NOCTRODEX pitch deck — text version
Slide 1 — // P U B L I C _ P I TC H · P R E - S E E D · AU G U S T 2 0 2 6 ⚡ EDHTA · paper v3
// P U B L I C _ P I TC H · P R E - S E E D · AU G U S T 2 0 2 6 ⚡ EDHTA · paper v3
NOCTRODEX
( O P C ) P R I VAT E L I M I T E D
Two equal product stages under one company.
AI AppSec software now · sovereign on-prem hardware next
S TA G E 1 // S O F T WA R E S TA G E 2 // H A R D WA R E
AI SAST & DAST On-prem AI hardware
AppSec software assist Appliances you own or manage
Code & apps stay under customer control No per-query rent for inference
Architecture: EDHTA (paper v3) — in Stage 1 apps · designed for Stage 2 appliances
Kolkata, India · noctrodex-hq.com · Pre-revenue · Public · internals redacted
Slide 2 — One thesis, two stages
One thesis, two stages
Software wedge first · sovereign compute next — full objects always include both
01 02 03
Prove value in AppSec Own the inference path Scale the stack
AI SAST + DAST assist where Same cyber AI delivered on EDHTA architecture IP +
code and apps stay under customer premises — no token software + appliance SKUs +
customer control. rent. managed path as capital allows.
// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 2 / 28 ]
Slide 3 — Go-to-market is staged — both stages are real
Go-to-market is staged — both stages are real
Commercial sequence, not abandonment of hardware (SBI / business overview still hold)
STAGE 1 — NOW STAGE 2 — NEXT
AI AppSec software On-prem AI hardware
• AI SAST — static analysis assist on owned • Purpose-configured AI appliances
code •
• Local inference · no per-query metering
AI DAST — authorised dynamic testing assist •
• Outright sale or managed (ISP-router)
Ghostmaster AI core (in development) •
• Models co-designed to hardware envelope
Operator / analyst software surface •
• Sovereign compute for cyber + industrial
Faster pilots · software IP · lower capital
// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 3 / 28 ]
Slide 4 — Stage 1 problem — AppSec needs better AI
Stage 1 problem — AppSec needs better AI
Cloud copilots leak code · one model window cannot do everything well
The pain
• Proprietary code into public metered AI
• Scanner noise vs late, expensive vulns
• SAST misses runtime · DAST misses root
• One model config cannot max long context +
deep judgment + tools
AppSec wants AI on SAST + DAST — with ownership
of source and scope.
Why one model window isn’t enough — EDHTA splits reader vs judge.
// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 4 / 28 ]
Slide 5 — Stage 1 products — AI SAST + AI DAST
Stage 1 products — AI SAST + AI DAST
Active development / pilot path · not public GA
AI SAST AI DAST
Static Application Security Testing — AI-augmented Dynamic Application Security Testing — AI-augmented
• Ingest customer-owned source / builds • Authorised testing of running applications
• AI-assisted finding prioritisation • AI-guided triage of dynamic findings
• Analyst-friendly review workflows • Pairs with SAST for root-cause linkage
• Built for AppSec + engineering SDLC • Customer policy & scope always apply
• Keep code off public metered APIs • No unauthorised scanning — ever
// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 5 / 28 ]
Slide 6 — Stage 1 buyers
Stage 1 buyers
AppSec-first positioning (not revenue share)
10% Outcomes they want
15% 35%
• Faster SAST triage
• Authorised DAST, less noise
• Source stays controlled
20% • Later path to on-prem AI
20%
AppSec / engineering Security consultancies Product cos (SDLC)
Research / labs Industrial path→S2
// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 6 / 28 ]
Slide 7 — Stage 1 workflows
Stage 1 workflows
Abstract paths — no internal tooling inventory
SAST path
01 02 03 04 05
Ingest code Analyse Prioritise Review Track fix
DAST path (authorised scope only)
01 02 03 04 05
Define scope Exercise app Collect signals Triage AI Remediate
// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 7 / 28 ]
Slide 8 — Ghostmaster — AI core (public view) ⚡ EDHTA · paper v3
Ghostmaster — AI core (public view) ⚡ EDHTA · paper v3
Cybersecurity-oriented model line · under development · not GA
What it is Product layers
AI for research and defensive workflows on infrastructure the
customer controls. 1. Ghostmaster (model)
2. Apps & software
Powers analyst assist for AppSec — SAST and DAST triage — · Operator console
without putting sensitive code on a public token API. · SAST / DAST focus
3. EDHTA architecture
Powered by EDHTA: long-context reading + high-precision judgment (paper v3 · company IP)
on your path. 4. On-prem hardware
(Stage 2)
Status: active iteration · not public GA.
// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 8 / 28 ]
Slide 9 — EDHTA — the architecture we ship ⚡ EDHTA · paper v3
EDHTA — the architecture we ship ⚡ EDHTA · paper v3
Formal ML paper (v3) · company IP · Stage 1 active · Stage 2 designed to host
RAW TYPED
READER JUDGE ADMITTED
INPUT BRIEF
Code · apps Long context Claims + High-precision Findings
reports to structure confidence AppSec assist when gated
How AppSec work becomes a brief — not a raw dump into a single window.
Stage 1 — active Stage 2 — designed Company IP
In softwares & apps: Ghostmaster EDHTA-v3 paper · copyright
Same architecture on owned on-
path · AppSec assist · reader / package · not “patented” · not public
prem appliances — local inference.
judge / memory. GA.
Full paper under company IP / NDA package · Document ID EDHTA-v3 · public view only
// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 9 / 28 ]
Slide 10 — Stage 1 architecture — EDHTA (public) ⚡ EDHTA · paper v3
Stage 1 architecture — EDHTA (public) ⚡ EDHTA · paper v3
Shape map only · no ports · same design Stage 2 hosts on-prem
GATEWAY READER JUDGE MEMORY
Routes long Long context High-precision Admitted findings
vs short work → structured brief AppSec assist only
Same architecture Stage 1 software runs · Stage 2 appliances are designed to host it on customer-owned mind.
Long materials Sharp judgment Admitted memory
Prioritise & assist without mega- Findings enter history only when
Code, reports, large pastes → briefs
window tax gated
// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 10 / 28 ]
Slide 11 — Stage 1 competitive frame
Stage 1 competitive frame
Illustrative design intent — not a lab benchmark
AI depth
5 Position
On-prem path Code privacy
Not “replace every scanner tomorrow.”
0
AI-native AppSec software that respects
ownership of code — with a clear Stage 2
hardware upgrade path.
Scores = design intent.
Noise control S1+D link
Legacy SAST/DAST Cloud AI copilots
Noctrodex S1 target
// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 11 / 28 ]
Slide 12 — STAGE 2 // SOVEREIGN COMPUTE
STAGE 2 // SOVEREIGN COMPUTE
Own the compute
On-prem AI appliances · co-designed models · no per-query metering
Where EDHTA runs on metal you own — equal brief: problem, product, deployment, buyers,
economics
Slide 13 — Stage 2 problem — renting intelligence fails production
Stage 2 problem — renting intelligence fails production
From business overview: economics · sovereignty · fit
SaaS never transfers control 5 The missing category
DIY GPU ops burden 4
Turnkey AI appliances where the model
Weak offline / air-gap 5 and the machine are designed together,
installed on the customer’s premises, and
fully operated by the customer.
Data leaves the perimeter 5
Not raw GPUs. Not metered cloud.
Token costs scale with success 5
0 1 2 3 4 5 6
// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 13 / 28 ]
Slide 14 — Stage 2 solution — co-design model and machine ⚡ EDHTA · paper v3
Stage 2 solution — co-design model and machine ⚡ EDHTA · paper v3
Local inference · EDHTA on owned hardware · not rent per query
Hardware
Purpose-configured AI appliances — compute, storage, power, One architecture
thermals.
Model stack Stage 1 software
Domain-tuned models (incl. cyber) sized for the appliance envelope. EDHTA in apps
EDHTA architecture
Same paper as Stage 1 apps — reader / judge / memory on the mind.
Stage 2 appliance
Ops path EDHTA on owned mind
Design → assemble → install → customer operates; air-gap capable.
Same paper. Your metal.
// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 14 / 28 ]
Slide 15 — Stage 2 product surface — appliance classes
Stage 2 product surface — appliance classes
Thematic roadmap variants · not SKU quotes
Edge Mid-range High-capacity
Compact sovereign inference Facility-class appliances for
Team / lab class stacks for
for constrained sites and heavier local model + tool
AppSec + research workloads.
offline cells. loops.
// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 15 / 28 ]
Slide 16 — Stage 2 deployment — outright vs managed
Stage 2 deployment — outright vs managed
ISP-router analogy from business overview / SBI profile
No query metering
What never moves
On-prem compute
Compute stays on the customer’s
premises. Data does not leave for
Customer maintains* inference. Nothing is billed per query.
What changes: title, capex vs opex, who
maintains the metal.
Capex preference
*Managed = Noctrodex maintains.
Outright = customer or contract.
Customer title
Illustrative scores.
0 1 2 3 4 5 6
Managed deployment Outright purchase
// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 16 / 28 ]
Slide 17 — Stage 2 engagement path
Stage 2 engagement path
How an appliance programme runs
01 02 03 04 05
Discovery Co-design Build Deploy Support
Compute class, Integration &
Workload, latency, Assemble, validate, Install on premises,
memory, model maintenance — not
privacy, environment load model bundle hand over control
architecture access rent
// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 17 / 28 ]
Slide 18 — Stage 2 buyers
Stage 2 buyers
India first · industrial & institutional sovereignty (business overview §6)
Why they buy appliances
15%
25%
20% • Data residency / offline
• Predictable cost envelope
• Own the metal and models
20% • Graduate from Stage 1 software
20%
Manufacturing / OT Healthcare on-site Research & education
SME / mid-market Air-gap / critical
// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 18 / 28 ]
Slide 19 — Stage 2 economics — planning view
Stage 2 economics — planning view
BOM buckets illustrative · no supplier SKUs · re-quote before purchase
Unit economics (public)
15%
Margin from BOM + assembly + integrated
15% 45% model value — not infinite cloud COGS per
query.
Managed deployments only when fee/advance
25% covers hardware outlay (bank profile honesty).
Early company: capital discipline first.
GPU compute CPU / memory / board
Storage & network Power / chassis / other
// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 19 / 28 ]
Slide 20 — Stage 2 competitive frame
Stage 2 competitive frame
Business overview alternatives — illustrative axes
Local control
5 Differentiation
Cyber fit Cost predict.
Not a cloud API reseller.
Not a white-box GPU dump.
0 Not a pure body-shop SI.
Co-designed model + machine for
sovereign cyber and industrial AI.
Scores = design intent.
Turnkey Air-gap
Cloud AI APIs DIY GPU servers
Noctrodex S2 target
// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 20 / 28 ]
Slide 21 — Stage 2 hardware — tamper-responsive by design
Stage 2 hardware — tamper-responsive by design
Physical security engineered into the board, not bolted onto the box
SECURE ISLAND ALERT PLANE BOUNDARY
Host · accelerator · storage Cellular radio, own battery Every penetration declared
Tamper controller Signed periodic heartbeat Filtered feed-throughs
Key in battery-backed RAM Works with the host powered down SIM tray: the one serviceable
Under the mesh, inside potting Silence is the alarm exception, logs and alerts
Tamper-responsive, not tamper-proof — intrusion is detected, keys are destroyed before extraction, and the owner
is notified.
// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 21 / 28 ]
Slide 22 — The board — designed, verified, fabricating
The board — designed, verified, fabricating
4-layer carrier · 100 × 72 mm · DRC clean, zero errors, zero unconnected
Tamper mesh
0.15 mm traces at 0.35 mm pitch — a 0.5 mm drill cannot pass between them without
cutting one
Zeroise path
Key lives in battery-backed RAM inside the mesh. Tamper cuts its power: no host, no
mains, microseconds
top — MCU, radio, sensors
Controller
STM32U5 with eight hardware tamper channels; backup registers erase in VBAT mode
Alert plane
LTE-M module on an independent battery — signed heartbeat, absence triggers the alarm
// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 22 / 28 ]
Slide 23 — Made in India — and honest about the stage
Made in India — and honest about the stage
Design, verification and fabrication routed domestically wherever it is competitive
DESIGNED VERIFIED FABRICATING REVENUE
Kolkata, India DRC clean · 0 errors Prototype ordered Pre-revenue
Domestic supply chain What is real today
Indian fabricators evaluated and quoted for the prototype Real: the board is designed, the mesh is laid out, design-
run, with capability confirmed at the fine trace and rule checks pass with zero errors, and manufacturing files
spacing the tamper mesh requires. are with a fabricator.
