Saolix Technologies · Threat Intelligence Solutions

Saolix Shield. AI threat intelligence and hunting.

A professional cyber security platform for institutions that must answer for every response. Shield is being built to combine threat intelligence with your own signals, help your analysts hunt for attackers with AI, show the attack path, and make sure no action is taken outside approved policy.

Pre-release The simulator, sample report and images show the planned design, with fictional data.

01 · Claim

Designed so that no security response happens without a policy that allows it and a record that proves it.

02 · Story

Security teams run many tools, and each one sees part of an attack. The warning signs sit in separate consoles: a strange login, an unusual network route, a new admin role, a large download. Shield is being built to bring identity, network, endpoint and cloud signals into one timeline and show how they connect. An AI copilot will explain the likely attack path. Responses such as disabling a session or isolating a host will run only under approved policy, and each one will be recorded for audit.

03 · Chain

AI explains the attack. Policy controls the response.

Shield is designed on the same principle as Eagle: AI can correlate and explain, but only approved policy acts.

The Shield decision chain: security signals, AI correlation and explanation, the determinism boundary, a policy-controlled response, and a sealed audit record SHIELD · DECISION CHAIN Signalsidentity · network · cloud AI assistscorrelate · explain Responseapproved policy Sealed auditevery action kept AI ASSISTS · PROBABILISTIC POLICY DECIDES · DETERMINISTIC DETERMINISM BOUNDARY
Illustration of a Shield incident: identity, network, endpoint and cloud events on one timeline are linked into an attack path; the copilot explains it and the response to disable the session waits for policy approval SAOLIX SHIELD · INCIDENT S-0932 ILLUSTRATION ONE TIMELINE · FOUR SOURCES IdentityNetworkEndpointCloud 02:14 repeated MFA prompts 02:31 new route 02:40 admin role added 03:05 bulk storage read 02:0002:3003:0003:30 correlated attack path ATTACK PATH MFA fatigue on user j.sample Session from new network route Privilege escalation to admin Bulk read of customer storage COPILOT EXPLANATION Four events in 51 minutes that no single tool would flag on its own. Together they match an account takeover followed by data staging. Suggested response: disable session. advisory only · cannot take action POLICY GATE Disable session · policy P-07 requires one approver · audit row sealed Approve Reject

Illustration: how a Shield incident is designed to look. All names and identifiers are fictitious.

04 · Capabilities

What Shield is being built to do.

01

Unified visibility

Will put identity, network, endpoint and cloud events on one timeline, instead of four consoles.

one timeline · many sources
02

Attack-path context

Will link events that no single tool would flag on their own, and show how they connect into one attack.

correlation · sequence
03

Agentic security copilot

Will explain the likely attack path and suggest a response in plain language, grounded in the events.

advisory · never acts
04

Policy-controlled response

Every response will run only under approved policy, with approvals where required, and be recorded for audit.

zero trust · sealed audit
05

Threat intelligence

Will bring in the threat intelligence feeds you choose and match known indicators and attacker techniques against your own events, so a known threat is recognised the moment it appears.

feeds you choose · indicators · techniques
06

AI-assisted threat hunting

Will let analysts search the whole timeline for attackers no alert has caught, with the copilot proposing hunts and explaining what it finds. Hunts inform; policy still controls every response.

proactive hunts · advisory AI
05 · Deployment

Designed for your infrastructure.

Shield is designed to follow the same deployment model as Eagle.

Shield system overview, pre-release, target design: Shield is being built as an AI threat intelligence and threat hunting platform. Your identity, network, endpoint and cloud tools are designed to send their events to Shield, and threat intelligence feeds you choose are designed to be matched against them. Shield is designed to run inside your environment, on-premise or hybrid. It is designed to put events and intelligence on one timeline, let threat hunters search across it and link events into attack paths, and have an AI security copilot, running on a locally hosted model, propose hunts, explain the likely attack path and suggest a response. The copilot is advisory and never acts. Below the determinism boundary, responses such as disabling a session or isolating a host are designed to run only under approved policy, with approvals from your security team where policy requires them, and every response is designed to be recorded for audit, with the evidence kept on your side. Responses are designed to be applied to your sessions and hosts. No external AI service is designed to be used. SHIELD · SYSTEM OVERVIEW decision path AI · advisory you configure PRE-RELEASE · TARGET DESIGN YOUR PEOPLE & SYSTEMS OUTSIDE SHIELD INSIDE YOUR ENVIRONMENT · ON-PREMISE OR HYBRID Your security tools identity · network endpoint · cloud events Threat hunters proactive hunts Security team approvers · responders Shield Threat intelligence & one timeline Threat hunting & attack paths AI security copilot Policy-controlled response Approvals Sealed audit record your events matched with intelligence feeds hunt across the timeline · link events into one attack proposes hunts · explains · suggests · never acts disable a session · isolate a host where policy requires them every response recorded · evidence stays on your side DETERMINISM BOUNDARY · AI EXPLAINS, POLICY ACTS Local AI locally hosted model Policies you own policies · approvers Threat intelligence feeds feeds you choose External AI services not used Sessions and hosts responses applied

Target design of a pre-release product. It shows how Shield, an AI threat intelligence and threat hunting platform, is designed to work, not a released product.

On-premise or hybridDesigned to run inside your environment, with the evidence kept on your side for data residency.
Local AIThe copilot is designed to run on a locally hosted model, with no data sent to an external AI service.
Customer-controlledYour policies, your approvers, your audit trail.
Contact · Saolix GroupPeople. Products. Possibilities.

Your next chapter.
Let’s build it together.

Explore a product, discuss a project, or find the right expertise. Tell us where you want to go. We’ll help you take the next step.

Enterprise softwarePrivate AIEngineering & consulting