The most dangerous file isn’t the one the whole world knows. It’s the one nobody has named yet.

It’s a file created for just one company. For one computer. For one situation.

Traditional antivirus long worked on a simple logic: someone sees a threat, describes it, adds it to a list, and the protection recognizes it next time. This principle still makes sense for things that repeat.

But the security world has moved on.

Today, an attacker can create a new variant of malicious code quickly, cheaply, and precisely for a specific target. Such a file doesn’t have to be on any blacklist. It doesn’t need a name someone has already entered into a database. And that’s where the problem with classic defense begins: it waits for the past, while the attack comes from the future.

AI antivirus as a protective robotic knight with a shield guarding corporate data against a dark digital attacker
AI antivirus as a protective shield between corporate data and malicious code — the principle on which ITHOPE builds its own local endpoint protection.

The point is simple: when a malicious file gains trust inside a company, it’s not just about one computer. It’s about documents, accounting, contracts, know-how, operations, and customer trust. One bad moment can trigger a loss that can’t be fixed by simply reinstalling a laptop.

At ITHOPE, we are therefore building our own AI antivirus: local endpoint protection with a detection engine designed to assess a file based on what it truly is, not just whether someone has already named it.

Not as another marketing label slapped on an old antivirus. As a different way of thinking about trust, risk, and protecting corporate data.

Local decision Core file assessment without sending sensitive data to a foreign cloud.
Explainable verdict Not just an anonymous message, but an understandable reason why the file is suspicious.
European product An auditable approach, own infrastructure, and a business without selling user data.

AI antivirus for companies

We are building a product for companies that want to protect laptops, workstations, and internal files without turning security into blind trust in a foreign cloud.

Key topics: local antivirus, endpoint protection, suspicious file detection, explainable verdict, European cybersecurity, and AI endpoint security for businesses.

Why traditional antivirus hits its limit

Antivirus based mainly on known signatures is strong where attacks repeat themselves. If the same malicious file spreads between companies, it makes sense to describe it, share the information, and recognize it faster next time.

But today’s attacks no longer need to be massive and repeatable. An attacker can modify existing malicious code, repackage it, create a variant for a specific company, or exploit a legitimate-looking file. To the average user, it looks like an attachment, an installer, a document, an internal tool, or a utility program.

For a company, the hardest moment is right before the incident: deciding whether to trust a file or stop it.

This is where we see space for an AI antivirus and endpoint protection that can also work with an unknown variant. Not just waiting for a list of known threats. Not just asking: „Has anyone seen this before?„ Also asking: „What does this file do, what does it look like, and why should a computer trust it?"

Realistic laptop and monitor in an office, a red suspicious file is stopped by an AI shield before reaching protected corporate devices
A suspicious file is stopped before it gains trust in the company's working environment — the AI layer evaluates it before it gets executed.

What AI antivirus means according to ITHOPE

The word AI is slapped on everything today. We don’t want to use it as decoration. For an antivirus, it only makes sense if it helps make a better security decision on a specific file while remaining understandable to the person responsible for security.

Our vision is simple:

  • So it doesn’t rely only on a list of known threats. A new or modified file must make sense to assess even when it has no history.
  • So the core assessment runs locally. Corporate files are not training material for foreign services.
  • So the result makes sense to a human. An administrator, technician, or security team needs to know why the system flagged something.
  • So the product can be audited and explained. Cybersecurity for companies cannot stand on a black box that everyone just trusts.
  • So it respects the European view on data. Without a model where the product’s value is built on the user losing sight of what happens to their data.

Exactly how we do this, we’ll keep to ourselves.

In cybersecurity, know-how is not a decoration for a presentation. It’s the essence of the product.

Close-up of a monitor showing the visual flow of a file through an AI layer into a shield, a red quarantine area and green approved files
Product principle: a file enters assessment, the AI layer helps with the verdict, a risky file ends up in quarantine, and safe ones continue onwards.

For partners and investors

We're not looking for applause for an idea. We're looking for people who understand that the endpoint protection market will have to change.

We have a functional detection engine, our own infrastructure, and a realistic path to a product. Now it makes sense to talk to people who can help with the product, the market, financing, or tough security opposition.

Why companies might be interested

Corporate security often rests on a compromise. A small or medium-sized company doesn’t want to run a complex security apparatus. At the same time, it can’t rely on the fact that everything dangerous has already been experienced, described, and entered into the rules by someone else.

A local AI antivirus can be interesting for companies for four reasons.

First: data. Sensitive attachments, internal programs, accounting exports, or technical documents shouldn’t leave the corporate environment without a very good reason.

Second: comprehensibility. If the protection flags something, a person needs to understand why. Otherwise, security becomes just another window the user clicks away.

Third: independence. European companies will increasingly deal with where their data is evaluated, who owns the security technology, and how dependent they are on a few global suppliers.

Fourth: usability. Strong protection shouldn’t only be for corporations with large security teams. A good product must also be practical for a firm that wants to protect laptops, workstations, and internal processes without unnecessary complexity.

Local server and workstation infrastructure in an IT lab, multiple laptops and monitors are protected by an AI shield
Local protection isn't just a nice word for marketing. For companies, it means control over where files are assessed and how dependent they are on remote services.

