NOCTRODEX // PUBLIC_PITCH
Site PDF
Slide 1: // P U B L I C _ P I TC H · P R E - S E E D · AU G U S T 2 0 2 6 ⚡ EDHTA · paper v3. NOCTRODEX
Slide 2: One thesis, two stages. Software wedge first · sovereign compute next — full objects always include both
Slide 3: Go-to-market is staged — both stages are real. Commercial sequence, not abandonment of hardware (SBI / business overview still hold)
Slide 4: Stage 1 problem — AppSec needs better AI. Cloud copilots leak code · one model window cannot do everything well
Slide 5: Stage 1 products — AI SAST + AI DAST. Active development / pilot path · not public GA
Slide 6: Stage 1 buyers. AppSec-first positioning (not revenue share)
Slide 7: Stage 1 workflows. Abstract paths — no internal tooling inventory
Slide 8: Ghostmaster — AI core (public view) ⚡ EDHTA · paper v3. Cybersecurity-oriented model line · under development · not GA
Slide 9: EDHTA — the architecture we ship ⚡ EDHTA · paper v3. Formal ML paper (v3) · company IP · Stage 1 active · Stage 2 designed to host
Slide 10: Stage 1 architecture — EDHTA (public) ⚡ EDHTA · paper v3. Shape map only · no ports · same design Stage 2 hosts on-prem
Slide 11: Stage 1 competitive frame. Illustrative design intent — not a lab benchmark
Slide 12: STAGE 2 // SOVEREIGN COMPUTE. Own the compute
Slide 13: Stage 2 problem — renting intelligence fails production. From business overview: economics · sovereignty · fit
Slide 14: Stage 2 solution — co-design model and machine ⚡ EDHTA · paper v3. Local inference · EDHTA on owned hardware · not rent per query
Slide 15: Stage 2 product surface — appliance classes. Thematic roadmap variants · not SKU quotes
Slide 16: Stage 2 deployment — outright vs managed. ISP-router analogy from business overview / SBI profile
Slide 17: Stage 2 engagement path. How an appliance programme runs
Slide 18: Stage 2 buyers. India first · industrial & institutional sovereignty (business overview §6)
Slide 19: Stage 2 economics — planning view. BOM buckets illustrative · no supplier SKUs · re-quote before purchase
Slide 20: Stage 2 competitive frame. Business overview alternatives — illustrative axes
Slide 21: Stage 2 hardware — tamper-responsive by design. Physical security engineered into the board, not bolted onto the box
Slide 22: The board — designed, verified, fabricating. 4-layer carrier · 100 × 72 mm · DRC clean, zero errors, zero unconnected
Slide 23: Made in India — and honest about the stage. Design, verification and fabrication routed domestically wherever it is competitive
Slide 24: Company revenue mix — staged (illustrative %). Pre-revenue · not a forecast of contracted business
Slide 25: Company snapshot. Public legal facts · street address omitted
Slide 26: Founder. Public site bio · education + professional background
Slide 27: Stage honesty + roadmap themes. Build velocity · S1 then S2 · priority scores are illustrative (1–5)
Slide 28: The ask ⚡ EDHTA · paper v3. Seed support to get the first tamper-responsive units into the field

NOCTRODEX pitch deck — text version

Slide 1 — // P U B L I C _ P I TC H · P R E - S E E D · AU G U S T 2 0 2 6 ⚡ EDHTA · paper v3

// P U B L I C _ P I TC H · P R E - S E E D · AU G U S T 2 0 2 6 ⚡ EDHTA · paper v3

NOCTRODEX

( O P C ) P R I VAT E L I M I T E D

Two equal product stages under one company.

AI AppSec software now · sovereign on-prem hardware next

S TA G E 1 // S O F T WA R E S TA G E 2 // H A R D WA R E

AI SAST & DAST On-prem AI hardware

AppSec software assist Appliances you own or manage

Code & apps stay under customer control No per-query rent for inference

Architecture: EDHTA (paper v3) — in Stage 1 apps · designed for Stage 2 appliances

Kolkata, India · noctrodex-hq.com · Pre-revenue · Public · internals redacted

Slide 2 — One thesis, two stages

One thesis, two stages

Software wedge first · sovereign compute next — full objects always include both

01 02 03

Prove value in AppSec Own the inference path Scale the stack

AI SAST + DAST assist where Same cyber AI delivered on EDHTA architecture IP +

code and apps stay under customer premises — no token software + appliance SKUs +

customer control. rent. managed path as capital allows.

// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 2 / 28 ]

Slide 3 — Go-to-market is staged — both stages are real

Go-to-market is staged — both stages are real

Commercial sequence, not abandonment of hardware (SBI / business overview still hold)

STAGE 1 — NOW STAGE 2 — NEXT

AI AppSec software On-prem AI hardware

• AI SAST — static analysis assist on owned • Purpose-configured AI appliances

code •

• Local inference · no per-query metering

AI DAST — authorised dynamic testing assist •

• Outright sale or managed (ISP-router)

Ghostmaster AI core (in development) •

• Models co-designed to hardware envelope

Operator / analyst software surface •

• Sovereign compute for cyber + industrial

Faster pilots · software IP · lower capital

// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 3 / 28 ]

Slide 4 — Stage 1 problem — AppSec needs better AI

Stage 1 problem — AppSec needs better AI

Cloud copilots leak code · one model window cannot do everything well

The pain

• Proprietary code into public metered AI

• Scanner noise vs late, expensive vulns

• SAST misses runtime · DAST misses root

• One model config cannot max long context +

deep judgment + tools

AppSec wants AI on SAST + DAST — with ownership

of source and scope.

Why one model window isn’t enough — EDHTA splits reader vs judge.

// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 4 / 28 ]

Slide 5 — Stage 1 products — AI SAST + AI DAST

Stage 1 products — AI SAST + AI DAST

Active development / pilot path · not public GA

AI SAST AI DAST

Static Application Security Testing — AI-augmented Dynamic Application Security Testing — AI-augmented

• Ingest customer-owned source / builds • Authorised testing of running applications

• AI-assisted finding prioritisation • AI-guided triage of dynamic findings

• Analyst-friendly review workflows • Pairs with SAST for root-cause linkage

• Built for AppSec + engineering SDLC • Customer policy & scope always apply

• Keep code off public metered APIs • No unauthorised scanning — ever

// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 5 / 28 ]

Slide 6 — Stage 1 buyers

Stage 1 buyers

AppSec-first positioning (not revenue share)

10% Outcomes they want

15% 35%

• Faster SAST triage

• Authorised DAST, less noise

• Source stays controlled

20% • Later path to on-prem AI

20%

AppSec / engineering Security consultancies Product cos (SDLC)

Research / labs Industrial path→S2

// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 6 / 28 ]

Slide 7 — Stage 1 workflows

Stage 1 workflows

Abstract paths — no internal tooling inventory

SAST path

01 02 03 04 05

Ingest code Analyse Prioritise Review Track fix

DAST path (authorised scope only)

01 02 03 04 05

Define scope Exercise app Collect signals Triage AI Remediate

// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 7 / 28 ]

Slide 8 — Ghostmaster — AI core (public view) ⚡ EDHTA · paper v3

Ghostmaster — AI core (public view) ⚡ EDHTA · paper v3

Cybersecurity-oriented model line · under development · not GA

What it is Product layers

AI for research and defensive workflows on infrastructure the

customer controls. 1. Ghostmaster (model)

2. Apps & software

Powers analyst assist for AppSec — SAST and DAST triage — · Operator console

without putting sensitive code on a public token API. · SAST / DAST focus

3. EDHTA architecture

Powered by EDHTA: long-context reading + high-precision judgment (paper v3 · company IP)

on your path. 4. On-prem hardware

(Stage 2)

Status: active iteration · not public GA.

// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 8 / 28 ]

Slide 9 — EDHTA — the architecture we ship ⚡ EDHTA · paper v3

EDHTA — the architecture we ship ⚡ EDHTA · paper v3

Formal ML paper (v3) · company IP · Stage 1 active · Stage 2 designed to host

RAW TYPED

READER JUDGE ADMITTED

INPUT BRIEF

Code · apps Long context Claims + High-precision Findings

reports to structure confidence AppSec assist when gated

How AppSec work becomes a brief — not a raw dump into a single window.

