The open stack QROS is built on
QROS is engineered on proven open-source and enterprise technology — from the perimeter (WAF/IDS) to post-quantum cryptography, the automation layer, and the AI that drives the agent. No black boxes: every layer is a tool you can audit, replace, or run yourself.

HAProxy
The QROS perimeter layer: TLS termination, L7 routing and signature-based web filtering that the firewall/IPS roles configure and harden.
haproxy.com
Suricata
Deep, protocol-aware packet inspection deployed at the network edge — real-time threat detection with rules the QROS IDS roles ship and tune.
suricata.ioSnort
The classic signature-based IDS, deployed alongside Suricata for layered, defense-in-depth threat detection across the fleet.
snort.orgOpenSearch
The SOC’s searchable event store — indexed logs, alerts and security telemetry for fast detection, hunting and investigation.
opensearch.orgGrafana
Live dashboards over the IDS and SIEM telemetry — posture, alert trends and attack visualization at a glance for the blue team.
grafana.comRHEL
A hardened, vendor-supported production target for CIS/STIG audits and remediation — benchmarked and hardened by QROS playbooks.
redhat.comDebian
The baseline open-source OS QROS benchmarks and hardens (CIS L1/L2) across fleets — the workhorse of modern infrastructure.
debian.orgWindows Server
Audited over WinRM: CIS/STIG benchmarks applied to Windows Server fleets alongside Linux — one tool, the whole datacenter.
microsoft.comOpenSSL
The TLS and X.509 engine QROS inspects — and the substrate beneath our post-quantum signing. The foundation of every certificate we read.
openssl.orgoqs-provider (Open Quantum Safe)
The provider that adds NIST post-quantum algorithms — ML-KEM, ML-DSA, SLH-DSA — to OpenSSL. The core of QROS quantum readiness.
openquantumsafe.orgAnsible
The agent runs signed Ansible playbooks for audits and hardening — idempotent, reversible, check-vs-repair by design.
ansible.comReact
The QROS console and Explore UI — a fast, component-driven single-page app for internet-wide search and audit reporting.
react.devPython
The FastAPI backend: scan parsers, CVE enrichment, the on-prem Agent API and the orchestration layer tying it all together.
python.orgRust
Memory-safe native scanner binaries and performance-critical tooling in the harness — speed without the footguns.
rust-lang.org
OpenClaw
The on-prem agent runtime at the heart of the QROS AI Harness — the MCP tool surface that turns a model into a security operator.
qros.dev/ai-harnessOllama
The model server the harness is compatible with — run any model your way: locally on your own hardware, or in the cloud. Your choice.
ollama.comEvery layer above is open and auditable. See how they fit together in the AI Harness, or explore the compliance case behind QROS.
FAQ
What technology stack is QROS built on?
QROS is built on open, auditable technology: HAProxy for the WAF/IPS perimeter, Suricata and Snort for IDS, OpenSearch and Grafana for the SOC, RHEL/Debian/Windows Server as audit targets, OpenSSL with the oqs-provider for post-quantum (NIST PQC) cryptography, Ansible for automation, React/Python/Rust for the application, OpenClaw as the agent runtime, and Ollama-compatible models that run locally or in the cloud.
Is QROS locked into a specific AI model or cloud?
No. The QROS AI Harness is Ollama-compatible, so you can run any model your way — a self-hosted model on your own hardware, or a cloud LLM. Your data and infrastructure stay under your control; there is no vendor lock-in.
Start your cryptographic risk assessment with QROS
Explore now →