RuSIEM
RuSIEM is a Russian SIEM software vendor providing real-time security event monitoring, ML-based threat analytics, and regulatory-compliant solutions to government agencies, financial institutions, and critical infrastructure operators across Russia and CIS markets.
- Company typePrivate
- Founded2014
- HeadquartersMoscow, Russia
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What RuSIEM does
RuSIEM is a Russian developer of Security Information and Event Management (SIEM) software, headquartered at the Skolkovo Innovation Center in Moscow, that delivers real-time collection, correlation, and analysis of security and IT infrastructure events for government agencies, financial institutions, critical infrastructure operators, and other regulated enterprises primarily in Russia and the CIS. The platform is built on a microservices architecture that combines Elasticsearch for raw event storage, PostgreSQL and ClickHouse for incidents and event data, and a proprietary in-house message bus called RuSIEM MQ; the codebase has accumulated over 10 years of continuous development since 2014 and includes more than 650 built-in correlation rules out of the box. The product portfolio comprises a core commercial RuSIEM SIEM, an Analytics module that applies ML and Deep Learning to behavioral anomaly detection, an IoC threat intelligence module that ingests indicators from 260+ open sources, a WAF for web application protection launched in 2025, an IT infrastructure monitoring module, a managed SOC offering, and a free RvSIEM Log Management tier that serves as a product-led growth entry point.
The company monetizes through perpetual and subscription licenses priced by EPS (events per second) or RPS (requests per second) tiers, recurring technical support contracts, and partner-delivered implementation services; pricing is custom and project-based rather than list-published. RuSIEM's go-to-market is channel-led, relying on a network of more than 630 partners globally, four major distributors (Axoft, Mont, OCS, and TenIT), and major system integrators such as Croc, Softline, and Lanit, supplemented by direct enterprise sales for large government accounts. Strategic differentiators include FSTEC Russia certification (Certificate No. 4969 for SIEM, valid through 2030, and No. 5061 for WAF, valid through 2031), inclusion in the Russian Software Registry, integration with GosSOPKA and FinCERT, and compatibility with domestic operating system and security platforms such as Astra Linux and Dallas Lock. The company's first international subsidiary, BelSIEM in Belarus, was opened in June 2025, marking the formal start of cross-border corporate expansion.
RuSIEM firmographics
Firmographics- Name
- RuSIEM
- Legal name
- Общество с ограниченной ответственностью «РуСИЕМ»
- Website
- https://rusiem.com
- Company type
- Private
- Founded year
- 2014
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- RuSIEM is a Russian SIEM software vendor providing real-time security event monitoring, ML-based threat analytics, and regulatory-compliant solutions to government agencies, financial institutions, and critical infrastructure operators across Russia and CIS markets.
- Ownership category
- akta.pro rank
RuSIEM industry classification
Industry- Product category
- Security Information and Event Management (SIEM) Software
- NAICS
- Software Publishers (5132), Security Systems Services (except Locksmiths) (561621)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- SIEM Platforms & Log Management (HDADAGAA)
- akta.pro secondary industries
- Managed Detection & Response (MDR) & SOC Services (HDADAGAG), Unified Threat Management (UTM) Appliances (HDAFAFAB), Security Operations Center (SOC) as a Service (BPAEADAB), IT Risk Management (ITRM) (HDADAIAD)
Keywords
Where RuSIEM is headquartered
LocationHeadquarters
- HQ city
- Moscow
- HQ country
- Russia
- HQ region
- Europe
Offices2 records
Markets served
RuSIEM business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Commercial Software Licenses: RuSIEM generates revenue primarily from commercial software licenses for its SIEM system and additional modules. The company offers perpetual (бессрочные) licenses and subscription-based support. Pricing is based on EPS (events per second) volume for commercial products and RPS for WAF. The Analytics module licenses from 500 EPS and above without limits on number of sources.
