Why I'm building
AstraQ Cyber Defence

A small apartment in Akola, a third year of B.Tech, a student innovation cell to run, and a stubborn feeling that none of the tools I was using were built by people who actually had to use them.

I started AstraQ Cyber Defence in 2025, in my third year at Rashtriya Raksha University. I was also running a twenty member student innovation cell on the side. The Deloitte Cyber Strategy internship came the next year, in my fourth year, from January to June 2026. A lot of people asked me why I wanted one more thing on my plate. The honest answer is that I kept running into the same problem in every place I worked. The software was bad, and nobody seemed to mind.

Take CTFd, the platform almost every Capture The Flag event in India runs on. It is built on Flask and Jinja templates from a decade ago. Every CTF I joined started with the same set of small failures. The site got slow under load. Player environments leaked into each other. Organizers spent more time fixing the infrastructure than writing challenges. And if you were a student who wanted to practice on real problems between events, there was no good place to go. You waited for the next CTF or you stopped learning.

The same shape of problem kept showing up. Phishing detection in most email clients still works like a binary spam filter from 2005. Enterprise search inside large companies, the kind a sales engineer or a legal team would actually need, is broken in a specific way. The data is locked up in twenty different systems. The search is keyword only. And any AI assistant you bolt on top sends sensitive documents to someone else's cloud. Malware analysis for security teams still means running suspicious files inside a sandbox that somebody set up by hand five years ago and nobody has touched since.

These are not edge cases. They are everyday workflows for people who get paid to do security, and almost no Indian company was building for them.

None of this came at me as a market opportunity, though. The truth is that I wanted to build a company first, long before I knew what kind. Not specifically a cybersecurity company. Just a company. The cybersecurity part arrived later, after the four problems above came into focus slowly, over years of running into them in school, internships, and competitions. By the time AstraQ became a company, the gap was not something I had to argue for. I had already been living in it.

Why four products and not one

People ask me this often. The clean startup answer is that you should pick one wedge and go deep. I tried to honour that for a few months, and then I noticed something. The four problems I cared about were not separate products. They were the same customer at four different times of day.

Phoebe is an enterprise RAG platform. It connects to the systems a company already uses, indexes them with hybrid search, and answers questions with citations. The whole thing can run inside a customer firewall. No data leaves their network. We built it for BFSI, healthcare, and government, because those are the people who cannot use any of the obvious AI tools.

Athena CTF is what I wanted in college and could not find. It runs three platforms under one account. A live competition platform for events. A practice arena that is always open, so a student preparing for an interview can solve real challenges any day of the week. And an enterprise training platform for organizations that want to upskill their own teams. Every player gets an isolated environment. No shared state. No leaks.

Metis Mail is an open source, AI native email client. It unifies Gmail, Outlook, and Zoho into one workspace. Every incoming email is checked for phishing before you see it. The assistant can summarise threads, draft replies, or search by question. It exists because nobody has built a calm email app in a decade.

Morpheus is still in development. It is a VM sandbox where an analyst can submit a suspicious file and let autonomous agents handle the analysis. The agents decide which tools to run, chain them as needed, and return a structured report. The sandbox is destroyed when the job ends. No host exposure. No manual configuration.

Why all four at once? Because the same kind of customer needs all four. Phoebe gives them private AI. Athena builds the people who use it. Metis protects the inbox those people live in. Morpheus catches the malware that gets through the inbox anyway. Most companies in the space try to do one of these and never ship the rest. We picked four because they are connected, and because we have the discipline to keep them small and focused.

What नित्यं रक्षणम् means to me

The company motto is in Sanskrit. नित्यं रक्षणम् means eternal protection. I am Marathi, from a small town in Vidarbha, and putting the motto in Sanskrit was a quiet choice. The defence sector in India often hides behind English acronyms borrowed from American doctrine. I wanted something rooted.

The motto is not on the site to sound profound. It is there so that I remember what the job is. The job is not selling a tool. It is not winning a hackathon. It is not raising a round. The job is that someone, somewhere, runs a hospital or a payments company or a state agency, and our software is one of the things keeping them safe at three in the morning. That is what I want AstraQ to be, year after year, for as long as I am running it.

The day I finally told them

Before AstraQ had its name, we wanted to call the company Chhatrapati, after Chhatrapati Shivaji Maharaj. The Ministry of Corporate Affairs would not allow it; the name is restricted, for reasons that make sense the second you sit with them. AstraQ was the alternative we built around. Astra for the weapon, Q for the company that comes after. The motto stayed Sanskrit. The intent stayed the same.

We had set a registration date with the registrar for 26 June 2025. That is my parents' marriage anniversary, and I had quietly liked the idea of starting the company on a day that already meant something at home. The filing got delayed. AstraQ was finally incorporated on 18 July 2025, which is my younger brother's date of birth. The replacement was also a day that meant something.

I had not told my parents any of this yet. Early on I had decided I would not say a word about the company until I could keep it running with my own money, or with money the company earned itself. If I had to borrow from home, it was not really mine. So I kept the incorporation certificate to myself for months.

The day I let myself tell them came on 8 October 2025. We had been selected for the Samarth Incubation Program run by C-DOT and STPI, and we received a one lakh rupee grant at the India Mobile Congress in Delhi. I told my father I was leaving for a competition. After the ceremony I sent him a photograph. Sinoy and me holding the cheque, the C-DOT and STPI officials standing beside us. That was how my parents found out their son had a company.

The team

AstraQ is not just me. It is seven people.

