Built by working engineers, for working engineers. Packetman saysWelcome to the about page. I'm PacketMan — the voice of DataStun's founding team. This page tells you who built DataStun, why, and what convictions show up in every product decision. The short version: our founders spent four decades inside network problems where the gap between what the monitoring said and what was actually happening was the whole story. Pentagon communications recovery after September 11. Six CENTCOM deployments diagnosing the biometrics systems behind the Iraq surge. The founding era of packet analysis at Network General, when Sniffer was inventing the category. A training practice that certified 3,500 NetAnalysts in 27 countries. NetQoS, the network-performance company they built to a $200M acquisition by CA Technologies. Every one of those was a different angle on the same observation: traditional monitoring tells you traffic moved, it doesn't tell you what the traffic actually experienced. DataStun is what closing that gap looks like as a shipped product.

DataStun exists because its founding team spent four decades watching traditional monitoring miss the question that matters in a breach: where did the data actually go? The product is the answer.

Our founding team

Senior network-forensics practitioners with four decades in the field — Pentagon communications recovery after 9/11, six CENTCOM deployments, the founding era of packet analysis, a training practice that certified 3,500+ NetAnalysts in 27 countries, and NetQoS through its $200M acquisition by CA Technologies. We build tools the way people who’ve had to use them at 2 a.m. would build them.

The team behind DataStun

Our founders’ work is the substance behind the product. The same observation runs through every chapter of it: the network is usually the witness, and the witness is rarely asked the right question.

Four decades

The founding era of packet analysis

From the early days of network diagnostics at Network General — where Sniffer invented the category of packet analysis — our team has spent four decades doing the thing most tools only summarize: actually reading what crossed the wire instead of trusting a vendor’s dashboard.

Mission-critical

Pentagon & CENTCOM

Our founders led communications recovery at the Pentagon in the days after September 11, and ran six CENTCOM deployments across Iraq, Afghanistan, Qatar, Kuwait, Bahrain, and Djibouti — diagnostic work in environments where a wrong answer was unforgiving.

Training the field

3,500+ NetAnalysts in 27 countries

A training practice that certified 3,500+ NetAnalysts in 27 countries and served a majority of the Fortune 100. The conviction behind it — complex problems can be solved — isn’t aspirational; it’s what our founders saw after walking into hundreds of engagements where everyone else had given up.

Built & exited

NetQoS → $200M acquisition by CA Technologies

NetQoS, the network-performance company our team built to a $200M acquisition by CA Technologies, with the PhD engineers who built its TCP analysis engine. The philosophy that came out of that work — obviate the problem, don’t just react to it — is the one DataStun ships on.

Patented

Controlling how data moves

Our team holds U.S. security patents for techniques that control how data moves across a network. That work underpins one of the diagnostic add-ons DataStun offers today — denial-at-the-endpoint with no middlebox and no cloud proxy.

Now

DataStun · Security Institute

DataStun ships the measurement layer our team spent four decades realizing was missing. Security Institute is the educator brand that distills the methodology into training. Both share a single conviction: practitioners who can read what the network is actually doing make the rest of the security stack work.

Three convictions, anchored in the work

Every product decision in DataStun traces back to one of three observations our founders earned the hard way. They are not slogans — they are the rules that decide what gets built and what doesn’t.

“Your network is lying to you, and it’s not your fault.”

Forty years in rooms where vendors, departments, and teams told different stories about what went wrong — and the packets told the real one. Traditional monitoring was built to report whether traffic moved; it was never built to tell you how it moved or what it experienced. That gap isn’t an engineer’s failing. It’s a measurement problem the industry hasn’t closed. DataStun closes it.

“Complex problems can be solved.”

A hard-won principle, not a slogan — the observation our founders made after walking into hundreds of engagements where everyone had given up. The shift from two-dimensional symptom-chasing to three-dimensional deep-packet inspection with hypothesis testing turns intractable problems into diagnosable ones, consistently.

“The goal is to obviate.”

The philosophy our founders carried into DataStun: prevent problems, don’t just react to them. Every diagnosis should produce a system that fails less often afterward. The engineer who hires DataStun shouldn’t need to hire it again for the same category of problem.

Three brand layers, one mission

A practitioner-anchored security platform needs a practitioner you can hear. We separated the layers deliberately so each one stays honest to what it’s for.

