About KIROSEC

Security investigations should not require surrendering your evidence.

KIROSEC is an offline-first security log analyzer that transforms raw evidence into traceable findings and actionable reports — inside your own environment.

324
Detection rules
182
MITRE ATT&CK techniques
0
Forced telemetry

Air-gap capable · On-device analysis · Customer-controlled evidence

Our story

Built from two sides of the same investigation.

Lewis approached security analysis as a software engineer: how do you reliably ingest, normalize, and connect large volumes of evidence?

Joseph — known as Notche — approached it as a cybersecurity practitioner: how do security tools operate, what evidence do they generate, and what does an analyst need to understand what happened?

Their combined experience revealed a recurring problem. Many security-analysis platforms assume continuous connectivity and permission to send evidence to the cloud. That model works for many organizations — but not for every investigation.

Affected systems may need to be isolated. Logs may contain sensitive operational information. Internal policies, client agreements, or data-residency requirements may also restrict where evidence can be processed.

We built KIROSEC for those situations: serious security log analysis that continues to work when cloud processing is unavailable, restricted, or simply not preferred.

Our mission

To help security teams turn complex log evidence into clear, defensible findings without forcing that evidence outside their environment.

Our vision

A future where capable security analysis remains available to every investigator, regardless of connectivity, infrastructure, or data-location constraints.

Principles

What we stand for

The four commitments every product decision is measured against.

Offline-first

Core investigation capabilities remain available without a continuous internet connection.

Evidence-linked

Findings should remain traceable to the events, entities, rules, and techniques that produced them.

Analyst-centered

Security tooling should help investigators reach an answer — not create another collection of unexplained alerts.

Customer-controlled

Organizations should decide where their security evidence is stored, processed, and reviewed.

The founding team

Software engineering meets cybersecurity operations.

KIROSEC is built by two founders combining product engineering with practical knowledge of cybersecurity tools and investigation workflows.

LV

Lewis John Villamor

Co-founder and Chief Technology Officer

Lewis John Villamor is a Certified Computer Engineer, technical leader, and full-stack developer with experience in enterprise applications, cloud infrastructure, software architecture, and data-intensive systems.

At KIROSEC, Lewis leads the product's architecture, offline processing engine, desktop application, infrastructure, and engineering direction. He focuses on turning complex security requirements into dependable and usable software.

View Lewis on LinkedIn
JN

Joseph Elginne Noche

Co-founder and Cybersecurity Lead

Joseph Elginne Noche, known as Notche, is a cybersecurity practitioner with experience in security tools, operations, and log-driven investigation. He works with ES|QL, KQL, and LQL to examine security data and identify suspicious activity.

At KIROSEC, Joseph leads the product's cybersecurity direction, including supported log sources, detection requirements, threat behaviors, investigation workflows, and MITRE ATT&CK alignment.

View Joseph on LinkedIn
Founded in the Philippines

A focused team building for a global security problem.

KIROSEC was founded in the Philippines by two Adamson University alumni. Lewis is based in Metro Manila, while Joseph is based in Calabarzon.

Today, KIROSEC remains a two-person, founder-led team. Lewis leads engineering and product development, while Joseph leads cybersecurity and detection direction.

As adoption grows, we plan to expand carefully across security research, detection engineering, software development, customer success, and MSP partnerships.

We are not currently advertising formal positions, but we welcome introductions from people who believe in offline-first security analysis.

Currently in closed beta

Bring us an investigation your current tools struggle with.

We are working with a limited group of incident responders, internal security teams, consultants, and MSPs before wider availability. Tell us about your log sources, investigation workflow, or deployment constraints, and we will show you how KIROSEC is being built to address them.

Or talk directly with the founders — support@kirosec.com