Autonomous SOC platformWhere traditional tools wait to recognise an already-catalogued threat, BALLA learns each machine's normal behaviour, detects the slightest deviation, known or entirely new, contextualises it against global threat intelligence, then executes a proportionate, fully traceable response. All within milliseconds, and with no human in the loop for standard cases.
Known and unknown attacks · Every decision explained · Sovereign data · Sovereign deployment
Building the intelligence of the future.
A real product, not a promise
The principle
Three promises, kept in a continuous loop, machine by machine, with no day off. It is this sequence, detect, then understand, then act, that separates genuine autonomous cybersecurity from just another alerting tool.
Signatures only catch what's already known. BALLA learns each endpoint's normal, programs, hours, networks, sequences, and flags the slightest deviation, including the targeted, never-seen attacks that do the most damage.
An anomaly score is not a decision. Every threat is cross-referenced with CVE, MITRE ATT&CK and malware intelligence, then explained in plain language. From score to verdict.
Understanding without acting is arriving too late. BALLA blocks, isolates, kills or quarantines in a fraction of a second, faster than any human team, with human sign-off on the calls that matter.
Who it's for
Sectors where an intrusion costs millions, trust, or lives. BALLA learns each one's own behaviour and adapts to it.
Fraud, exfiltration, ransomware: catch the abnormal before it reaches the accounts.
Sprawling networks, millions of subscribers: a vast attack surface, covered continuously.
Sensitive citizen data and sovereignty: protection you control, hostable locally.
Patient records and connected devices: availability and confidentiality, no compromise.
Enterprise-grade security, at a fraction of the cost and with no dedicated SOC team.
Endpoints, servers and, tomorrow, industrial systems: coverage that grows with you.
The pipeline
Every event follows exactly the same fully decoupled path: no layer calls the next one directly, everything flows through a message bus. This architecture guarantees three things at once, resilience (an isolated failure doesn't bring down the chain), end-to-end traceability (every decision links back to its source event), and controlled latency around 150 ms at the 99th percentile.
A lightweight agent watches 28+ event families on each endpoint, cryptographically signed, and buffers locally, encrypted, if the network drops.
A decoupled Apache Kafka bus moves events resiliently, tens of thousands per second, keeping every machine's events in order.
The BALLA brain tells normal from abnormal without knowing the threat in advance, catching real attacks without drowning teams in false alarms.
Every alert is qualified by threat intelligence: CVE, malware family, MITRE ATT&CK technique, reputation, cross-machine correlation. A score becomes a diagnosis.
The decision becomes a signed action (Ed25519), reversible and fully audited, with human sign-off for the most sensitive calls.
Under the hood
Most solutions rely on a single model, and that model either misses too many threats or raises too many false alarms. BALLA takes the opposite stance: a stack of specialised, complementary layers, where each has one responsibility, defined interfaces, and covers the others' blind spots. It is this depth of defence that simultaneously reduces missed threats and false alarms.
Online, signature-free learning that spots statistical deviation the instant it happens. The first line of defence against the unknown.
Compares each activity to the machine's and role's own profile, calibrated over 14 days. A server's normal is not a designer's.
Reads the chain of actions and catches the abuse of trusted tools, like Word spawning PowerShell to download a payload.
Trained on analyst corrections, it separates true threats from unusual-but-legitimate behaviour, and sharpens with every use.
Picks the best response under strict guardrails, never on critical systems without sign-off. Driven by reinforcement learning, it improves with every incident.
Unlike an impossible-to-understand black box, BALLA justifies every decision: the XAI / SHAP method shows exactly which factors weighed in, and by how much. This transparency matters on two counts, team trust, since they see why an alert was raised, and GDPR compliance (Article 22) on automated decisions.
Performance
In cybersecurity, speed isn't a luxury: it's the difference between blocking an attack and suffering it. Here are the production targets we aim for and measure continuously, from decision time to false-alarm rate.
