Defence in depth
A tool that protects others cannot be a weakness itself. That is why we hold BALLA to the same standard we sell: every communication is encrypted and mutually authenticated, every command is cryptographically signed, every sensitive action is written to a tamper-proof log. Protection is organised into three criticality tiers, P0, P1, P2, to prioritise without ever neglecting.
Phishing remains the number-one entry point for attacks. Our dedicated service analyses every message with an escalation logic: the more ambiguous a signal, the more it is handed up to an intelligent layer. Detection is natively bilingual French + English, a product requirement for multilingual environments. And it is privacy-first: no email body is stored, learning relies on public datasets and opt-in, and the service runs offline.
The first line rests on verifiable, explainable signals: spelling mistakes, lookalike domains via typosquatting, URL features (ephemeral tunnels, dynamic DNS), SPF / DKIM / DMARC authentication, business-email-compromise (BEC) patterns and dangerous attachments. Fast, transparent, and effective on the majority of cases.
For subtler messages, a fine-tuned multilingual transformer (mDeBERTa / XLM-R) analyses the meaning of the text, not just its form. A lightweight lexical backend stays as a permanent fallback: the service is therefore always available, including offline or in air-gapped environments.
For the most complex or novel cases, the BALLA-LLM cognitive layer produces a natural-language explanation of why a message is deemed dangerous, zero-shot, with no prior example. The analyst understands, decides, and saves time.
Release signing
Every BALLA package is signed with the SISKO key below. Verify it on the downloaded archive, before extracting it.
7F6D 89BF C337 02BE 035F 00B1 1281 DCB2 2053 70C0
Ed25519 · key 1281DCB2205370C0 · SISKO Releases <maksissoko07@gmail.com>
Only trust the key if its fingerprint matches this value EXACTLY — cross-check it against an independent channel (a public key server). A key fetched from the same place as the archive proves nothing if the server is compromised.
# Sur l'archive téléchargée, AVANT de l'extraire :
gpg --import sisko-releases-pubkey.asc
gpg --fingerprint 1281DCB2205370C0 # doit afficher l'empreinte ci-dessus
gpg --verify SHA256SUMS.txt.asc SHA256SUMS.txt # authenticité
shasum -a 256 -c SHA256SUMS.txt # intégrité (macOS)
sha256sum -c SHA256SUMS.txt # intégrité (Linux)Privacy by design: only what detection needs, nothing more.
Automated decisions are made explainable by SHAP, with a guaranteed right to human review on sensitive cases.
Fully on-premise deployable, down to a completely disconnected air-gapped mode, for the most demanding sovereign clients.
Every sensitive action is written to a Merkle-style chained, signed log: any attempt at later modification is immediately detectable.
mTLS everywhere between components: no service trusts another by default, even inside the system.