About DPLens
A UK company building a secure Windows log collection agent.
DPLens Ltd makes one product: an agent that collects Windows logs, cuts SIEM ingest on the machine where events are written, and runs entirely on your own infrastructure.
In short
DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows.
It replaces the Splunk Universal Forwarder and Snare, cuts SIEM ingest at the source and adds file integrity monitoring, in one signed agent that is secure by design, with no vendor control plane. DPLens Manager, included in every subscription, gives you central configuration, fleet health monitoring, and deployment and upgrades.
Our point of view
Why we built DPLens
Windows servers write a lot of events, and a large share of them are of little use for detection: object-access events such as Event ID 4662 on domain controllers, Windows Filtering Platform connection events such as 5156, and the same routine records repeated over and over. Many SIEMs bill by the volume they ingest, so organisations pay to send, store and search that noise.
The usual answer is to forward everything and filter centrally. By then the data has crossed the network and the bill has been run up. We think the cheaper and simpler place to decide what a SIEM needs is the machine where the event is written, so DPLens filters, parses, aggregates, enriches, masks and rate-limits on the host, and counts every event it removes.
An agent that runs on every server, reads the Security log and holds credentials for your SIEM is part of your attack surface. We think it should be treated that way: built with secure engineering practices, signed, shipped with a software bill of materials, running with least privilege, and calling nobody you did not configure. That is why security is in the design rather than in the marketing.
Finally, we think running an agent fleet should be simple. DPLens Manager, included in every subscription, gives you central configuration, fleet health monitoring, and deployment and upgrades, and like the agent it is self-hosted and air-gap capable.
Principles
How we build DPLens
Five commitments, each one something you can check in the product or its documentation.
01
Reduce at the source
Filter, aggregate and rate-limit on the Windows host, before anything crosses the network or is billed. Nothing is dropped silently: every reduction is counted and attributed to the rule that made it.
02
Run on your infrastructure
The agent and DPLens Manager both run on your own infrastructure. No cloud service and no internet access needed, so air-gapped is a normal deployment.
03
No call-home
No telemetry and no licensing service. The licence is verified offline, and upgrades happen when you roll them out. DPLens connects only to the destinations you configure, plus a public-IP lookup service if you choose to add that enrichment.
04
Claims that match the manual
A public manual covers requirements, installation, configuration, deployment and operations in full. Our marketing claims follow the documentation, not the other way round.
05
Secure by design
Secure engineering throughout; protected secrets; a tamper-evident audit trail; Authenticode-signed releases with an SBOM. The detail is in our Trust Centre.
Who we are
Built in the UK
DPLens is built in the UK. DPLens Ltd is registered in England and Wales, company number 17427626, with its registered office in Thrapston, Northamptonshire.
We know trust has to be earned with evidence. The best evidence of how we work is what we ship: a public manual, signed releases with checksums and an SBOM, and a tamper-evident audit trail in the product itself. If you have a vendor-risk questionnaire, send it to us.
How we sell
You can book a demo or request an evaluation licence directly, and our partner programme is recruiting resellers, distributors, MSSPs, systems integrators and technology partners in every region. DPLens is priced per agent and per network source (each syslog or NetFlow receiver), with no per-GB ingestion cost; see pricing.
Find out more
Where to go next
Trust Centre
How DPLens is built, signed and verified, and how to report a vulnerability.
Read more →Documentation
The full 1.0 manual: requirements, installation, configuration, deployment and operations.
Read the docs →Partner programme
Resellers, distributors, MSSPs, integrators and technology partners in every region.
Become a partner →Contact
Sales, partners, security disclosures, privacy and general enquiries.
Contact us →See it on your own logs
Try DPLens on one Windows server before you talk to anyone.
Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.