The first cybersecurity-specialised LLM — developed in France

SYLink AI80 billion parameters

Sovereign artificial intelligence, trained exclusively on cybersecurity data. Hosted in France. Zero foreign dependency.

Hosted in the Unitel datacentres — Marseille, France

Free trial · no credit card · no commitment

On-premise · Zero Cloud Act exposure·4.2% measured hallucination rate·MTTD < 5 min
94%
Accuracy
sur benchmarks cyber
184ms
Latency
average response
4.2%
Hallucinations
measured rate
63k+
Samples
training data
One platform — six tools — a single AI

All your security toolsbrought together in one place.

One dashboard to replace the pile of separate products X or Y. Everything sits in one place, driven and managed by an AI under your control.

The AI informs you. You decide.

Traditional Approach

  • 1 SIEM (Splunk / QRadar)
  • 1 EDR (Crowdstrike / SentinelOne)
  • 1 NDR (Darktrace / Vectra)
  • 1 SOAR (Palo Alto / IBM)
  • 1 vuln scanner (Tenable / Qualys)
  • 1 third-party honeypot (Thinkst Canary)
  • 1 mobile MDR
  • → 7 contracts · 7 dashboards · 7 different languages · data that never talks to itself

SYLink Approach

  • DPI Probe + EDR + Mobile + HoneyPot + PenTest
  • 1 AI (SYLink AI 80B) making them talk to each other
  • 1 unified dashboard
  • 1 contract — sovereign data
  • Every source correlates automatically
  • HMAC audit chain: DORA / NIS2 compliance built in
  • → You see everything, the AI handles it, you decide
Coherent by design — not a bag of bought-in tools

We do not ship seven separate products for you to integrate. Every SYLink module was designed from the start to be se parler — SYLink AI is the single orchestrator that ties an EDR alert to a DPI flow, a touch on the HoneyPot, a finding from the PenTest VM and an exposed credential. You see the full attack chain, not seven disconnected silos.

Three levels of power

From the open-source release to the UniSOC production build — one model, three variants.

VersionParametersContextLicenseUsage
SYLink AI 8B
F16 · 16 GB · T° 0.6
8.2B32 768 in / 4 096 outApache 2.0SOC Tier 1 · fast triage · open source
SYLink AI 32B
Q5_K_M · 22 GB · T° 0.3
32.8B16 384 in / 8 192 outSalesSOC Tier 2/3 · in-depth investigation · on-premise
SYLink AI, 80 billion parametersUniSOC
Production · extended context · multi-tenant
~80BextendedProductionThe AI engine of the UniSOC platform

Model lineage

Built on Qwen3 (Apache 2.0), then fine-tuned by SYLink Technologie on exclusive cybersecurity corpora. Published openly through Ollama for the community.

$ollama pull sylink/sylink:32b

Composition of the training dataset

  • Incident response playbooks (NIST CSF)
  • MITRE ATT&CK documentation — 14 tactics, 200+ techniques
  • CVE bulletins & exploit analyses
  • Compliance frameworks (NIS2, ISO 27001, NIST 800-53…)
  • Threat intelligence reports & APT TTPs
  • Annotated detection rules (Sigma, YARA)
8B: 45,018 samples32B: 63,313 samples80 bn: 80,000+ (extended by UniSOC)

5 areas of specialisation

Unlike general-purpose LLMs, SYLink AI is trained exclusively on cybersecurity corpora — standards, incidents, attack techniques and compliance frameworks.

Threat Intelligence

  • MITRE ATT&CK alignment — 14 tactics, 200+ techniques
  • Threat actor profiling (APT groups, cybercrime crews)
  • IOC analysis and correlation against 12M+ indicators
  • Zero-day vulnerability assessment

Incident response

  • NIST CSF guidance — detect, contain, eradicate, recover
  • Automated alert triage with a priority score
  • Dynamic containment plans adapted to the context
  • Forensic assistance and evidence preservation

Vulnerability management

  • CVE analysis with real exploitation context
  • Patch prioritisation by business risk
  • Structured pentesting methodology
  • Real-time correlation between CVEs and exposed assets

Compliance & governance

  • NIS2, GDPR, DORA — reports generated automatically
  • ISO 27001, NIST 800-53, CIS Controls
  • SOC 2, PCI-DSS, HIPAA — contextual guidance
  • Mapping of regulatory obligations
  • Prioritised remediation recommendations

Detection Engineering

  • Generation of tailored Sigma and YARA rules
  • SIEM query optimisation (Splunk, Elastic)
  • Natural-language threat hunting (French + English)
  • False-positive analysis and rule tuning

Total sovereignty

  • Hosted in the Unitel datacentres — Marseille
  • No data ever leaves French soil
  • Zero dependency on AWS, Azure, GCP or OpenAI
  • Outside the scope of the US Cloud Act
  • Meets the SecNumCloud requirements

Real-time analysis pipeline

From raw event to response action — every step automated and enriched by the 80-billion-parameter SYLink AI.

