We deploy, commission and operate
Cybersecurity powered by open source and on-premise AI
Security built on an open-source stack (Wazuh, OPNsense, Keycloak, SonarQube) and running on your organization's own infrastructure. With a focus on automated vulnerability management and static code analysis (SAST) that catches flaws at the development stage — your data stays within the borders of Türkiye.
How does C3T implement cybersecurity for organizations?
C3T treats cybersecurity not as a product sale but as an engineering job that is deployed and operated. Instead of expensive commercial licences, it commissions a security architecture built on a mature open-source stack (Wazuh, ELK, OPNsense/pfSense, Keycloak, Teleport, SonarQube, TheHive, GoPhish) and running on the organization's own infrastructure; on request, it is configured fully offline (air-gapped). It delivers across eight areas: penetration testing and vulnerability management, SOC/SIEM/XDR, incident response, network and server security, identity and access management, data and email security, training and compliance consulting. Log correlation and anomaly detection are strengthened with AI running inside the organization; your data stays within the borders of Türkiye and every action is auditable. C3T does not stop at reporting the vulnerabilities it finds — it fixes the code, applies the patch and keeps operating the stack. Getting started is risk-free: a free security feasibility study and a prioritised roadmap. This approach is in line with KVKK (Turkish Personal Data Protection Law), the Information and Communication Security Guide (BİGR) and the domestic sourcing principles of Law No. 7545.
Eight cybersecurity service areas
Every area runs on open source and on-premise. Visit the relevant page for details.
Penetration Testing & Vulnerability Management
We identify, report and patch the vulnerabilities in your web, mobile and network assets — we do not just find them, we close them.
Explore penetration testingSOC: SIEM / XDR / Threat Hunting
Open-source SIEM/XDR with Wazuh and ELK; log correlation and continuous threat hunting powered by on-premise AI. No expensive licences.
Explore SOC/SIEMIncident Response & Ransomware
Emergency response the moment a cyberattack or ransomware hits; we bring your systems back with minimal damage and in the shortest possible time.
Explore incident responseNetwork & Server Security
Smart firewall based on OPNsense/pfSense, end-to-end encrypted VPN and Linux/Windows server hardening; with Law No. 5651 log compliance.
Explore network securityIdentity & Access Management (IAM/PAM)
Single sign-on (SSO) and multi-factor authentication (MFA) with Keycloak, privileged access management (PAM) and session recording with Teleport.
Explore identity managementData & Email Security
Data loss prevention (DLP) with content filtering and AI-based data classification, email threat protection with local NLP.
Explore data securityTraining & Phishing Simulation
Organization-specific phishing simulation with GoPhish, security awareness training for staff and secure coding training for your software team.
Explore trainingKVKK · ISO 27001 · BİGR Compliance
We implement KVKK Art. 12, ISO 27001 and BİGR (Turkey's Information and Communication Security Guide) compliance with open-source tools, on-premise; migration support to open source (AKKY) for the public sector.
Explore compliance consultingWhy open source and on-premise AI?
For public institutions, healthcare, energy and finance, no security benefit is worth letting data leave the organization. A mature open-source stack delivers enterprise-grade security without expensive licences or vendor lock-in. On-premise deployment protects data sovereignty and KVKK compliance from day one; log correlation and anomaly detection are strengthened with on-premise AI running inside your organization — millions of records are filtered without ever leaving.
Cost and independence: a mature open-source stack instead of expensive commercial licences; enterprise-grade security without vendor lock-in.
Data sovereignty stays with you: analysis runs on your own infrastructure and your data remains within the borders of Türkiye — designed for KVKK and BİGR from day one.
On-premise AI: we strengthen log correlation and anomaly detection with a model running inside your organization; millions of records are filtered without ever leaving.
Public sector or private sector?
The same open-source foundation, configured around two different priorities.
Public sector
The priority is data sovereignty and regulatory compliance. We meet the obligations of the Information and Communication Security Guide (BİGR), Law No. 7545 and institutional SOME (CSIRT) requirements on an open-source budget, aligned with the public sector's open-source policy (Circular No. 2023/13).
- BİGR alignment + gap analysis + roadmap
- Law No. 7545-aligned architecture with 100% data localisation
- Institutional SOME (CSIRT) setup and operation
- Open-source (AKKY) migration analysis report for the public sector
Private sector
The priority is fitting enterprise-grade security into an SME budget. We do not write a consultant's report and leave; we deploy, commission and operate while taking on the responsibility. SOC/SIEM, identity management and incident response are the areas that deliver value fastest.