Defence in depth
A tool that protects others cannot be a weakness itself. That is why we hold BALLA to the same standard we sell: every communication is encrypted and mutually authenticated, every command is cryptographically signed, every sensitive action is written to a tamper-proof log. Protection is organised into three criticality tiers, P0, P1, P2, to prioritise without ever neglecting.
Phishing remains the number-one entry point for attacks. Our dedicated service analyses every message with an escalation logic: the more ambiguous a signal, the more it is handed up to an intelligent layer. Detection is natively bilingual French + English, a product requirement for multilingual environments. And it is privacy-first: no email body is stored, learning relies on public datasets and opt-in, and the service runs offline.
The first line rests on verifiable, explainable signals: spelling mistakes, lookalike domains via typosquatting, URL features (ephemeral tunnels, dynamic DNS), SPF / DKIM / DMARC authentication, business-email-compromise (BEC) patterns and dangerous attachments. Fast, transparent, and effective on the majority of cases.
For subtler messages, a fine-tuned multilingual transformer (mDeBERTa / XLM-R) analyses the meaning of the text, not just its form. A lightweight lexical backend stays as a permanent fallback: the service is therefore always available, including offline or in air-gapped environments.
For the most complex or novel cases, the BALLA-LLM cognitive layer produces a natural-language explanation of why a message is deemed dangerous, zero-shot, with no prior example. The analyst understands, decides, and saves time.
Attack reconstruction
An attack is almost never an isolated event, but a sequence. BALLA reconstructs it end-to-end and, with BALLA-LLM, reveals in plain language the MITRE ATT&CK techniques used.
Which program launched which other, the causal root of the chain.
Same file, same address, same fingerprint across several endpoints.
Consistency with the logical flow of an attack per ATT&CK.
“A phishing email delivered an encoded PowerShell script that dumped credentials, spread over SMB to 3 endpoints, opened a command-and-control beacon, then triggered encryption. A typical human-operated ransomware pattern.”
Progression along MITRE ATT&CK
BALLA-LLM highlights the ATT&CK techniques that recur most across incidents, to anticipate the likely next move.
Why BALLA
We bring together what classic approaches keep apart: accessibility, personalisation, transparency and full control over your data. Here, criterion by criterion, is the difference.
Cost
BALLADetection
BALLAResponse
BALLAPersonalisation
BALLATransparency
BALLASovereignty
BALLAPricing
Our model is simple and proven by the greatest tech successes: a free, open base that builds trust and adoption, then revenue on advanced features, autonomous response and support. From the open-source community to the sovereign institution, everyone finds the level that fits their stakes and their means.
The endpoint agent and core detection layers, open and auditable. Built for the community, research, small organisations and anyone who wants to verify for themselves that there is no backdoor and no hidden data collection.
The full platform: all AI layers, the real-time SOC cockpit, threat enrichment, response and remediation, with standard to 24/7 support. For banks, telecoms, administrations and SMBs that want genuine autonomous cybersecurity.
For governments, defence and critical infrastructure: mandatory 100% local hosting, full source-code audit, completely disconnected air-gapped mode, dedicated SLA and support. Digital sovereignty with no compromise.
Indicative pricing for SMBs and large enterprises is shared on request, in FCFA or euros.
FAQ
Answers to what comes up before getting started.
An antivirus recognises what it already knows. BALLA learns each endpoint's normal behaviour and detects the anomaly, meaning the new or targeted attack that no signature covers.
It detects, decides and can execute proportionate responses, under strict guardrails. The most sensitive decisions and critical systems always keep a human in the loop.
Not if you don't want it to. BALLA can be deployed fully on your side, down to a completely disconnected air-gapped mode. You keep control, wherever you choose.
BALLA learns an endpoint's normal behaviour in about two weeks. Reference profiles avoid cold start and make detection useful from day one.
Windows, macOS and Linux, via a lightweight agent that installs in minutes per endpoint, without disrupting the user.
That is exactly what the multi-level architecture and supervised filtering are built to avoid. The goal is clear: fewer false alarms, never more.
Twenty minutes is all it takes to grasp what changes when an AI learns, decides and acts, with your data staying under your control.