- Technical Support and Updates: Technical support and software updates are provided under certificates with defined support periods (e.g., RuSIEM SIEM support until 2030, RuSIEM WAF support until 2031). Support is available via email, documentation portal, and community channels.
- Free Product Entry Point (RvSIEM Free): RvSIEM Free serves as a free entry-level product for log management, enabling evaluation, training, and small deployments. This drives awareness and potential conversion to commercial products for larger deployments.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | RuSIEM Analytics licensing from 500 EPS |
| One time/ perpetual license | Multi-year contract | RuSIEM WAF perpetual licenses with RPS tiers |
| Freemium | Pay-as-you-go | RvSIEM Free - free log management solution |
Go-to-market motion3 records
Distribution channels5 records
Marketing channels6 records
RuSIEM product offering
Product offeringCore offering
RuSIEM develops and sells a Russian Security Information and Event Management (SIEM) platform for real-time collection, normalization, correlation, and analysis of information security and IT infrastructure events. The commercial offering centers on the core RuSIEM SIEM system and is extended by modular add-ons — RuSIEM Analytics (ML/DL-based behavioral anomaly detection), RuSIEM IoC (indicator-of-compromise matching against 260+ feeds), RuSIEM WAF (web application firewall), and RuSIEM Monitoring — plus a free log-management tier (RvSIEM Free) and a deployable SOC service, all built for Russian regulatory compliance including FSTEC certification and GosSOPKA integration.
Product overview
RuSIEM is a Russian company offering a modular platform for security information and event management (SIEM) with real-time data analysis. The product portfolio consists of the core RuSIEM SIEM system complemented by add-on modules: RuSIEM Analytics (ML/DL-based behavioral analysis and anomaly detection), RuSIEM IoC (Indicators of Compromise threat detection), RuSIEM WAF (web application firewall), RuSIEM Monitoring (IT infrastructure monitoring), and SOC on RuSIEM (managed security operations center). The free tier is covered by RvSIEM Free, a limited Log Management version. All products are designed for Russian regulatory compliance including FSTEC certification and GovSOPKA integration.
Differentiator
Problem solved
Functional benefit
Brands
- RuSIEM: Commercial SIEM system for real-time analysis of information security and IT infrastructure events, combining analytics, visualization, and incident management
- RuSIEM Analytics
- RuSIEM IoC
- RuSIEM WAF
- RvSIEM Free
- RuSIEM Monitoring
- SOC on RuSIEM
Products and services
- RuSIEM (Core SIEM) Commercial SIEM system for real-time analysis and correlation of information security and IT infrastructure events, combining advanced analytics, visualization, automatic response, and flexible incident management with over 650 built-in correlation rules; sold on perpetual or subscription licenses priced by EPS volume to government, financial, and enterprise customers in Russia and the CIS.
- RuSIEM Analytics ML and Deep Learning module for the commercial RuSIEM platform that detects threats and behavioral anomalies, tracks user/entity behavior, manages assets, identifies vulnerabilities, and supports security-standards compliance through automatic baseline rules; licensed separately from 500 EPS without limits on the number of data sources.
- RuSIEM IoC Indicators-of-Compromise module that detects attempts by corporate devices to connect to malicious infrastructure before attacks escalate, loading threat intelligence from 260+ sources (including FinCERT) and processing up to 250,000 indicators daily with mathematical priority ranking; licensed as a separate add-on to commercial RuSIEM deployments.
- RuSIEM WAF Intelligent Web Application Firewall that protects against SQL injection, XSS, and other web-layer attacks with real-time traffic analysis, cascading rule logic, containerized deployment (Docker, Kubernetes), domestic-platform support (Astra Linux), and performance scaling from 1 to 100,000 RPS; sold under perpetual licenses with optional custom rule development.
- RvSIEM Free Freely distributed log management solution for collecting, normalizing, reporting, searching, visualizing and long-term storing of information security events; provides a subset of the commercial RuSIEM capabilities for evaluation, training, and use in small companies or pilot projects before upgrading to commercial RuSIEM.
