Blog & Research
Our articles on AI detection, digital sovereignty and the engineering of BALLA.
We applied to phishing detection the same uncompromising protocol we use for network anomalies: measure without leakage, on hard cases held strictly out of training. A public F1 of 0.99 turned out to be a mirage; a model trained on sovereign, diverse data reaches strong performance on our internal benchmark, which we label honestly for what it is.
We evaluated the Autoencoder + Isolation Forest architecture on CICIDS2017 under a leakage-free protocol. The result: modest real performance, a non-linear reduction that does not beat PCA, and a drift in benign traffic that invalidates any fixed threshold.
A compromised security system is the worst-case scenario. Here is how SISKO protects itself, to the same standard it applies to everyone else.
An AI that decides without being able to justify itself has no place in cybersecurity. Here's how BALLA makes every alert readable, and why that's non-negotiable.
Detection alone isn't enough. Here is how BALLA turns a raw signal into a signed, executed decision, faster than the blink of an eye.
Antivirus recognises what it already knows. To stop never-seen attacks, you must learn normal behaviour, and measure the deviation.
A single model either misses too many threats or raises too many false alarms. The answer: specialised, complementary layers.
Protecting a nation's digital life with tools it does not control is not sovereignty. Here is our stance.