01
Ingestion
DPI + EDR + SIEM logs
02
Normalization
Parsing, deduplication, TTL
03
Correlation
EDR × DPI × CTI × UEBA
04
ML scoring
50+ features per event
05
AI triage
SYLink AI, 80 billion parameters — analysis
06
Response
Alert + SOAR auto-trigger

Multi-source correlation

  • DPI × EDRNetwork and endpoint cross-referenced for every host
  • Real-time CTI12M+ IOCs queried on every outbound connection
  • UEBABehavioural baseline per user and per machine
  • Sigma/YARA100,000+ rules evaluated on every EDR event
  • Kill chainAutomatic multi-stage MITRE ATT&CK reconstruction

Detection capabilities

  • 80+ MITRE techniquesAutomated coverage across 14 ATT&CK tactics
  • Beacon C2Detection of periodic C2 communications (timing)
  • DNS/ICMP tunnelingAnalysis of legitimate protocols abused for exfiltration
  • Shadow IT / Shadow AIReal-time mapping of unauthorised applications
  • Lateral movementSMB, RDP, Pass-the-Hash and Golden Ticket detection

Measured performance

Metrics from production deployments — real data on Unitel infrastructure.

<3 min
MTTD
average time to detect
−80%
False positives
vs. static rules alone
99.9%
Availability
Platform SLA
<48h
Time-to-protect
full rollout

Detection engine

SYLink AI response latency184 ms
Accuracy on cyber benchmarks94%
AI hallucination rate4.2%
ML features per event50+

Volume handled in production

DPI flows analysed per day4M+
YARA/Sigma rules evaluated100 000+
IOCs queried in real time12M+
Training samples63 000+
MITRE techniques covered80+
CTI enrichments / alert15 sources

SYLink AI in action

Real queries — click to see the answers.

The brain of UniSOC

The 80-billion-parameter SYLink AI is the engine at the centre of the UniSOC platform — it powers every analysis, investigation and automated response feature.

  • Automatic alert triage with a plain-language explanation
  • Natural-language threat hunting — ask in French or in English
  • Cross EDR×DPI investigation — automatic kill chain reconstruction
  • NIS2, GDPR and DORA compliance reports generated on demand
  • Remediation recommendations set in the context of your own infrastructure
  • SOC voice assistant — real-time security briefing
100% local — data stays in France

The 80-billion-parameter SYLink AI runs entirely inside the Unitel datacentres in Marseille. No external API call, no data passed to a third party. Your logs, alerts and incidents stay in your sovereign space.

vs. the alternatives

CrowdStrike Charlotte AIGeneral-purpose GPT-4 (OpenAI)
Microsoft Copilot SecurityGPT-4 Azure (USA)
SentinelOne Purple AIGeneral-purpose GPT-4 (OpenAI)
Palo Alto Cortex XSIAMUS cloud, multi-LLM
SYLink AI, 80 billion parametersCyber LLM, hosted in France, running locally

Frequently asked questions — SYLink AI

Performance, hallucination, DORA compliance, GPUs: everything a CISO should know before auditing a SOC LLM.

Why an on-premise LLM rather than OpenAI or Anthropic?
Three reasons: (1) Sovereignty — US LLM APIs (OpenAI, Anthropic, Azure OpenAI, Bedrock) fall under the 2018 Cloud Act, FISA 702 and the CLOUD Act. In July 2025 Microsoft acknowledged it could not guarantee confidentiality against a US warrant. (2) Compliance — NIS2 article 21 and the GDPR require your logs to stay within the territory. (3) Cost — beyond 100k requests a month, a US LLM API costs more than an amortised H100 GPU.
Which SYLink AI models are available?
Three on-premise variants: SYLink AI 8B (8 GB VRAM, 4 sec per triage, ideal for public bodies under 50 endpoints), SYLink AI 32B (24 GB VRAM, 5-8 sec per triage, the mid-market sweet spot) and SYLink AI 80B (80 GB VRAM, 12 sec per triage, deep threat hunting). All published on ollama.com/sylink/sylink.
What is the measured hallucination rate?
Observed hallucination rate: 4.2% on SOC triage, measured by manual re-labelling of a 5% sample of AI decisions. Compare with the 8-15% typical of an unaudited general-purpose US LLM. UniSOC implements a chained HMAC-signed audit trail (DORA art. 28) — every decision is traceable and reviewable.
How many GPUs does SYLink AI need?
For a mid-market tenant with 200 endpoints, a single H100 GPU (80 GB) comfortably runs the 32B model plus agentic triage. For an MSP serving 50 tenants: two to three H100s. Amortised over three years, an H100 costs less than 100,000 requests a month on the OpenAI GPT-4 API.
How can the AI be audited for DORA and NIS2?
UniSOC implements DORA art. 28 compliance (algorithm auditability) natively: every AI decision (verdict, auto-close, auto-block, auto-response) is recorded in an append-only, per-tenant chained HMAC trail. The prompt and the LLM response are hashed, never stored in clear. A weekly job replays each chain and raises an alert if tampering is detected. A human review loop is mandatory, with an approve/overrule/skip status and a comment.
Does SYLink AI replace SOC analysts?
No. SYLink AI handles the L1 (triage) and L2 (contextual correlation) layers of the SOC pyramid — around 80% of daily events. Human analysts focus on deep hunting, response orchestration on critical incidents, and quality review of the AI (5% sampling). The model: one human SOC analyst plus AI can absorb the volume of four to five analysts working alone — with no drop in quality.

See the 80-billion-parameter SYLink AI in real conditions

A demonstration on your own data, inside your own infrastructure. Nothing is shared.

Cookie settings

We use cookies to improve your experience on our site. By continuing to browse, you accept our privacy policy and our use of cookies under the GDPR.