Meet Franklin
Franklin lives on your router, learns how every device behind it normally behaves, and stops threats before they spread.
Network is healthy
auto-refresh 10s
Healthy Sequences
0
Malicious Sequences
0
Network Topology
Office Gateway
Riverside HQzarouter_DEMO01HQ
Connected Devices
workstation-09
192.168.1.109
612 ok
file-server-01
192.168.1.20
1840 ok
workstation-12
192.168.1.112
488 ok
reception-ipad
192.168.1.31
1204 ok
conf-room-tv
192.168.1.40
932 ok
hr-laptop-03
192.168.1.55
776 ok
Live preview of Franklin · anonymized sample network
What Franklin does
Franklin analyzes the traffic of every device behind your router in real time, catching malicious activity and odd communications before damage occurs.
Franklin scores traffic on the router itself. No cloud round-trips, no slowdown, and your traffic never has to leave the building.
Franklin learns what normal looks like for each device and flags what strays from it, so novel malware is caught by its behavior, not a signature list.
How Franklin works
Franklin installs on your router and starts working immediately. Minimal footprint, zero configuration.
Franklin learns how each device on your network normally behaves and builds its own baseline — no rules to write, no signatures to update.
Franklin scores activity in real time on the router, identifying anomalies that signature-based tools never see.
Threats are contained automatically. Franklin alerts you with the reason, not a flood of raw logs.
Use cases
Ship Franklin on subscriber routers to detect botnets, DDoS staging, and compromised devices before they affect your infrastructure. Aggregate behavioral telemetry across millions of endpoints.
News
ZeroAnomaly is a featured startup at Web Summit Lisbon, 9–12 November 2026. Come meet the team, see Franklin, and tell us about your network.
Research
calBERT: Securing Routers Serving IoT Networks using Contrastive Augmented Learning
J. Carter, S. Mancoridis, P. Protopapas, B. Mitchell, B. Lilley
contrastBERT: Behavioral Anomaly Detection for Malware using Contrastive Learning
J. Carter, S. Mancoridis, P. Protopapas, B. Mitchell
sysBERT: Improved Behavioral Malware Detection using BERT Trained on sys2vec Embeddings
J. Carter, S. Mancoridis, P. Protopapas
Malware Detection in Cloud Native Environments
B. Mitchell, A. Chandnani, J. Carter, D. Roumelioti, S. Mancoridis
Behavioral Malware Detection using Language Model Classifier Trained on sys2vec Embeddings
J. Carter, S. Mancoridis, P. Protopapas, E. Galinkin
Team

John Carter, PhD
Co-Founder
Research in behavioral malware detection and contrastive learning at Drexel University.
john@zeroanomaly.com
Brian Mitchell, PhD
Co-Founder
Technology leader and cybersecurity researcher with over 30 years of industry and academic experience.
brian@zeroanomaly.com
Spiros Mancoridis, PhD
Co-Founder
Auerbach Berger Endowed Chair in Cybersecurity and Distinguished Professor of CS at Drexel University.
spiros@zeroanomaly.com
Pavlos Protopapas, PhD
Co-Founder
Scientific Program Director at the Institute for Applied Computational Science, Harvard University.
pavlos@zeroanomaly.comContact
Tell us about your environment — we'll show you what Franklin finds.