Founding access — launching on Product Hunt · first 50 teams

The AI layer above your security stack.

Thugir reads every alert from the tools you already run, tells you what's actually critical, and hands you the exact fix — in plain English. Not another scanner. A reasoning engine.

Watch 30s demo
No credit card Your data, never sold Cancel anytime

Thugir in 30 seconds — from raw alerts to a ranked, plain-English action plan.

Maps every finding to the framework you answer to

GDPRISO 27001Cyber Essentials SOC 2HIPAANHS DSP Toolkit SRACQCPCI DSSNIS2
The real problem

You don't have a tools problem.
You have a time problem.

The real problem isn't a lack of security tools. It's too many alerts, too many dashboards, too much manual investigation — and nobody with the time to connect the dots before an attacker does.

£78k
Average loss from a single phishing email at a conveyancing firm.
340%
Rise in phishing attacks targeting NHS staff since 2023.
3 of 200
Findings in a typical scan that actually matter. Thugir tells you which three.
How Thugir thinks

Observe. Reason. Act.

A scanner runs tools and lists results. Thugir observes evidence, builds context, and reasons toward the one action that matters most.

Observe

Thugir ingests evidence from the tools you already run — endpoints, network, Microsoft 365, scanners. Every observation is traceable to its source.

Reason

It builds the attack paths a real adversary would take, separates signal from noise, and scores what matters with CVSS + EPSS + CISA KEV + your actual exposure.

Act

You get a ranked, plain-English action plan — each fix mapped to the compliance control it satisfies. No 40-page PDF. Just what to do next.

Why Thugir

Reasoning you can trust — and prove.

Evidence-backed, never hallucinated

Every finding traces to a real artifact from a real tool. Thugir never surfaces an AI guess as a confirmed fact — confidence and source are always shown.

It gets smarter every scan

Reject a false positive once and it stays gone. Scan three is sharper than scan one because Thugir learns your environment over time.

Risk scoring that reflects reality

Not a raw CVSS list. Internet exposure, asset criticality, exploit availability and blast radius fuse into one 0–100 Thugir Risk Score — with an SLA and an executive one-liner.

Real attack-path synthesis

“Three realistic paths run from this exposure to your client data. This is the choke point.” Fix one thing and two paths close. That's the conversation Thugir gives you.

› Fix CVE-2024-XXXX on the VPN gateway → 2 of 3 paths to client data close.
Built for who you are

Your regulator. Your risk. Your language.

Thugir speaks the obligations you're actually measured against — and keeps the evidence audit-ready.

Law firms

Pass the SRA. Sleep at night.

The SRA expects documented cyber policies, staff-training evidence and incident-response procedures. Most firms don't have them. We fix that — and keep you protected.

SRAGDPRCyber Essentials
Healthcare

DSPT done. Ransomware stopped.

Every GP practice and dental clinic is a DSP Toolkit obligation and a ransomware target. We handle both — and keep your CQC evidence ready before they ask.

NHS DSPTCQCGDPR
MSPs

Fewer alerts. Fewer tickets.

Your IT company keeps systems running. Thugir keeps attackers out and regulators happy — white-labelled, across every client, from one console. Different job, different expertise.

White-labelMulti-clientISO 27001
🔒 Founding member pricing — locked for life for the first 50 teams
Pricing

Less than one breach. Less than one hire.

No setup fees. Hardware optional. Cancel any time — we earn your business every month.

Essentials
Solo practice · 1 site
£299/mo
billed monthly · 2 months free annually
  • Monthly AI scan + plain-English report
  • Core frameworks (Cyber Essentials, GDPR + one of SRA/CQC/DSPT)
  • Prioritised, evidence-backed remediation
  • Email support
Professional
Growing firm · multi-site
£499/mo
billed monthly · 2 months free annually
  • Everything in Essentials, plus:
  • Continuous monitoring & all 14 frameworks
  • Attack-path synthesis & choke-point analysis
  • Audit-ready compliance evidence packs
  • Priority support & vCISO sessions
MSP Partner
Per client site
from £149/site/mo
volume pricing · healthy margin built in
  • White-label, your brand
  • Multi-customer central console
  • Bulk pricing & 35–40% margins
  • Read-only customer portals
30-day money-back Cancel anytime No setup fees Hardware optional, not required
R
“I built Thugir after watching healthcare practices and law firms get breached while having perfectly good security tools installed. The tools weren't the problem — nobody had time to interpret the alerts and connect the dots. Thugir is the AI that does that reasoning for you.”
— Founder, Thugir Labs · now onboarding our founding cohort personally
Questions

The honest answers.

Is this just another scanner?
No. A scanner runs tools and lists results. Thugir is a reasoning engine — it correlates evidence across your whole stack, builds the attack paths an adversary would actually take, and tells you the one fix that matters most. It sits above your tools, it doesn't replace them.
Do I have to rip out my existing security tools?
No. Thugir is the intelligence layer on top of what you already run. It reads from your existing endpoints, network, Microsoft 365 and scanners and makes them work harder together.
Do I need the Node One hardware?
No. Thugir is software-first. Node One is an optional on-prem sensor for customers who want deeper local network visibility — most teams never need it.
What does “early access” mean right now?
We're onboarding a founding cohort by hand. You join the list, we reach out, set you up personally, and you lock founding pricing for life. No credit card to join.
Will the AI take actions on my network on its own?
Co-pilot before autopilot. By default Thugir only detects, explains and recommends — every action needs your explicit approval. Automation is opt-in, and only after it has earned your trust over time.
Is my data safe?
Findings are evidence-backed and traceable, access is role-based, and the audit log is append-only. We never surface an AI guess as a confirmed fact, and we'll never have a client face a regulator alone.
Security & trust

Built to be trusted
with what matters.

A security product has to hold itself to a higher standard. Here's how Thugir earns that.

Evidence-backed

Every finding traces to a real artifact from a real tool. No AI guess is ever shown as a confirmed fact.

Role-based access

Granular permissions across roles, so people see exactly what they should — and nothing they shouldn't.

Append-only audit log

Every action is recorded and never altered or deleted — a defensible record for you and your regulator.

Your data stays yours

Never sold, never used to train public models. Co-pilot before autopilot — automation is always opt-in.

Founding access

Stop drowning in alerts.
Start knowing what matters.

Join the founding cohort. We'll reach out, set you up personally, and lock your pricing for life.

Or email us directly at [email protected]