What a company, partner, or investor should take from this

This isn’t another marketing label for an old antivirus. We’re building our own security technology in Brno for an era when a malicious file doesn’t need to be known to be dangerous.

For companies, it’s important to protect laptops, workstations, and internal files without unnecessarily sending sensitive data outside their own environment. For partners, it’s an opportunity to be part of a product that solves a practical problem for IT administrators. For investors, it’s a signal that this isn’t an idea on paper, but a direction with a functional detection engine, its own background, and a clear path to a product.

Why we dare to do this

Because we aren’t a team that discovered security yesterday.

ITHOPE has 18 years of experience in IT, service, infrastructure, and security. We have our own data lab. We have our own compute and GPU infrastructure in Brno. We handle both AI and security under one roof.

We’re not building a slide deck. We’re building the engine.

The real ITHOPE lab in Brno, a technician works on electronics under a microscope
Real work in the ITHOPE lab. We bring the same emphasis on control, precision, and our own infrastructure to the development of the AI antivirus.

Why investors might be interested

Cybersecurity isn’t a nice add-on to IT. It’s the infrastructure of trust. Companies will continue to need endpoint protection, risk management, and tools that make sense even outside the world of large corporations.

From an investment perspective, we see several reasons why a local AI antivirus makes sense to address right now:

  • Attackers are changing the economics of an attack. Creating new variants of malicious files is more accessible than before.
  • Companies are addressing data and jurisdiction. Not every security function has to automatically end up in a foreign cloud.
  • The European market needs trustworthy alternatives. Not as isolation from the world, but as greater control over a critical IT layer.
  • The product can grow gradually. From a detection engine to a usable tool for real companies, partners, and IT administrators.

This isn’t a promise of a quick miracle. It’s a bet on a category where decisions about trust, data, and the ability to protect companies from unknown variants of malicious files will be made.

Honestly: where we are today

It’s not a finished antivirus yet.

We have a functional detection engine, lab-verified results, and a well-thought-out path to a product. There’s still work ahead of us: productization, user interface, integration, team, partnerships, distribution, and the market.

But the direction is clear.

The security of the next decade won’t just be about larger lists of known threats. It will be about the ability to understand an unknown file before it becomes another incident.

What we’ll show in person

We don’t want to publicly describe the technical know-how that constitutes a competitive advantage. But it makes sense to show partners, investors, and people from the field more in a personal setting.

We can talk about how we think about the product, where the detection engine stands today, what our infrastructure looks like, what role local evaluation plays, what types of partnerships make sense, and what we need for the next phase.

Just as important as financing for us is quality opposition. We don’t just want agreement. We want to talk to people who can find weaknesses before the market does.

How we prove it

Words aren’t enough in cybersecurity. That’s why we test the detection engine against reality, not just on slides.

It already runs on real Windows: it reacts correctly to a test threat (standard EICAR sample) — flags it, clearly explains why, and reversibly isolates it. And on real Windows system files, it reports no false positives, meaning it doesn’t bother normal operations.

What still needs to come, and what we’re working on, is hard independent proof: certification by independent labs (like AV-TEST or AV-Comparatives), which is the only thing enabling a fair comparison with existing antiviruses. Until we have it, we don’t claim to „defeat" anyone — we only promise what we can substantiate. This honesty is precisely why we’re looking for partners for the next phase.

Who we want to meet

We’re interested in feedback from people who build, buy, finance, or critically evaluate security.

  • Investors who understand B2B cybersecurity and a long-term product.
  • Security people who can provide hard opposition without the marketing sugar.
  • Partners who see room for a European, local, and auditable alternative.
  • Product people who can help get a strong engine into a form that a real company will want to use.

FAQ: AI antivirus, local protection, and product status

What is an AI antivirus?

An AI antivirus is protection that doesn’t rely solely on a list of known threats. The goal is to assess a suspicious or unknown file based on its characteristics and give a person an understandable verdict.

What’s the difference between a traditional antivirus and an AI antivirus?

A traditional antivirus is strong mainly where a known threat pattern already exists. An AI antivirus should also help where a file has no history or resembles a new variant of a known problem.

Is the ITHOPE antivirus a finished product?

No. We have a functional detection engine and lab-verified results, but it’s not a finished commercial antivirus yet. We are working on the path from an engine to a usable product.

Why should the evaluation be local?

Because corporate data should remain under the company’s control. For the core decision, we don’t want to build on files being automatically sent to a foreign cloud.

For whom does a local AI antivirus make sense?

For companies, IT administrators, security partners, and organizations that want better endpoint protection while also addressing trust, auditability, and data handling.

Why is local endpoint protection important for the market?

Because companies are increasingly looking for a combination of three things: AI cybersecurity, corporate device protection, and data control. A local AI antivirus fits right into the intersection of these topics.

Why are we talking about this already?

Because we’re looking for the right people for the next phase: investors, partners, security opponents, and product teammates. Early feedback is just as important for such a product as the development itself.

If this direction interests you, get in touch. We’ll show partners, investors, and people from the field more in person.

See also: AI training for companies · IT for Business