Platform

EDR & MDR · Detect & respond

Axyom deploys Bitdefender GravityZone on your machines and operates the managed response service. The available status and detections land in the same portal where your external surface, your leaked credentials, your compliance and your insurance policy already live.

The domain scan is free; the endpoint layer is activated afterwards.

What it is

Managed detection and response on your machines.

Axyom deploys the Bitdefender GravityZone agent on your laptops and servers and coordinates the managed response service. The integration brings the available status of each machine into the portal, converted into findings and framework references. The scope of action is agreed when the service is activated.

You bought licenses for the whole staff and someone deployed them back in the day. Since then nobody opens the vendor's console, because opening it every morning is in nobody's job description at your company. Meanwhile a new laptop comes in without an agent, a user turns off the firewall to make the machine faster and one machine has gone three weeks without reporting.

The EDR raises an incident at three in the morning, writes its analysis and leaves it in the inbox until someone turns on the laptop. When your customer sends the security questionnaire or your insurance policy is up for renewal, the question is what percentage of your machines is really covered, and today the honest answer is that you do not know.

20

managed devices included in Pro

6

endpoint controls in the catalog

What it is
The layer that looks inside your machines: the Bitdefender GravityZone engine deployed by Axyom and a managed response service with its scope defined at activation.
Who it is for
Companies of 10 to 250 employees with nobody who opens a security console every morning. They have licenses deployed and nobody watching what the console has been warning about for weeks.
Where it's included
MDR 24/7 in the Pro and Max plans, up to 20 managed devices. Above that figure, each additional managed device is €13 per month and each mobile device €3 per month.
What we need
To deploy the GravityZone agent on your laptops and servers, removing the previous protection product, and to agree in writing what the operations center may do without asking for confirmation.
Cadence
Device protection and the portal sync are separate processes. Check the latest information received and the follow-up conditions of the activated service.

What it watches

The signals that come out of your fleet.

Six controls come out of the fleet of laptops and servers; mobile and the XDR sensors are contracted separately.

Machines without an agent
Machines the console discovers on the network and does not manage. Each one is attack surface with no telemetry.
Disabled modules
Nine protection modules per machine, each with its own severity when one is turned off.
Outdated agent or signatures
Old signatures, old product and both updates disabled. An agent without current signatures is blind to what is recent.
Machines not reporting
After seven days without a signal. It may be off, retired or silenced by an attacker.
Active threat
Confirmed malware or an unremediated detection, with the evidence of whether the machine is still infected or only detected.
Open incidents
Detection name, machine, scope, whether the main action was to block, actual date and a link to open it.
The team's mobile devices
Android, iOS and Chromebook: malware, on-device antiphishing, malicious domain filtering and jailbreak or encryption status.
XDR sensors
Identity, network and productivity applications, so the same incident reads as a whole even when it crosses domains.
Fleet coverage
How many machines there are, how many are managed and how many meet the five machine controls, with a date.

EPP prevents known threats on each machine and EDR correlates what gets through that prevention; XDR extends the correlation with identity, network and productivity sensors. MDR is the service that operates all of that on your behalf 24 hours a day, and it comes with the Pro plan.

Who provides what

The engine, the service and the Axyom layer.

Axyom does not build a detection engine of its own, and each of the three pieces of this module comes from a different place.

Engine

Bitdefender GravityZone

The same prevention, EDR and XDR sensor stack Bitdefender sells to its enterprise customers: Exploit Defense, Fileless Attack Defense, HyperDetect, Sandbox Analyzer, Network Attack Defense and Ransomware Mitigation, plus continuous telemetry and automatic correlation across machines.

Service

Managed response by Axyom

Axyom operates the MDR service on Bitdefender GravityZone according to the agreed scope. At activation, the machines, the authorizations and the response procedure are specified.

Cross-check

What Axyom adds

The information from the machines is brought together with the findings from the external surface, the exposed credentials and the compliance evidence. The shared file lets you review these signals together and coordinate the necessary actions.

The scope is agreed in writing

What is isolated automatically, what is blocked and what waits for someone on your team to confirm is written down before starting, and that agreement is reviewed with you rather than inherited from a default configuration. Pro's MDR covers 20 managed devices; above that, each additional device is €13 per month with the same 24-hour service, and each mobile device €3 per month.

What you receive

Three things you can show a third party.

01

Coverage with a number

How many machines there are, how many are managed and how many meet the five machine controls. It is the answer to your customer's questionnaire and to the insurer's question, with a date.

02

The task with an owner

Every problem comes out with an owner and instructions on two levels: what it means for the business and what to do in the console, step by step, with its estimated effort. It goes into the same remediation plan as the scanner's findings.

03

Evidence per framework

Every closed control carries its ISO 27001, NIS2, ENS and NIST CSF reference into the compliance file, without documenting it by hand again. The history keeps the date of each sweep.

