Open Source

See what your
security program
actually covers.

Cyber Defense Matrix AI maps your tools and capabilities across the Cyber Defense Matrix — a proven 5×5 framework that cuts through vendor noise and shows you where you're strong, where you're exposed, and what to do about it.

5x5

Defense Matrix

25

Security Cells

5

Maturity Levels

What It Does

No buzzwords. Just clarity.

Built on Sounil Yu's Cyber Defense Matrix — a framework that maps what you have against what you need. Open source, license-free, and free for anyone to use, test, and deploy in their own environment.

Map Your Coverage

Plot your security tools and capabilities across 5 asset classes and 5 NIST functions. See at a glance what’s covered and what isn’t.

Measure What Matters

Rate each cell from 1 to 5 based on real capability — not vendor promises. Track progress as your program matures.

Find the Gaps

Stop guessing where you’re exposed. The matrix reveals blind spots that slide decks and sales pitches won’t show you.

Built for Teams

Security isn’t a solo effort. Invite your team, share assessments, and get everyone — technical or not — on the same page.

AI-Ready Data

Export structured assessment data that’s safe to share with AI tools. No credentials, no architecture details — just the signal an LLM needs to help you prioritize.

Ecosystem

How real tools map to the matrix

Every security tool covers different cells. See where the overlap is and where the gaps are — no vendor pitch required.

CrowdStrike

CrowdStrike

Endpoint SecurityEnterprise

Cloud-native endpoint protection platform that combines next-gen antivirus, endpoint detection and response, and managed threat hunting.

ID
PR
DT
RS
RC
DEV
APP
NET
DAT
USR

Covers 5 of 25 cells

Falcon PreventFalcon InsightFalcon OverWatchFalcon Discover

AI-Powered

Your AI Security Advisor

An agentic assistant that reads your projects, finds gaps, and proposes changes — you stay in control.

AI Security Advisor
OpenRouterDefault
  • Access 100+ models (Claude, GPT-4, Llama, Mixtral)
  • Single API key for all providers
  • Pay-per-token, no contracts
Anthropic SDKDirect
  • Native tool_use streaming — lowest latency
  • Direct Anthropic API — no middleman
  • Best for production deployments

Provider auto-detected at startup. Set one key and go.

Reads your assessments, tools, and gaps
Proposes maturity updates & tool mappings
Every change requires your approval
Compare across multiple projects
All data stays in your Supabase instance

The Problem

Security shouldn't require a translator.

Marketing lingo, made-up terminology, and endless vendor consolidation have made it nearly impossible to understand what a security tool actually does for your program. Brands merge, products rebrand, and capabilities get buried under layers of buzzwords.

Sounil Yu created the Cyber Defense Matrix as a way to cut through the noise — a simple 5×5 grid that maps security functions against asset classes. It started as a framework in a book. Cyber Defense Matrix AI turns that framework into a tool any security team can deploy.

This is open source software, built for security teams to run in-house, so you control the sensitive data it collects. Free to use, free to improve, built in the open.

Open Source

Self-host on your own infrastructure. Full control over your data, your deployment, and your roadmap. No vendor lock-in, ever.

Framework-Driven

Built on Sounil Yu’s Cyber Defense Matrix — a proven model used across the industry. No marketing whitepapers, just structure.

Community-Built

Free for every security team, from startups to enterprises. Contribute on GitHub and help shape what comes next.

AI-Safe by Design

Share your security posture with AI systems without exposing operational details. Structured visibility that’s safe to analyze externally.

Process

Three steps. That's it.

01

Define Your Scope

Set up a project for your organization and define what you’re assessing.

02

Assess Honestly

Walk through all 25 cells. Rate your actual maturity — not where you wish you were. Map the tools you have.

03

See the Truth

Review your coverage gaps, export reports, and prioritize what to fix based on real data.

Your security posture shouldn't be a mystery.

Deploy Cyber Defense Matrix AI for your team or try the live demo. Open source, self-hosted, no strings attached.