Stage 1 — active Stage 2 — designed Company IP

In softwares & apps: Ghostmaster EDHTA-v3 paper · copyright

Same architecture on owned on-

path · AppSec assist · reader / package · not “patented” · not public

prem appliances — local inference.

judge / memory. GA.

Full paper under company IP / NDA package · Document ID EDHTA-v3 · public view only

// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 9 / 28 ]

Slide 10 — Stage 1 architecture — EDHTA (public) ⚡ EDHTA · paper v3

Stage 1 architecture — EDHTA (public) ⚡ EDHTA · paper v3

Shape map only · no ports · same design Stage 2 hosts on-prem

GATEWAY READER JUDGE MEMORY

Routes long Long context High-precision Admitted findings

vs short work → structured brief AppSec assist only

Same architecture Stage 1 software runs · Stage 2 appliances are designed to host it on customer-owned mind.

Long materials Sharp judgment Admitted memory

Prioritise & assist without mega- Findings enter history only when

Code, reports, large pastes → briefs

window tax gated

// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 10 / 28 ]

Slide 11 — Stage 1 competitive frame

Stage 1 competitive frame

Illustrative design intent — not a lab benchmark

AI depth

5 Position

On-prem path Code privacy

Not “replace every scanner tomorrow.”

0

AI-native AppSec software that respects

ownership of code — with a clear Stage 2

hardware upgrade path.

Scores = design intent.

Noise control S1+D link

Legacy SAST/DAST Cloud AI copilots

Noctrodex S1 target

// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 11 / 28 ]

Slide 12 — STAGE 2 // SOVEREIGN COMPUTE

STAGE 2 // SOVEREIGN COMPUTE

Own the compute

On-prem AI appliances · co-designed models · no per-query metering

Where EDHTA runs on metal you own — equal brief: problem, product, deployment, buyers,

economics

Slide 13 — Stage 2 problem — renting intelligence fails production

Stage 2 problem — renting intelligence fails production

From business overview: economics · sovereignty · fit

SaaS never transfers control 5 The missing category

DIY GPU ops burden 4

Turnkey AI appliances where the model

Weak offline / air-gap 5 and the machine are designed together,

installed on the customer’s premises, and

fully operated by the customer.

Data leaves the perimeter 5

Not raw GPUs. Not metered cloud.

Token costs scale with success 5

0 1 2 3 4 5 6

// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 13 / 28 ]

Slide 14 — Stage 2 solution — co-design model and machine ⚡ EDHTA · paper v3

Stage 2 solution — co-design model and machine ⚡ EDHTA · paper v3

Local inference · EDHTA on owned hardware · not rent per query

Hardware

Purpose-configured AI appliances — compute, storage, power, One architecture

thermals.

Model stack Stage 1 software

Domain-tuned models (incl. cyber) sized for the appliance envelope. EDHTA in apps

EDHTA architecture

Same paper as Stage 1 apps — reader / judge / memory on the mind.

Stage 2 appliance

Ops path EDHTA on owned mind

Design → assemble → install → customer operates; air-gap capable.

Same paper. Your metal.

// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 14 / 28 ]

Slide 15 — Stage 2 product surface — appliance classes

Stage 2 product surface — appliance classes

Thematic roadmap variants · not SKU quotes

Edge Mid-range High-capacity

Compact sovereign inference Facility-class appliances for

Team / lab class stacks for

for constrained sites and heavier local model + tool

AppSec + research workloads.

offline cells. loops.

// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 15 / 28 ]

Slide 16 — Stage 2 deployment — outright vs managed

Stage 2 deployment — outright vs managed

ISP-router analogy from business overview / SBI profile

No query metering

What never moves

On-prem compute

Compute stays on the customer’s

premises. Data does not leave for

Customer maintains* inference. Nothing is billed per query.

What changes: title, capex vs opex, who

maintains the metal.

Capex preference

*Managed = Noctrodex maintains.

Outright = customer or contract.

Customer title

Illustrative scores.