The production path is domestic PCB fabrication plus Not yet real: assembled hardware, firmware on silicon,
domestic box-build, so the appliance a sovereignty field testing, and any customer deployment. No product is
customer buys is itself made here. generally available.
// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 23 / 28 ]
Slide 24 — Company revenue mix — staged (illustrative %)
Company revenue mix — staged (illustrative %)
Pre-revenue · not a forecast of contracted business
120
Reading the chart
100
80
60 Y1* software-led (Stage 1).
Y2–Y3* hardware sale + managed
40 rise (Stage 2).
20 Axis = illustrative mix % of revenue
composition, not rupees.
0
Y1* Y2* Y3*
SAST/DAST software Hardware sale
Managed appliances Support / training
// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 24 / 28 ]
Slide 25 — Company snapshot
Company snapshot
Public legal facts · street address omitted
6
Legal facts
5 5
5
4 4
4 NOCTRODEX (OPC) Pvt Ltd
3 Incorp: 27 Jul 2026
3 RoC: Kolkata, India
CIN: U62010WB2026OPC288993
NIC: 62010 · 62020 · 26201
2
Pre-seed · founder-funded
1 HQ: Kolkata, India
noctrodex-hq.com
0
SPICe Incorp Banking S1 apps S2 design
// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 25 / 28 ]
Slide 26 — Founder
Founder
Public site bio · education + professional background
Soumabha Majumdar
Founder & CEO · AI & Cyber Security Engineer
Dual prior career tracks: corporate software developer and infosec / security engineer.
Cyber forensics-trained AI security engineer. Professional experience spans corporate
product/engineering development and information-security engineering — including
security research, healthtech infosec, offensive research, and full-stack delivery —
before founding NOCTRODEX (OPC) PRIVATE LIMITED in 2026.
Corporate path Infosec path Education · certs
Prior corporate developer / Infosec engineer track:
engineering experience security research, healthtech MSc Digital Forensics (NFSU)
building software products infosec, authorised testing BTech · CEH · eWPTX
and full-stack systems. craft. Kolkata, India
// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 26 / 28 ]
Slide 27 — Stage honesty + roadmap themes
Stage honesty + roadmap themes
Build velocity · S1 then S2 · priority scores are illustrative (1–5)
₹0 0 Pre S1→S2
External equity Named clients Revenue GTM path
Near-term priority (1–5 illustrative)
AI SAST path 5
AI DAST path 5
AppSec pilots 5
Operator console 4
Appliance SKU (S2) 3
Managed deploy (S2) 3
// SYSTEM_STATUS: ONLINE · Public · internals redacted · Aug 2026 [ 27 / 28 ]
Slide 28 — The ask ⚡ EDHTA · paper v3
The ask ⚡ EDHTA · paper v3
Seed support to get the first tamper-responsive units into the field
Assemble Firmware Field test Pilots
First units built Tamper logic proven Red-team the mesh Indian industrial
and brought up on silicon before it ships partners
Already funded and in motion What seed support covers
Board designed and verified — design-rule checks pass with zero
Assembly and bring-up of the first units · firmware for the tamper
errors and zero unconnected nets.
and heartbeat path · independent red-team of the mesh ·
enclosure and potting · regulatory work for the cellular radio · pilot
Prototype fabrication ordered: 5 boards, 4-layer, ENIG, 0.15 mm
units placed with partners.
tamper mesh. Founder-funded.
Stage 2 owned-compute CAPEX (planning ceiling, not a quote): Mind $40k / ₹39L · Operator laptop $3.2k / ₹3.0L · System $43k / ₹42L · High
+ import $61k / ₹59L
Soumabha Majumdar · Founder & CEO · prior corporate developer + infosec engineer Watch the 120-second film
MSc Digital Forensics (NFSU) · BTech · CEH · eWPTX · soumabha@noctrodex-hq.com · noctrodex-hq.com youtu.be/FOmpgGIauLQ
Public · EDHTA paper v3 company IP · pre-revenue · planning ceilings are not firm quotes · Aug 2026