SYLink AI80 billion parameters
Sovereign artificial intelligence, trained exclusively on cybersecurity data. Hosted in France. Zero foreign dependency.
Free trial · no credit card · no commitment
All your security toolsbrought together in one place.
One dashboard to replace the pile of separate products X or Y. Everything sits in one place, driven and managed by an AI under your control.
The AI informs you. You decide.
❌ Traditional Approach
- 1 SIEM (Splunk / QRadar)
- 1 EDR (Crowdstrike / SentinelOne)
- 1 NDR (Darktrace / Vectra)
- 1 SOAR (Palo Alto / IBM)
- 1 vuln scanner (Tenable / Qualys)
- 1 third-party honeypot (Thinkst Canary)
- 1 mobile MDR
- → 7 contracts · 7 dashboards · 7 different languages · data that never talks to itself
✓ SYLink Approach
- DPI Probe + EDR + Mobile + HoneyPot + PenTest
- 1 AI (SYLink AI 80B) making them talk to each other
- 1 unified dashboard
- 1 contract — sovereign data
- Every source correlates automatically
- HMAC audit chain: DORA / NIS2 compliance built in
- → You see everything, the AI handles it, you decide
We do not ship seven separate products for you to integrate. Every SYLink module was designed from the start to be se parler — SYLink AI is the single orchestrator that ties an EDR alert to a DPI flow, a touch on the HoneyPot, a finding from the PenTest VM and an exposed credential. You see the full attack chain, not seven disconnected silos.
Three levels of power
From the open-source release to the UniSOC production build — one model, three variants.
| Version | Parameters | Context | License | Usage |
|---|---|---|---|---|
SYLink AI 8B F16 · 16 GB · T° 0.6 | 8.2B | 32 768 in / 4 096 out | Apache 2.0 | SOC Tier 1 · fast triage · open source |
SYLink AI 32B Q5_K_M · 22 GB · T° 0.3 | 32.8B | 16 384 in / 8 192 out | Sales | SOC Tier 2/3 · in-depth investigation · on-premise |
SYLink AI, 80 billion parametersUniSOC Production · extended context · multi-tenant | ~80B | extended | Production | The AI engine of the UniSOC platform |
Model lineage
Built on Qwen3 (Apache 2.0), then fine-tuned by SYLink Technologie on exclusive cybersecurity corpora. Published openly through Ollama for the community.
Composition of the training dataset
- Incident response playbooks (NIST CSF)
- MITRE ATT&CK documentation — 14 tactics, 200+ techniques
- CVE bulletins & exploit analyses
- Compliance frameworks (NIS2, ISO 27001, NIST 800-53…)
- Threat intelligence reports & APT TTPs
- Annotated detection rules (Sigma, YARA)
5 areas of specialisation
Unlike general-purpose LLMs, SYLink AI is trained exclusively on cybersecurity corpora — standards, incidents, attack techniques and compliance frameworks.
Threat Intelligence
- MITRE ATT&CK alignment — 14 tactics, 200+ techniques
- Threat actor profiling (APT groups, cybercrime crews)
- IOC analysis and correlation against 12M+ indicators
- Zero-day vulnerability assessment
Incident response
- NIST CSF guidance — detect, contain, eradicate, recover
- Automated alert triage with a priority score
- Dynamic containment plans adapted to the context
- Forensic assistance and evidence preservation
Vulnerability management
- CVE analysis with real exploitation context
- Patch prioritisation by business risk
- Structured pentesting methodology
- Real-time correlation between CVEs and exposed assets
Compliance & governance
- NIS2, GDPR, DORA — reports generated automatically
- ISO 27001, NIST 800-53, CIS Controls
- SOC 2, PCI-DSS, HIPAA — contextual guidance
- Mapping of regulatory obligations
- Prioritised remediation recommendations
Detection Engineering
- Generation of tailored Sigma and YARA rules
- SIEM query optimisation (Splunk, Elastic)
- Natural-language threat hunting (French + English)
- False-positive analysis and rule tuning
Total sovereignty
- Hosted in the Unitel datacentres — Marseille
- No data ever leaves French soil
- Zero dependency on AWS, Azure, GCP or OpenAI
- Outside the scope of the US Cloud Act
- Meets the SecNumCloud requirements
Real-time analysis pipeline
From raw event to response action — every step automated and enriched by the 80-billion-parameter SYLink AI.
Multi-source correlation
- DPI × EDR — Network and endpoint cross-referenced for every host
- Real-time CTI — 12M+ IOCs queried on every outbound connection
- UEBA — Behavioural baseline per user and per machine
- Sigma/YARA — 100,000+ rules evaluated on every EDR event
- Kill chain — Automatic multi-stage MITRE ATT&CK reconstruction
Detection capabilities
- 80+ MITRE techniques — Automated coverage across 14 ATT&CK tactics
- Beacon C2 — Detection of periodic C2 communications (timing)
- DNS/ICMP tunneling — Analysis of legitimate protocols abused for exfiltration
- Shadow IT / Shadow AI — Real-time mapping of unauthorised applications
- Lateral movement — SMB, RDP, Pass-the-Hash and Golden Ticket detection
Measured performance
Metrics from production deployments — real data on Unitel infrastructure.
Detection engine
Volume handled in production
SYLink AI in action
Real queries — click to see the answers.
The brain of UniSOC
The 80-billion-parameter SYLink AI is the engine at the centre of the UniSOC platform — it powers every analysis, investigation and automated response feature.
- Automatic alert triage with a plain-language explanation
- Natural-language threat hunting — ask in French or in English
- Cross EDR×DPI investigation — automatic kill chain reconstruction
- NIS2, GDPR and DORA compliance reports generated on demand
- Remediation recommendations set in the context of your own infrastructure
- SOC voice assistant — real-time security briefing
The 80-billion-parameter SYLink AI runs entirely inside the Unitel datacentres in Marseille. No external API call, no data passed to a third party. Your logs, alerts and incidents stay in your sovereign space.
vs. the alternatives
Frequently asked questions — SYLink AI
Performance, hallucination, DORA compliance, GPUs: everything a CISO should know before auditing a SOC LLM.