0 1 2 3 4 5 6

Managed deployment Outright purchase

// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 16 / 28 ]

Slide 17 — Stage 2 engagement path

Stage 2 engagement path

How an appliance programme runs

01 02 03 04 05

Discovery Co-design Build Deploy Support

Compute class, Integration &

Workload, latency, Assemble, validate, Install on premises,

memory, model maintenance — not

privacy, environment load model bundle hand over control

architecture access rent

// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 17 / 28 ]

Slide 18 — Stage 2 buyers

Stage 2 buyers

India first · industrial & institutional sovereignty (business overview §6)

Why they buy appliances

15%

25%

20% • Data residency / offline

• Predictable cost envelope

• Own the metal and models

20% • Graduate from Stage 1 software

20%

Manufacturing / OT Healthcare on-site Research & education

SME / mid-market Air-gap / critical

// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 18 / 28 ]

Slide 19 — Stage 2 economics — planning view

Stage 2 economics — planning view

BOM buckets illustrative · no supplier SKUs · re-quote before purchase

Unit economics (public)

15%

Margin from BOM + assembly + integrated

15% 45% model value — not infinite cloud COGS per

query.

Managed deployments only when fee/advance

25% covers hardware outlay (bank profile honesty).

Early company: capital discipline first.

GPU compute CPU / memory / board

Storage & network Power / chassis / other

// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 19 / 28 ]

Slide 20 — Stage 2 competitive frame

Stage 2 competitive frame

Business overview alternatives — illustrative axes

Local control

5 Differentiation

Cyber fit Cost predict.

Not a cloud API reseller.

Not a white-box GPU dump.

0 Not a pure body-shop SI.

Co-designed model + machine for

sovereign cyber and industrial AI.

Scores = design intent.

Turnkey Air-gap

Cloud AI APIs DIY GPU servers

Noctrodex S2 target

// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 20 / 28 ]

Slide 21 — Stage 2 hardware — tamper-responsive by design

Stage 2 hardware — tamper-responsive by design

Physical security engineered into the board, not bolted onto the box

SECURE ISLAND ALERT PLANE BOUNDARY

Host · accelerator · storage Cellular radio, own battery Every penetration declared

Tamper controller Signed periodic heartbeat Filtered feed-throughs

Key in battery-backed RAM Works with the host powered down SIM tray: the one serviceable

Under the mesh, inside potting Silence is the alarm exception, logs and alerts

Tamper-responsive, not tamper-proof — intrusion is detected, keys are destroyed before extraction, and the owner

is notified.

// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 21 / 28 ]

Slide 22 — The board — designed, verified, fabricating

The board — designed, verified, fabricating

4-layer carrier · 100 × 72 mm · DRC clean, zero errors, zero unconnected

Tamper mesh

0.15 mm traces at 0.35 mm pitch — a 0.5 mm drill cannot pass between them without

cutting one

Zeroise path

Key lives in battery-backed RAM inside the mesh. Tamper cuts its power: no host, no

mains, microseconds

top — MCU, radio, sensors

Controller

STM32U5 with eight hardware tamper channels; backup registers erase in VBAT mode

Alert plane

LTE-M module on an independent battery — signed heartbeat, absence triggers the alarm

// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 22 / 28 ]

Slide 23 — Made in India — and honest about the stage

Made in India — and honest about the stage

Design, verification and fabrication routed domestically wherever it is competitive

DESIGNED VERIFIED FABRICATING REVENUE

Kolkata, India DRC clean · 0 errors Prototype ordered Pre-revenue

Domestic supply chain What is real today

Indian fabricators evaluated and quoted for the prototype Real: the board is designed, the mesh is laid out, design-

run, with capability confirmed at the fine trace and rule checks pass with zero errors, and manufacturing files

spacing the tamper mesh requires. are with a fabricator.

The production path is domestic PCB fabrication plus Not yet real: assembled hardware, firmware on silicon,

domestic box-build, so the appliance a sovereignty field testing, and any customer deployment. No product is

customer buys is itself made here. generally available.

// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 23 / 28 ]

Slide 24 — Company revenue mix — staged (illustrative %)

Company revenue mix — staged (illustrative %)

Pre-revenue · not a forecast of contracted business

120

Reading the chart

100

80

60 Y1* software-led (Stage 1).

Y2–Y3* hardware sale + managed

40 rise (Stage 2).

20 Axis = illustrative mix % of revenue

composition, not rupees.

