A security product should be the hardest thing on your network to abuse.
Seculogik sits above your detection stack and holds your cases, your evidence and your decisions. This page says what the platform enforces on your behalf, how you can check it for yourself, and what we do not yet hold — because we would rather you read that here than discover it in a procurement questionnaire.
Sovereignty you can attest, not just believe
Sovereignty is a switch you own. AI runs on your own box by default; the cloud is reached only when you bring your own key and say so. The platform publishes a machine-readable attestation of its current posture — whether cloud AI is allowed at all, and at which level that rule is set — so your auditor, your DPO or your own monitoring can check it at any time without asking us.
Every cloud-bound AI call, on the record
If you do choose cloud AI, each outbound call is written to a tamper-proof ledger before it leaves: where it went, which posture applied, and how much was redacted first. Entries cannot be edited or deleted afterwards, and the whole ledger exports for your data-protection officer. Local inference never leaves the box, so there is nothing to disclose.
A tamper-evident audit trail
Every change made in the platform — a verdict, a status, a setting, a user — is recorded in an audit trail that resists alteration after the fact and is kept separately for each client. When a regulator or a client asks who decided what and when, the answer is already written down.
Signed updates that roll themselves back
Every release is cryptographically signed and verified before a single byte is applied. Updates are never pushed onto your box: an administrator reviews and applies them, a restore point is taken first, and if the platform fails its own health check afterwards the update rolls back on its own. Air-gapped sites get an offline path, and every update is kept in history.
You can see what is inside
Each release ships with a software bill of materials — a complete inventory of its components — so your procurement, your vulnerability team and your regulator can answer “are we exposed?” without opening a ticket with us. Behind it, no release leaves us without static analysis, dependency vulnerability scanning and secret scanning, so a component with a known weakness is stopped at the gate rather than shipped to you.
Secrets encrypted, never shown again
Credentials for your detection stack — open-source SIEM and data stacks such as Wazuh, OpenSearch, Elastic or ClickHouse, market platforms such as Splunk, Sentinel, CrowdStrike, Defender, Okta or Entra ID, and any custom connector we build for you — are encrypted at rest, never logged and never displayed back once saved. Destinations you configure are re-checked at the moment they are used, not only when they are entered.
Identity your IT team already trusts
Single sign-on through SAML, multi-factor authentication with a hard requirement for administrators, role-based access, scoped API keys you can revoke in one click, and an SSO-only mode for organisations that do not want local passwords at all.
Hardened out of the box
The installer ships the perimeter with the product: modern browser protections on every response, a web application firewall in front of the platform, automatic banning of brute-force sources and a host firewall — applied by the same script that installs the software, so hardening is never a step someone forgot.
Response stays in your hands
Destructive actions such as isolating a host, resetting credentials or blocking an address always require a person, and no playbook can quietly downgrade that. Remote response agents keep your vendor credentials on your own hosts; the platform never holds them, so compromising the platform does not hand anyone your firewall or your EDR.
Data protection built in
Subject-access export and erasure on request, retention rules per class of data, and redaction of secrets and personal data — including French SIRET and RIB identifiers — before anything is sent to a cloud model. Your GDPR obligations are handled as a feature, not as a project.
Report a vulnerability.
We run a coordinated-disclosure policy and ship it with the product, including the advisory format we use and the path a report takes from receipt to fix. Every Seculogik deployment whose operator sets a security contact publishes it in the standard machine-readable form, so a researcher who finds an instance finds the right mailbox — yours for your box, ours for the platform.
To report something about the platform itself, use the contact form and mark the message security; it goes to engineering, not sales. From 11 September 2026 the Cyber Resilience Act's reporting obligations apply to us as a manufacturer: an actively exploited vulnerability in our product is reported to ENISA and the national CSIRT with a 24-hour early warning, and affected customers are told directly rather than left to find the advisory.
Report through the contact formSaid plainly.
- No ANSSI qualification, CSPN or SecNumCloud. A readiness assessment is on our roadmap; a claim is not. We would rather tell you now than let a slide imply it.
- No third-party penetration-test report yet. Adversarial review is continuous inside engineering; a formal external test is part of the design-partner phase.
- No SLA. Early-stage vendor, design-partner programme, direct access to the engineers who built it.
- No published customer references. We name a customer only with their written consent, and we will not imply one with a logo wall.
- No multi-tenant SaaS. One deployment per customer or per MSSP, on infrastructure you control. Multi-client is a hard wall inside your deployment, enforced at several independent layers — not a shared cloud with a filter in front of it.