers, servers, or workstations.
What your admins get to see is the product of four decades of forensic work. Every IP address you reach out to, and every IP that tries to reach you, is graded for reputation through a pipeline of a dozen-plus checks. Every executable on your machines is graded too, against the world’s large corpora of known-good and known-bad software per operating system. The start of authority behind every DNS name is examined — where that name’s record actually came from — because a lookalike name that resolves to a hostile address is a favorite trick, and almost nobody checks the authority chain for you. We watch QUIC sessions (the new RFC 9000 protocol now carrying most of the modern web) the same way we watch TCP. And when a program starts fanning out and talking to many machines — the signature of malware moving laterally — we identify the exact executable that spawned it, not just the device. That last one is rare, powerful, and comes straight from breach forensics.
Ask whether they understand QUIC — the RFC 9000 protocol that now carries most internet traffic, largely unnoticed. If your admins, your MSSP, or your executives don’t know a new protocol is quietly running the internet, that is a serious gap. DataStun watches it for you, and helps your team learn it. Running the platform is educational by design — you understand your own network better the longer you use it, one clear answer at a time, with PacketMan explaining every field along the way.
We are pre-commercial. The product runs in production for early customers; the binding documents (Privacy Policy, Terms of Service) are written and self-binding today and will be tightened to operative legal language with counsel before commercial launch.
That posture is deliberate. The honest version of “coming soon” is that we ship to early users now, the platform is real, and we say what we collect (/data-collection) and what we won’t (/trust) without legalistic hedging. If anything in the policy or this page would prevent your organization from using the product as it exists today, please tell us before you sign up — that feedback shapes the policy.
Sign up free, enroll an agent, and see your fleet’s network behavior the way people who’ve spent four decades reading packets would see it.