Saolix Shield. Security signals into governed action.
Cyber security for institutions that must answer for every response. Shield is being built to bring signals together, show the attack path, and make sure no action is taken outside approved policy.
In development The simulator, sample report and images show the planned design, with fictional data.
Designed so that no security response happens without a policy that allows it and a record that proves it.
Security teams run many tools, and each one sees part of an attack. The warning signs sit in separate consoles: a strange login, an unusual network route, a new admin role, a large download. Shield is being built to bring identity, network, endpoint and cloud signals into one timeline and show how they connect. An AI copilot will explain the likely attack path. Responses such as disabling a session or isolating a host will run only under approved policy, and each one will be recorded for audit.
AI explains the attack. Policy controls the response.
Shield is designed on the same principle as Eagle: AI can correlate and explain, but only approved policy acts.
Illustrative concept: how a Shield incident is designed to look. All names and identifiers are fictitious.
What Shield is being built to do.
Unified visibility
Will put identity, network, endpoint and cloud events on one timeline, instead of four consoles.
one timeline · many sourcesAttack-path context
Will link events that no single tool would flag on their own, and show how they connect into one attack.
correlation · sequenceAgentic security copilot
Will explain the likely attack path and suggest a response in plain language, grounded in the events.
advisory · never actsPolicy-controlled response
Every response will run only under approved policy, with approvals where required, and be recorded for audit.
zero trust · sealed auditDesigned for your infrastructure.
Shield is designed to follow the same deployment model as Eagle.
Explore the design. Inspect it.
Shield is in development, starting with its policy and access-control foundation. The concept simulator and sample report show how it is designed to work.
Shield Concept Simulator
Work four fictional incidents: see the four-source timeline, the attack path, the policy gate, and approve a response yourself. A response no policy covers is refused.
Open the simulator ↗ Download · PDF · conceptSample incident report
The planned Incident Response Report for a fictional account takeover: timeline, attack path, policy gate, approval and audit log.
Download the sample → BriefingDesign walkthrough
How Shield would sit in your environment, and where the determinism boundary sits.
Request a briefing →Further reading.
Your next chapter.
Let’s build it together.
Explore a product, discuss a project, or find the right expertise. Tell us where you want to go. We’ll help you take the next step.