- RuSIEM Monitoring IT-infrastructure monitoring module that tracks the status of nodes, applications and business-critical servers, identifies violations tied to status changes, and includes a remote-administration console with built-in HelpDesk for handling IT operations incidents alongside security events.
- SOC on RuSIEM Managed Security Operations Center service built on the RuSIEM platform, combining event collection, analysis and correlation for centralized monitoring and incident response; offered in internal, commercial, and hybrid deployment models for organizations that need turnkey 24/7 SOC capabilities powered by RuSIEM.
Quantifiable outcome
- Processes >100 million events per second in commercial projects
- +4 more outcomes
Companies that use RuSIEM
Customer profileNamed customers5 records
Segments5 records
Ideal customer profiles5 records
RuSIEM technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration4 records
AI capability5 records
Feature8 records
RuSIEM partnerships and signals
Strategic signalPartnerships
19 partnerships are on record, tiered regional, core, major and minor.
- ООО БелСИЕМ (BelSIEM)regionalBelSIEM was opened in Minsk, Belarus in June 2025 as a regional partnership initiative to expand RuSIEM presence in the Belarusian market.
- Astra LinuxcoreCompatibility with Astra Linux Special Edition confirmed in July 2022, supporting deployment in Russian operating system environments.
- FinCERT (Bank of Russia)coreRuSIEM integrated with FinCERT (Financial Computer Emergency Response Team of Bank of Russia) in February 2021 for financial sector threat intelligence sharing.
- R-VisioncoreFull integration with R-Vision completed in December 2020, enabling interoperability between RuSIEM SIEM and R-Vision security products.
- AxoftmajorMajor distributor of RuSIEM products across Russian and CIS markets.
- MontmajorMajor distributor of RuSIEM products across Russian and CIS markets.
- OCS DistributionmajorMajor distributor of RuSIEM products across Russian and CIS markets.
- TenITmajorMajor distributor of RuSIEM products across Russian and CIS markets.
- CrocmajorSystem integrator partner providing implementation and consulting services for RuSIEM deployments.
- SoftlinemajorSystem integrator partner providing implementation and consulting services for RuSIEM deployments.
- LanitmajorSystem integrator partner providing implementation and consulting services for RuSIEM deployments.
- Jet (jet.su)minorSystem integrator partner providing RuSIEM implementation services.
- Megafon (Business Division)minorTelecom and integration partner providing RuSIEM implementation and services.
- Er-TelecomminorIntegration partner providing RuSIEM implementation services.
- Step (step.ru)minorIntegration partner providing RuSIEM implementation services.
- IrsenminorIntegration partner providing RuSIEM implementation services in Belarus.
- ConfidentminorSecurity integration partner providing RuSIEM implementation services.
- IT-VBCminorIntegration partner providing RuSIEM implementation services.
- Oceit StoreminorIntegration partner providing RuSIEM implementation services.
Scale indicators10 records
Recent moves7 records
Expansion highlights6 records
RuSIEM competitors and assessment
Company assessmentBroad incumbents
- IBM QRadar: IBM QRadar is an enterprise SIEM incumbent whose Russian tier-1 clients are being forced to evaluate Russian alternatives like RuSIEM as Western vendors exit the market.
- Splunk (Cisco): Splunk is the global SIEM category leader; RuSIEM directly competes where Splunk is displaced from Russian regulated workloads under import-substitution mandates.
- Microsoft Sentinel: Microsoft Sentinel is a cloud-native SIEM in the Microsoft Security stack; it competes with RuSIEM for any cross-border or multinational Microsoft-aligned environments that RuSIEM can still serve in Russia.
- Elastic Security: Elastic Security provides SIEM capabilities on the Elastic stack — the same Elasticsearch core used inside RuSIEM — making it a comparable alternative for globally-oriented buyers considering RuSIEM.