Six of us are batchmates from RRU's Computer Science and Cyber Security program, all graduating in 2026. We have been losing competitions together for two years before we ever called this a company. Most of the team was built out of those competitions, and out of losing in them together.

Anvesha Saini and I were the first to try anything together. We went to the Innovation, Design and Entrepreneurship Bootcamp run by AICTE and the Ministry of Education's Innovation Cell at SVNIT, Surat. I came back with a Best Performer recognition. More importantly we came back with a working understanding of how to stand in a room full of strangers and talk about an idea.

The next year, four of us were selected for the Smart India Hackathon through the internal round at RRU. Me, Bismit Panda, Anvesha, and Raunak Sinha. SIH was the first time we built something with real deadlines, real judges, and a real problem statement. It was also the first time we realised we worked well together under pressure.

Somewhere between SIH and what came next, we tried to build a different company. We were going to call it Sigma. Almost every bike taxi in India today runs on petrol. The riders work without a real contract or any safety net. There is no central authority anyone reports to. And the whole thing puts a small but steady amount of pollution into the air for what should be a five kilometre trip. Sigma was meant to fix that. Electric bikes owned by the company, ridden by people we actually employed instead of contracted, with proper safety training, a real grievance line, and fleet operations behind every rider. We were going to start small in Akola and prove the model.

Four of us were on it. Bismit, Anvesha, Raunak, and me. Ali was in college, head down on something else of his own that month. Sinoy was at home with a fever, contributing in short bursts between paracetamol doses.

Sigma did not die from market research. Everything was ready. The tech was ready. The pitch was ready. The market plan was ready. We were college students, but we had walked that plan into a corner where, on paper, it could actually work.

The one thing that was not ready, when the deadline came around, was one teammate's piece of the work. He had a clean slice of Sigma to deliver. Somewhere between the kickoff and the deadline, that slice quietly stopped progressing. We waited. We checked in. The check-ins became reminders. The reminders became questions. The questions did not get answers. The window closed. Sigma went with it.

I am not going to name him in a blog post that the internet can search. He is still very much on the team, still very much a friend, and if he ever reads this paragraph he will know exactly which piece of Sigma I am talking about. He still owes us that piece, by the way. We decided that week we were software people, and that we should go build software. AstraQ comes from that decision.

The OSINT story is my favourite. Ali Ahmad, Sinoy De, Anvesha, and I had applied for an OSINT hackathon organised by UPSIFS in Lucknow. We picked a maritime problem statement and spent weeks on it. Then the organisers cancelled the hackathon. We were sitting with a pile of research and no place to use it. Around the same time the NCIIPC Startup India AI Grand Challenge opened. We pivoted, reframed what we had, applied, and finished in the Top 6. The cancelled hackathon became the foundation for what AstraQ is today.

The team as it stands now:

Bismit Panda is CTO. I first really worked with him at SIH, where he was the one quietly writing code while the rest of us argued about scope. He has been writing software for five years across fourteen languages and frameworks, qualified GATE 2025, was an NTSE Scholar, is CEH certified, and interned at IIT Bombay. When we disagree on architecture, he usually wins, because he has already tried it both ways.

Raunak Sinha runs R&D and AI Research. He was the fourth person in that SIH room, and the one who stayed on the model problems long after the rest of us had moved on. He has shipped four production AI and ML systems end to end, mostly NLP and applied machine learning. Where the rest of us still treat models as something to wrap a product around, Raunak treats them as something to live with. Every model layer in the portfolio passes through his hands.

Anvesha Saini is COO. She has been part of this from before there was a this, since that first trip to the AICTE IDE Bootcamp at SVNIT, Surat. She is Vice President of IncuBeta, a former Project Analyst at AIC RRU, and co-author on a Scopus Q2 paper on AI security in Brain-Computer Interfaces. When I write a plan she reads it once and it turns into a calendar. The company runs because she runs it.

Sinoy De is CISO. He was in the OSINT group from day one, on that cancelled UPSIFS hackathon application and the NCIIPC Top 6 that came out of it. He is the second person in the C-DOT cheque photograph. Offensive security from RRU's SITAICS school, eJPT and Ethical Hacking certified, co-author on the same Scopus paper, Secretary of IncuBeta. Anything that leaves AstraQ as a product or a packet, he has signed off on the security of.

Ali Ahmad is Head of OSINT R&D. He was the fourth name on that cancelled OSINT hackathon application, and the one who refused to let the work die. Brahmastra, our intelligence-gathering framework, came out of those weeks. He has also volunteered at two National Cyber Security Exercises. The intelligence pipelines and our open-source ecosystem both live under him.

Bhumika Baghele is CMO, and she is the one person on the team I did not meet at RRU. We have been friends since tuition days in Akola. When I told her we needed someone serious about marketing, she said yes the same week and joined. She came from a BBA at Sant Gadge Baba Amravati University and now owns everything commercial, from brand to go-to-market.

I keep saying I started AstraQ. The truer sentence is that we started AstraQ. I get to be the face of it because someone has to be. The work is shared.

Where this goes

I am twenty one. AstraQ is small. We are not yet at scale. What I can promise is that we will not ship anything we would not run ourselves, and we will not say anything in a sales call that I would be embarrassed to repeat to a classmate.

If you want to talk, the calendar is open at appointy.xyz/raj/15min. If you want to try the products, athena-ctf.com and usephoebe.com are live. I would rather have ten customers who actually use the software than a thousand who looked at a landing page once. The slow way is the only way.