Live demo  Arrow | Source code | Documentation | Contact | Blog
tirreno - Open Security Analytics Platform Use cases How it works Pricing About
Arrow Download
The Lac d'Émosson, Valais, Switzerland.





How the tirreno
platform works

From a simple input to multi-dimensional security analytics





01.
Data
ingestion


02.
Data
enrichment


03.
Risk-based
analysis


04.
Review & 
autoblocking

tirreno receives real-time user event data from your applications through API calls.

 

User context and proprietary API enrich data, transforming it into actionable intelligence.

 

The rule engine processes data to identify positive signals, red flags, and regularities to re-evaluate user risk score.

 

Flagged accounts sent for manual review. Accounts with the lowest scores may be automatically suspended to prevent further access to your app.

‐ User ID
‐ Event type
‐ Time stamp
‐ User agent
‐ IP address
‐ Requested URI
 
‐ User activity metrics
‐ Behavioural data
‐ Device model
‐ Operating system
‐ IP geolocation
‐ VPN/Datacenter detection
‐ ASN information
 
ⓘ Account takeover
ⓘ Brute-force attack
ⓘ Non-human identities abuse
ⓘ Compromised accounts
ⓘ Account sharing
ⓘ Insider threats
ⓘ Dormant accounts
ⓘ Content abuse
↳ Manual review
↳ Blacklist

tirreno is an open security
analytics that makes it easy to
understand, monitor, and protect
your product from cyber threats,
account takeovers, and abuse.

—  Platform

—  Use cases

—  How it works

—  Pricing

—  About

—  Download

—  Live demo

—  GitHub

—  Dockerhub

—  Documentation

—  Blog

General team@tirreno.com
Support ping@tirreno.com
Security atdt@tirreno.com

Terms & conditions
Privacy policy
Imprint | Contact

Rue Galilée 7
1400 Yverdon-les-Bains
Switzerland Switzerland

©2025, tirreno




Open security analytics