Saolix Technologies · Threat Intelligence Solutions

Saolix Shield. Security signals into governed action.

Cyber security for institutions that must answer for every response. Shield is being built to bring signals together, show the attack path, and make sure no action is taken outside approved policy.

In development The simulator, sample report and images show the planned design, with fictional data.

01 · Claim

Designed so that no security response happens without a policy that allows it and a record that proves it.

02 · Story

Security teams run many tools, and each one sees part of an attack. The warning signs sit in separate consoles: a strange login, an unusual network route, a new admin role, a large download. Shield is being built to bring identity, network, endpoint and cloud signals into one timeline and show how they connect. An AI copilot will explain the likely attack path. Responses such as disabling a session or isolating a host will run only under approved policy, and each one will be recorded for audit.

03 · Chain

AI explains the attack. Policy controls the response.

Shield is designed on the same principle as Eagle: AI can correlate and explain, but only approved policy acts.

The Shield decision chain: security signals, AI correlation and explanation, the determinism boundary, a policy-controlled response, and a sealed audit record SHIELD · DECISION CHAIN Signalsidentity · network · cloud AI assistscorrelate · explain Responseapproved policy Sealed auditevery action kept AI ASSISTS · PROBABILISTIC POLICY DECIDES · DETERMINISTIC DETERMINISM BOUNDARY
Illustrative concept of a Shield incident: identity, network, endpoint and cloud events on one timeline are linked into an attack path; the copilot explains it and the response to disable the session waits for policy approval SAOLIX SHIELD · INCIDENT S-0932 ILLUSTRATIVE CONCEPT ONE TIMELINE · FOUR SOURCES IdentityNetworkEndpointCloud 02:14 repeated MFA prompts 02:31 new route 02:40 admin role added 03:05 bulk storage read 02:0002:3003:0003:30 correlated attack path ATTACK PATH MFA fatigue on user j.sample Session from new network route Privilege escalation to admin Bulk read of customer storage COPILOT EXPLANATION Four events in 51 minutes that no single tool would flag on its own. Together they match an account takeover followed by data staging. Suggested response: disable session. advisory only · cannot take action POLICY GATE Disable session · policy P-07 requires one approver · audit row sealed Approve Reject

Illustrative concept: how a Shield incident is designed to look. All names and identifiers are fictitious.

04 · Capabilities

What Shield is being built to do.

01

Unified visibility

Will put identity, network, endpoint and cloud events on one timeline, instead of four consoles.

one timeline · many sources
02

Attack-path context

Will link events that no single tool would flag on their own, and show how they connect into one attack.

correlation · sequence
03

Agentic security copilot

Will explain the likely attack path and suggest a response in plain language, grounded in the events.

advisory · never acts
04

Policy-controlled response

Every response will run only under approved policy, with approvals where required, and be recorded for audit.

zero trust · sealed audit
05 · Deployment

Designed for your infrastructure.

Shield is designed to follow the same deployment model as Eagle.

On-premise or hybridDesigned to run inside your environment, with the evidence kept on your side for data residency.
Local AIThe copilot is designed to run on a locally hosted model, with no data sent to an external AI service.
Customer-controlledYour policies, your approvers, your audit trail.
Contact · Saolix GroupPeople. Products. Possibilities.

Your next chapter.
Let’s build it together.

Explore a product, discuss a project, or find the right expertise. Tell us where you want to go. We’ll help you take the next step.

Enterprise softwarePrivate AIEngineering & consulting