- SOC with open-source SIEM/XDR (Wazuh + ELK)
- IAM, PAM, SSO and MFA with Keycloak/Teleport
- Ransomware and incident response support
- Deploys + operates + takes on the responsibility
How we work
We deploy, commission and operate — we do not write a report and walk away.
Feasibility
We start with a free security feasibility study: asset inventory, risk and compliance gap analysis, and a prioritised roadmap. No commitment.
Deployment
We deploy the open-source stack on your own infrastructure and integrate it with your existing systems. Every tool and where each piece of data is processed is clearly documented.
Operation
We do not deploy and walk away: monitoring, updates and incident response are operated under an SLA. Continuous monitoring and autonomous threat hunting stay active.
Regulation and compliance
A transparent and honest stance: we clearly state what we offer and in which status.
100% Data Localisation
The entire architecture stays within the borders of Türkiye; hosted on-premise or in a domestic cloud. Security analysis never moves your organization's data abroad.
Law No. 7545-Aligned Architecture
Infrastructure designed around the domestic sourcing and data localisation principles of Law No. 7545 (Cybersecurity Law). We are ready for rapid compliance once the authorisation framework is finalised.
Open Source in the Public Sector (2023/13)
Presidential Circular No. 2023/13 prioritises open-source use in the public sector. We are at your side for analysing and implementing the move from commercial licences to open source.
TSE Certification Process
We have formally started the process of becoming a TSE Class C Certified Penetration Testing Company for our penetration testing service; a TSE-registered specialist within our team is leading the process.
KVKK & BİGR Technical Measures
Implementation, not a consultant's report: we deploy and operate the technical measures of KVKK Art. 12 and the controls of the Information and Communication Security Guide (BİGR) with open-source tools.
Open Source + On-Premise AI
Mature open-source tools such as Wazuh, ELK, Teleport and Keycloak; strengthened with AI running inside your organization for log correlation and anomaly detection.
On-premise or external cloud?
A comparison of on-premise and external cloud/SaaS from an enterprise security perspective.
| Criterion | On-premise — C3T | External cloud / SaaS |
|---|---|---|
| Data location | In-house, 100% Türkiye | Usually abroad |
| KVKK / data sovereignty | Full control | Transfer risk |
| Licence cost | Open source, no licence | Subscription / per user |
| Customisation | Full | Limited |
| Vendor lock-in | None | Yes |
Frequently asked questions
What exactly does C3T do in cybersecurity?
C3T is not a reseller of products; it is an engineering team that deploys and operates security. We bring mature open-source tools (Wazuh, ELK, OPNsense, Keycloak, Teleport, SonarQube, TheHive, GoPhish) to life on your own infrastructure, with your data never leaving the borders of Türkiye; we do not stop at reporting the vulnerabilities we find — we close them and keep operating the stack under an SLA.
Why open source instead of commercial licences?
Three reasons: cost, independence and transparency. A mature open-source stack delivers enterprise-grade security without expensive licence fees; you are not locked into a vendor, and we clearly document every tool we use. This approach is also in line with the public sector's open-source policy (Circular No. 2023/13).
Does our data leave the organization?
No. Solutions run on your own infrastructure (on-premise) or in a domestic cloud; on request, they are configured fully offline (air-gapped). Log, security and system data stay within your organization and within the borders of Türkiye, and are never transferred to third parties or abroad. This secures KVKK compliance and data sovereignty from day one.
Are you ready for Law No. 7545 and BİGR compliance?
We design an architecture aligned with the domestic sourcing and data localisation principles introduced by Law No. 7545 (Cybersecurity Law); we are ready for rapid compliance once the Authorised Provider framework is finalised. As for the Information and Communication Security Guide (BİGR) and the technical measures of KVKK Art. 12, we deploy and operate them as the implementing partner, not as a consultant.
Do you hold a TSE certificate for penetration testing?
We have formally started the process of becoming a TSE Class C Certified Penetration Testing Company for our penetration testing service, and a TSE-registered specialist within our team is leading the process. Until it is complete, our honest position is clear: we are in the certification process. In the meantime, we continue to deliver technical value in the vulnerability management and secure code analysis (SAST) niche.
Why should I trust you if you have no references?
We build trust through transparency: we clearly document which tools we use, where we process your data and which compliance obligations (KVKK Art. 12, BİGR, ISO 27001) we meet. We do not promise you "flawless protection"; we deliver security that is measurable, auditable and transferable. Getting started is risk-free: we proceed with a free feasibility study and a prioritised roadmap.
Let's build your organization's security on-premise and with open source.
Let's start with a free security feasibility study: we map your risk and compliance gaps and give you a prioritised roadmap. No strings attached.