Meet Franklin

The lightweight AI protecting your router

Franklin lives on your router, learns how every device behind it normally behaves, and stops threats before they spread.

Network is healthy

Overview

auto-refresh 10s

Healthy Sequences

0

Malicious Sequences

0

Network Topology

Office Gateway

Riverside HQ

zarouter_DEMO01HQ

Connected Devices

workstation-09

192.168.1.109

612 ok

file-server-01

192.168.1.20

1840 ok

workstation-12

192.168.1.112

488 ok

reception-ipad

192.168.1.31

1204 ok

conf-room-tv

192.168.1.40

932 ok

hr-laptop-03

192.168.1.55

776 ok

Live preview of Franklin · anonymized sample network

What Franklin does

A small AI, built for the edge

Watches every device

Franklin analyzes the traffic of every device behind your router in real time, catching malicious activity and odd communications before damage occurs.

Runs on the router

Franklin scores traffic on the router itself. No cloud round-trips, no slowdown, and your traffic never has to leave the building.

Catches what signatures miss

Franklin learns what normal looks like for each device and flags what strays from it, so novel malware is caught by its behavior, not a signature list.

How Franklin works

Learn. Detect. Respond.

1
Edge-native

Deploy

Franklin installs on your router and starts working immediately. Minimal footprint, zero configuration.

2
Always-on

Observe

Franklin learns how each device on your network normally behaves and builds its own baseline — no rules to write, no signatures to update.

3
Milliseconds

Detect

Franklin scores activity in real time on the router, identifying anomalies that signature-based tools never see.

4
Autonomous

Respond

Threats are contained automatically. Franklin alerts you with the reason, not a flood of raw logs.

Use cases

Franklin on every edge

Network-wide threat visibility

Ship Franklin on subscriber routers to detect botnets, DDoS staging, and compromised devices before they affect your infrastructure. Aggregate behavioral telemetry across millions of endpoints.

  • CPE anomaly detection
  • Botnet identification
  • Subscriber protection SLA
franklin — isps & carriers
→ franklin active · 1,248 flows observed
→ behavioral baseline established
→ 0 alerts in past 24h
! anomaly detected · confidence 94%
✗ classification: suspicious lateral movement
✓ threat contained automatically
✓ team notified with full context
response time: 1.8ms

News

Featured at Web Summit Lisbon

ZeroAnomaly is a featured startup at Web Summit Lisbon, 9–12 November 2026. Come meet the team, see Franklin, and tell us about your network.

Team

Who we are

John Carter, PhD

John Carter, PhD

Co-Founder

Research in behavioral malware detection and contrastive learning at Drexel University.

john@zeroanomaly.com
Brian Mitchell, PhD

Brian Mitchell, PhD

Co-Founder

Technology leader and cybersecurity researcher with over 30 years of industry and academic experience.

brian@zeroanomaly.com
Spiros Mancoridis, PhD

Spiros Mancoridis, PhD

Co-Founder

Auerbach Berger Endowed Chair in Cybersecurity and Distinguished Professor of CS at Drexel University.

spiros@zeroanomaly.com
Pavlos Protopapas, PhD

Pavlos Protopapas, PhD

Co-Founder

Scientific Program Director at the Institute for Applied Computational Science, Harvard University.

pavlos@zeroanomaly.com

Contact

Get in touch

Tell us about your environment — we'll show you what Franklin finds.