Direct peers
- Kaspersky KUMA: Kaspersky Unified Monitoring and Analysis Platform is a Russian-developed SIEM from Kaspersky, directly competing with RuSIEM across the same regulatory, government, and enterprise customer base in Russia and CIS.
- Positive Technologies (MaxPatrol SIEM / PT SIEM): Positive Technologies offers a Russian SIEM (PT SIEM / MaxPatrol SIEM) targeting the same Russian banks, state corporations, and critical infrastructure customers, with a deeper installed base in many large enterprises.
- R-Vision: R-Vision is a Russian security vendor offering SIEM and incident response platforms; RuSIEM already integrates with R-Vision, confirming overlap on product, customer, and ecosystem in the Russian enterprise market.
- Security Vision: Security Vision is a Russian SIEM/SOAR vendor competing for the same FSTEC-certified, GosSOPKA-integrated deployments in Russian banks, government, and critical infrastructure.
Emerging players
- InfoWatch: InfoWatch is a Russian information-security vendor with adjacent SIEM and event-monitoring capabilities that overlaps with RuSIEM in regulated Russian enterprise accounts.
- SearchInform: SearchInform provides Russian-built information-security and monitoring solutions that partially overlap with RuSIEM's event-monitoring use cases in Russian enterprise buyers.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
RuSIEM social profiles
Digital presenceRuSIEM compliance and trust
Trust signalCompliance4 records
RuSIEM financial estimates
Financial estimateRevenue estimate
Valuation estimate
RuSIEM leadership team
Management profileNumber of profiles
RuSIEM subsidiaries and ownership
Company hierarchySubsidiaries1 record
RuSIEM funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
RuSIEM M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about RuSIEM
What does RuSIEM do?
RuSIEM develops and sells a Russian Security Information and Event Management (SIEM) platform for real-time collection, normalization, correlation, and analysis of information security and IT infrastructure events. The commercial offering centers on the core RuSIEM SIEM system and is extended by modular add-ons — RuSIEM Analytics (ML/DL-based behavioral anomaly detection), RuSIEM IoC (indicator-of-compromise matching against 260+ feeds), RuSIEM WAF (web application firewall), and RuSIEM Monitoring — plus a free log-management tier (RvSIEM Free) and a deployable SOC service, all built for Russian regulatory compliance including FSTEC certification and GosSOPKA integration.
Is RuSIEM a public or private company?
RuSIEM is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was RuSIEM founded?
RuSIEM was founded in 2014. It employs 11 to 50 people.
Where is RuSIEM based?
RuSIEM is headquartered in Moscow, Russia, in the Europe region.
How does RuSIEM make money?
Three revenue lines are on record. Commercial Software Licenses are the primary driver. The others are technical Support and Updates and free Product Entry Point (RvSIEM Free).
Who are RuSIEM's main competitors?
Broad incumbents on record are IBM QRadar, Splunk (Cisco), Microsoft Sentinel and Elastic Security. Direct peers are Kaspersky KUMA, Positive Technologies (MaxPatrol SIEM / PT SIEM), R-Vision and Security Vision. Emerging players are InfoWatch and SearchInform.
Does RuSIEM have an API?
Yes. RuSIEM provides REST API integration capabilities for connecting data sources, agents, and managing nodes remotely. The system supports Syslog, REST API, and other protocols for integrating network devices, operating systems, applications, and services. Over 400 data sources are supported out of the box. API updates were noted in January 2018 enabling remote management of all nodes from a single interface.
What industry is RuSIEM in?
RuSIEM's product category is Security Information and Event Management (SIEM) Software. Its primary akta.pro industry code is HDADAGAA, SIEM Platforms & Log Management, with a secondary code of HDADAGAG, Managed Detection & Response (MDR) & SOC Services. Its NAICS code is 5132 and its SIC code is 7372.