Deployment that fits into how your network already works.

On-premise

Maximum control

Cloud

Instant start

On-premise

From setup to live visibility.

In 4 steps.

1

Infrastructure Provisioning

Preparing the hardware or virtual environment for NetFlow deployment according to sizing requirements.

25 min

2

System Installation

Automated installation of the FLOWCUTTER Probe and Collector engine.

120 min

3

Telemetry Redirection

Configuring your routers to export NetFlow/IPFIX data to the collector IP for your deployment.

15 min

4

Active Validation

Pilot phase. Full feature access to validate data accuracy and anomaly detection.

14 days

Sizing guide

TRAFFIC PROFILE RECOMMENDED SPECS
Non-sampled (1:1) up to 10 Gb/s 16 core CPU (32vCPU), 64GB, HDD storage
Non-sampled (1:1) up to 40 Gb/s 48 core CPU (96vCPU), 128GB, HDD storage
Sampled (1:1000) for high-volume ISP up to 200Gbps 16 core CPU (32vCPU), 64GB, HDD storage

Cloud

Faster access.

Lighter local footprint.

For teams who want rapid visibility without running the full platform locally.

1

Source Configuration

Configure your edge router to send NetFlow/IPFIX to our secure public endpoint.

25 min

2

Access & Analysis

Receive instant access to your hosted Grafana dashboard and start monitoring.

14 days

1

Source Configuration

Configure your edge router to send NetFlow/IPFIX to our secure public endpoint.

25 min

2

Access & Analysis

Receive instant access to your hosted Grafana dashboard and start monitoring.

14 days

Installation

Step-by-step

Without our team alongside.

HW Preparation

  • You prepare the hardware or virtual machine according to the requirements we provide.
  • Once ready, you grant temporary access to the system for our engineers.

System Installation

  • The entire installation is handled remotely by our team.
  • No local action is required from your side.

NetFlow Redirection

  • Your routers are configured to export NetFlow/IPFIX data to the FLOWCUTTER collector IP.
  • We guide you through this step if needed.

Trial & Validation

  • You enter a 30-day full-feature trial, with no traffic or functionality limits, allowing you to validate performance and insights in your real network.

Common questions

Answers before you start.

Where is our data processed? Does it leave our network?

No. FLOWCUTTER is designed as an on-premises or private-cloud solution:

  • Network telemetry never leaves your infrastructure
  • No external “call-home” traffic for NetFlow, DNS, or BGP data
  • Full control over data retention, access, and ownership
Does have Cloud deployment any limits?

Connectivity: Requires a Public IP on your router or a NAT setup.

Security: We support VPN Tunneling (IPsec/WireGuard) for encrypted telemetry transport (Optional but recommended).

Throughput: For full 800 Gb/s analysis without public internet bottlenecks, please choose On-Premise.

Is FLOWCUTTER a SIEM?

No — by design.

  • FLOWCUTTER complements SIEM platforms, it does not replace them
  • It provides network-level context that SIEMs usually lack
  • Data can be exported or correlated with SIEMs (Zabbix, Elastic, Sentinel, etc.)
How much traffic can FLOWCUTTER handle?

FLOWCUTTER is built for scale:

  • Tens to hundreds of Gbps of NetFlow/IPFIX
  • Horizontal scaling using collectors and probes
  • Designed for peak traffic, not just averages

FLOWCUTTER is deployed in ISP, IXP, and large enterprise networks with very high flow volumes.

Which devices and vendors are supported?

FLOWCUTTER relies on open standards, not vendor lock-in:

  • Routers and switches (Cisco, Juniper, MikroTik, Nokia, Huawei, etc.)
  • Firewalls
  • DNS resolvers
  • BGP sessions

If a device speaks NetFlow, IPFIX, BGP, or DNS, FlowCutter can work with it.

Do we need to change our network architecture?

No.

  • FLOWCUTTER is fully passive
  • No inline components
  • No impact on forwarding or routing
  • Zero risk of traffic disruption
What does FLOWCUTTER detect?

FLOWCUTTER focuses on network behaviour, not just signatures:

  • DDoS and volumetric attacks
  • DNS floods and amplification patterns
  • Lateral movement inside the network
  • Suspicious outbound traffic and reputation risks
  • Long-term issues (degradation, misrouting, abnormal growth patterns)
Is detection automatic?

Yes — FLOWCUTTER combines:

  • Statistical models
  • Behavioural baselines
  • Correlation of NetFlow, DNS, and BGP data
Does CLOUD deployment have any restrictions?

Cloud deployment includes the following considerations:

  • Vulnerability Scan is not enabled by default
  • Secure NetFlow/IPFIX transmission is optional and requires a VPN tunnel
Why isn’t BGP and SNMP monitoring enough on its own?

BGP tells you how the network is designed.

SNMP tells you how busy it is.

Flow data tells you what is actually happening inside it.

  • BGP shows routing intent and policy - how traffic should flow
  • SNMP shows interface utilization and device health - how much traffic flows
  • Flow (NetFlow/IPFIX) shows real communication patterns - who talks to whom, when, how much, and for how long

FLOWCUTTER correlates BGP, SNMP, and flow data to expose:

  • hidden traffic patterns
  • abnormal behavior invisible to utilization graphs
  • root causes behind congestion, attacks, and service degradation

Without flow visibility, you only see the structure and load of the network - not its actual behavior.

How does this compare to IDS/IPS?

They work best together:

  • IDS/IPS analyzes packets
  • FlowCutter analyzes network-wide behavior over time
  • FlowCutter answers where, since when, and with what impact
Can we run a Proof of Concept?

Yes.

  • Full-featured PoC in a real production environment
  • Clearly defined technical goals
  • No vendor lock-in after PoC completion
How does licensing work?

Transparent and predictable pricing

Based on volume of the traffic

No hidden fees

Designed for long-term cost stability

See FLOWCUTTER in your own network.

30 days. Your infrastructure. Your real traffic.