The product

DataStun

The shipped platform. Endpoint network observability covering security, performance, and data sovereignty in one lightweight agent. This is what you sign up for.

All features →

The educator

Security Institute

The training and methodology arm. Distills the diagnostic discipline our founders developed over decades of field work into curriculum and structured certifications. The product teaches the platform; the institute teaches the practice.

The voice

PacketMan

The voice of DataStun’s founding team. Voices the in-product information tips (about 300 of them across the dashboard), the methodology videos, and the “how the network actually behaves” explainers. Cartoon on the outside; four decades of packet-level forensics underneath.

“Pandemics spread at the speed of an airplane. Computer viruses spread at the speed of light.”
— Peter Diamandis

That observation is why DataStun exists. A blocklist someone updated last week can’t keep pace with a threat that moves at the speed of light — so we built protection that updates around the clock and catches new dangers the moment they appear.

Why we built it

Existing tools answer the wrong question. EDR tells you a process behaved suspiciously. Firewalls tell you traffic was permitted or denied. SIEMs tell you what the other tools said. None of them answer the question that defines a breach response: where did the data actually go?

The endpoint is the only vantage point that can answer it — the place where the encrypted session is being opened, where the executable behind it lives on disk, where the bytes are being counted. The agent runs there. We chose metadata-only as a deliberate constraint: destination, program, byte counts, timing — small enough that nobody has to trust us with content, rich enough to find a Trojan beaconing out of a temporary directory to a destination half a world away.

That constraint is the product’s permanent shape. We will never inspect content. We will never auto-upload your binaries. We will never merge your fleet’s observations across customer boundaries. Those aren’t marketing positions — they are the rules that decide what is allowed into the codebase. Read the trust posture →

A managed service — that you can manage yourself. Packetman saysPacketMan again. People hear "managed service" and assume a third party has to run it. Not here. DataStun is a service you run yourself — you can be your own M. You set up a tenant, you name your own admins, and they watch every agent across your fleet. An agent is just an endpoint: a computer, a server, a workstation. Your admins see where every address you talk to leads, where every address trying to reach you comes from, which program opened each session, and which program is fanning out across your network if something gets loose. And if you'd rather a professional organization run all that for you, an MSSP can — and you can switch either direction whenever you like, without touching a single agent. Start by learning it yourself, hand it to a pro later. Or start managed and take it in-house. Same platform either way.

“Managed service” usually means a third party runs it. DataStun flips that: it is a managed service you can run yourself — you can be your own M. You stand up a tenant, name your own admins, and they manage every agent in your fleet. An agent is simply an endpoint — one of your computers, servers, or workstations.

What your admins get to see is the product of four decades of forensic work. Every IP address you reach out to, and every IP that tries to reach you, is graded for reputation through a pipeline of a dozen-plus checks. Every executable on your machines is graded too, against the world’s large corpora of known-good and known-bad software per operating system. The start of authority behind every DNS name is examined — where that name’s record actually came from — because a lookalike name that resolves to a hostile address is a favorite trick, and almost nobody checks the authority chain for you. We watch QUIC sessions (the new RFC 9000 protocol now carrying most of the modern web) the same way we watch TCP. And when a program starts fanning out and talking to many machines — the signature of malware moving laterally — we identify the exact executable that spawned it, not just the device. That last one is rare, powerful, and comes straight from breach forensics.

One quick test for anyone you trust with your network.

Ask whether they understand QUIC — the RFC 9000 protocol that now carries most internet traffic, largely unnoticed. If your admins, your MSSP, or your executives don’t know a new protocol is quietly running the internet, that is a serious gap. DataStun watches it for you, and helps your team learn it. Running the platform is educational by design — you understand your own network better the longer you use it, one clear answer at a time, with PacketMan explaining every field along the way.

Where DataStun is today

We are pre-commercial. The product runs in production for early customers; the binding documents (Privacy Policy, Terms of Service) are written and self-binding today and will be tightened to operative legal language with counsel before commercial launch.

That posture is deliberate. The honest version of “coming soon” is that we ship to early users now, the platform is real, and we say what we collect (/data-collection) and what we won’t (/trust) without legalistic hedging. If anything in the policy or this page would prevent your organization from using the product as it exists today, please tell us before you sign up — that feedback shapes the policy.

See the product our team built

Sign up free, enroll an agent, and see your fleet’s network behavior the way people who’ve spent four decades reading packets would see it.