0

Y1* Y2* Y3*

SAST/DAST software Hardware sale

Managed appliances Support / training

// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 24 / 28 ]

Slide 25 — Company snapshot

Company snapshot

Public legal facts · street address omitted

6

Legal facts

5 5

5

4 4

4 NOCTRODEX (OPC) Pvt Ltd

3 Incorp: 27 Jul 2026

3 RoC: Kolkata, India

CIN: U62010WB2026OPC288993

NIC: 62010 · 62020 · 26201

2

Pre-seed · founder-funded

1 HQ: Kolkata, India

noctrodex-hq.com

0

SPICe Incorp Banking S1 apps S2 design

// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 25 / 28 ]

Slide 26 — Founder

Founder

Public site bio · education + professional background

Soumabha Majumdar

Founder & CEO · AI & Cyber Security Engineer

Dual prior career tracks: corporate software developer and infosec / security engineer.

Cyber forensics-trained AI security engineer. Professional experience spans corporate

product/engineering development and information-security engineering — including

security research, healthtech infosec, offensive research, and full-stack delivery —

before founding NOCTRODEX (OPC) PRIVATE LIMITED in 2026.

Corporate path Infosec path Education · certs

Prior corporate developer / Infosec engineer track:

engineering experience security research, healthtech MSc Digital Forensics (NFSU)

building software products infosec, authorised testing BTech · CEH · eWPTX

and full-stack systems. craft. Kolkata, India

// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 26 / 28 ]

Slide 27 — Stage honesty + roadmap themes

Stage honesty + roadmap themes

Build velocity · S1 then S2 · priority scores are illustrative (1–5)

₹0 0 Pre S1→S2

External equity Named clients Revenue GTM path

Near-term priority (1–5 illustrative)

AI SAST path 5

AI DAST path 5

AppSec pilots 5

Operator console 4

Appliance SKU (S2) 3

Managed deploy (S2) 3

// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 27 / 28 ]

Slide 28 — The ask ⚡ EDHTA · paper v3

The ask ⚡ EDHTA · paper v3

Seed support to get the first tamper-responsive units into the field

Assemble Firmware Field test Pilots

First units built Tamper logic proven Red-team the mesh Indian industrial

and brought up on silicon before it ships partners

Already funded and in motion What seed support covers

Board designed and verified — design-rule checks pass with zero

Assembly and bring-up of the first units · firmware for the tamper

errors and zero unconnected nets.

and heartbeat path · independent red-team of the mesh ·

enclosure and potting · regulatory work for the cellular radio · pilot

Prototype fabrication ordered: 5 boards, 4-layer, ENIG, 0.15 mm

units placed with partners.

tamper mesh. Founder-funded.

Stage 2 owned-compute CAPEX (planning ceiling, not a quote): Mind $40k / ₹39L · Operator laptop $3.2k / ₹3.0L · System $43k / ₹42L · High

+ import $61k / ₹59L

Soumabha Majumdar · Founder & CEO · prior corporate developer + infosec engineer Watch the 120-second film

MSc Digital Forensics (NFSU) · BTech · CEH · eWPTX · soumabha@noctrodex-hq.com · noctrodex-hq.com youtu.be/FOmpgGIauLQ

Public · EDHTA paper v3 company IP · pre-revenue · planning ceilings are not firm quotes · Aug 2026

// SLIDE INDEX
1. Title (Hero)
2. One Thesis, Two Stages
3. Go-to-market Sequence
4. Stage 1 Problem — Trilemma
5. Stage 1 Products — AI SAST + DAST
6. Stage 1 Buyers & Focus
7. Stage 1 Workflows
8. Ghostmaster AI Core
9. EDHTA — The Architecture We Ship
10. Stage 1 Architecture (EDHTA Map)
11. Stage 1 Competitive Frame
12. Stage 2 — Own The Compute
13. Stage 2 Problem — Renting Intelligence
14. Stage 2 Solution — Co-Design
15. Appliance Classes
16. Stage 2 Deployment Models
17. Stage 2 Engagement Path
18. Stage 2 Target Buyers
19. Stage 2 Unit Economics
20. Stage 2 Competitive Frame
21. Company Revenue Mix
22. Company Snapshot
23. Founder Background
24. Stage Honesty & Roadmap
25. The Ask & CAPEX Ceiling