Sample fleet view · Sample data

Header
5 machines with findings · 1 active threat · last sync in the example 2 h ago
Priority
DESK-HR-09 · open detection that requires review
Next
LAP-SAL-14 · firewall off and outdated signatures
Next
SRV-FILE-02 · 21 days without reporting
Discovered
2 machines identified without an agent installed
Coverage
Machine status according to the latest information received

Where it fits in the platform

Fleet telemetry, cross-checked with the rest.

An endpoint vendor's console says what is happening to a machine, and Axyom's file adds where the circulating credential came from, which ISO 27001 control fails when a module is turned off and how much insurability moves when fleet coverage drops. The six derived controls arrive with their ISO 27001, NIS2, ENS and NIST CSF reference written down.

Limits

What this endpoint layer does not do.

Check the scope before turning on the module and coordinate with your team the actions that fall to them.

The managed service runs on Bitdefender

The integration described is Bitdefender GravityZone. If you use another product, we review compatibility and scope with you before activating.

One protection agent per machine

When deploying, the previous one has to be removed. Two protection products living together get in each other's way and generate false positives.

The read-only integration takes no action

It reads the inventory, each machine's detail and the incident queue. Containment actions are part of the managed service, with the scope agreed in writing.

It does not install the agent on a new machine

It detects discovered machines without an agent and opens the task. Deployment is done by your team or your IT provider.

Sized for up to 2,000 machines

Each sweep goes through a fleet of up to 2,000 machines. Above that figure it is worth talking about a custom scope.

Pro's MDR covers 20 devices

Above that, each additional managed device is €13 per month. The identity, network and productivity XDR sensors are activated separately.

The six controls are about machines

Mobile protection is contracted and managed separately, with its own signals. It does not count toward the coverage of the fleet of laptops and servers.

Service activation

The plan includes the right to the service. Onboarding, agent installation and scope definition have to be completed.

Plans

The endpoint layer comes with Pro.

Pro and Max include MDR 24/7 for up to 20 managed devices, with the scope and the onboarding agreed. Each additional managed device costs €13/month. Mobile protection is contracted separately.

Free

To see your real risk before deciding anything.

€0

No cost · No card.

Everything to get looking:

  • Continuous scan External surface, 24/7
  • Posture and risk map Real-time CyberScore
  • Leaked credentials Counted, no detail
Start free

Base

For companies that want the whole platform without a security team of their own.

€190 / month

Self-serve · No commitment.

Everything in Free, plus:

  • Integrations Microsoft 365, Google Workspace and cloud
  • AI risk Apps with permissions over your data
  • Prioritized backlog Monthly remediation
  • 1 domain Continuously scanned
Get Base

Pro

For teams that need every sensor active and an expert behind it.

€990 / month

Advisor on escalation · No commitment.

Everything in Base, plus:

  • Security advisor On escalation, with SLA
  • Threat Intelligence Exposed credentials, under watch
  • Recurring pentesting Authenticated, report reviewed by Axyom
  • MDR 24/7 Up to 20 managed devices
  • Up to 5 domains All continuously scanned
Get Pro

Max

For high exposure or compliance demands.

€1,990 / month

Dedicated advisor · No commitment.

Everything in Pro, plus:

  • Dedicated security advisor A fixed person, monthly session
  • Priority response Incidents
  • Compliance by framework Downloadable evidence and attestation
  • Audit support Customer questionnaires and due diligence
Contact sales

FAQs.

What is the difference between antivirus, EDR, XDR and MDR?

Antivirus prevents known threats on each machine. EDR adds telemetry and correlation to hunt what gets through prevention, and it needs someone to watch it. XDR takes that correlation beyond the machine, with identity, network and productivity sensors. MDR is the service that operates all of that on your behalf 24 hours a day.

Why is the engine from Bitdefender?

GravityZone provides the protection and detection layer for the devices. Axyom coordinates its deployment, operates the activated MDR service and brings the available fleet information together with the rest of the security file.

Do I have to change antivirus?

For the service described, GravityZone is deployed. Compatibility, removal of the previous product and installation are planned during activation. If you want to keep another solution, we first review the scope we can offer.

Which actions does the operations center take without asking me?

Containment actions are agreed when the service starts and are written down: what is isolated automatically, what is blocked and what waits for someone on your team to confirm. That agreement is reviewed with you and is not imposed by default.

Do you cover the team's mobile devices?

Yes, with specific protection for Android, iOS and Chromebook: malware, on-device antiphishing, malicious domain filtering, network security and visibility of jailbreak, missing encryption and out-of-date devices. It is contracted per device at €3 per month, with no minimum, and it goes separately from the desktop agent because they are different licenses.

Choose how to start.

On your own

Analyze your domain and start with your security posture. Then connect your systems and turn on the capabilities you need.

With our team

Tell us what you need to protect and which requirements you have. We will review the scope and the right plan with you.

Start now.