tirreno
Security that belongs in your product, not just around it·tirreno.com
tirreno is a self-hosted, open source security framework that embeds threat, fraud, and abuse detection directly inside a product rather than around its infrastructure. It ingests real-time user event data via SDKs/API, builds behavioural context, applies a rule engine for risk scoring, and routes flagged accounts to manual review or automatic suspension. It includes a built-in dashboard, single-user activity view, field audit trails, and blacklist management.
What it's for
Features 18
- API access
- Audit logging
- Blacklist management and Blacklist API
- Built-in security dashboard
- Custom rules
- Email notifications
- Feed events to SIEM
- Field audit trail
- IP enrichment / IP geolocation and VPN/Datacenter detection
- No-code rule engine for risk scoring
- RBAC (role-based access control)
- Real-time event tracking via SDKs and API
- Review queue with automatic account suspension
- SAML single sign-on (option)
- Single user behavioural view
- Trust scoring
- Web-hooks
- Zero cookies tracking
At a glance
Integrations
Complianceself-reported
Resources
Pricing
Community Edition is free and open source (AGPLv3). Internal Edition pricing is quote-based ('Contact us'). Platform Edition starts 'From €3,985/mo' (EUR, not converted). Implementation service packages and the IP intelligence enrichment pack are separately priced add-ons in EUR. Subscriptions are managed and billed via Paddle; major credit cards accepted, with invoice payment available for Enterprise plans.
Open-source, self-managed edition; on-premises or air-gapped deployment
Unlimited monthly events; self-hosted; AGPLv3 license
Priced via 'Contact us'; for internal application security
Unlimited monthly events; commercial license
Starting price 'From €3,985/mo' for client-facing platforms (SaaS, FinTech, GenAI, marketplaces, public sector, digital platforms)
Unlimited monthly events; commercial license