The ecosystem
Xavani is our open-source AI agent gateway. It is the core of the ecosystem. Four open-source projects and all 23 Security Cloud products connect to it as one system. You discover once. The system remembers everything. You secure it all. An agent runs the work.
Select a project. Four open-source projects orbit one sun. Free and local, open-core into the Security Cloud.

Xavani is the agent gateway for the ecosystem. Every other project connects to it.
Xavani runs all 23 products as agent skills from one CLI. It scans, triages, reports, and responds.
Nyarhi stores your knowledge in a local-first graph. Every agent and module reads durable, private, cited knowledge of your systems.
Gavaza provides POPIA compliance checklists, PAIA manuals, and breach registers. You can show this evidence to a tender committee.
Mhangani audits your web properties against OWASP-aligned checks. It verifies headers, TLS, cookies, and CORS. It gives a posture score and clear remediation.
Every product shares one asset graph and one posture score. A Xavani agent operates every product. The four suites use the same open foundation.
Pentest delivery, finding library & client portal.
Continuous attack-surface management.
Firewall & network-config auditor with CIS benchmarks.
AI/LLM application security scanner (OWASP LLM Top-10).
Segmentation & zero-trust design and scoring.
Cyber range & vulnerable-lab-as-a-service.
AI-assisted code security (SAST/SCA) with fix diffs.
SME managed detection & response (MDR/SIEM).
AI log search & anomaly analysis.
Asset inventory with live CVE correlation.
Patch posture & priority advisories.
AI security copilot across your whole posture.
Cloud security posture management for AWS, Azure and GCP.
Guided POPIA compliance with AI policy generation.
Multi-framework GRC across ISO, PCI, SOC 2, NIST.
Incident management and breach-notification preparation.
Third-party & vendor risk with outside-in checks.
Email security & DMARC. The free lead-magnet check.
Continuous external-exposure & POPIA-readiness scoring.
SA-localised phishing simulation & human-risk training.
Dark-web & breach monitoring for leaked credentials.
Gamified, localised security-awareness LMS.
AI-matched government tender monitoring & bid intel.
The open-source products are free and local. The Security Cloud products are hosted and multi-tenant.