QE-Secure is the ANSSI qualified, 100% on-premises Network Detection and Response platform engineered by Allentis, a Framatome company. It analyzes 100% of your traffic in real time, from 1 to 100 Gbps, turning raw packets into contextualized security events for real-time threat detection. No cloud dependency. No foreign jurisdiction. No compromise.
Choosing a Network Detection and Response platform is a strategic network security decision, not a commodity purchase. It determines whether your most sensitive operational data stays under your exclusive control, or transits through an external cloud governed by extraterritorial law.
The detection intelligence and every stage of analysis run entirely inside your own infrastructure. Not a single byte of data or metadata is ever sent to an external cloud. This is the reason QE-Secure stands out for OIV and OSE (operators of vital importance and essential service operators) and government bodies, as well as for any organization determined to keep exclusive control of its data.
QE-Secure inspects 100% of traffic in real time up to 100 Gbps with no sampling, reconstructs full attack chains, maps detections to MITRE ATT&CK, and keeps investigation latency low through advanced indexing.
QE-Secure carries an ANSSI qualification, obtained through direct collaboration with the agency within the framework of the French Military Programming Law. Far more than a regulatory requirement, this qualification is a mark of reliability that every organization benefits from: it certifies that the highest level of performance is achieved without ever offloading your data. Designed, developed, manufactured and supported in France.
*Up to 99.99% false positive elimination depending on the detection context, powered by the MIND AI engine.
For years, security relied on the fortress model: high walls at the perimeter and strict control of who came in. That model is now obsolete. Attackers are frequently already inside, having entered through a phishing email, an infected USB device, a compromised supplier, or a vulnerable connected asset.
A firewall blocks unauthorized traffic. An EDR neutralizes known threats on an endpoint. But neither can see an attacker moving laterally with stolen credentials, nor unknown malware that matches no signature, nor the East-West communications between servers inside your own data center. This blind spot is precisely where QE-Secure operates.
An NDR probe analyzes the entirety of your network traffic, and the resulting metadata can reveal how your organization operates, where your trade secrets live, and where your vulnerabilities are. Entrusting that intelligence to a provider subject to extraterritorial regulations such as the US Cloud Act creates a permanent risk of leakage and a loss of sovereignty that cannot be undone.
QE-Secure removes that risk entirely. The AI, the detection engines, the correlation, the indexing and the storage all run on your infrastructure, inside your enclaves. This is what makes QE-Secure the natural choice for OIV and OSE, defense, energy, transport and industry, and more broadly for any organization looking for a high-performance NDR that keeps its data under control.
Delivered as ready-to-use appliances, hardened at every layer for deployment in the most sensitive environments.
A hardened Debian operating system with strict compartmentalization enforced through micro-programs, reducing the attack surface and isolating critical functions.
Three complementary engines combined: the proprietary MIND event engine, the Suricata signature and protocol engine, and the Yara pattern-matching engine. Known and unknown threats, together.
Appliances with 1 to 4 acquisition interfaces, connected to a traffic aggregator or directly to a TAP. Full-stream analysis in real time, with no sampling.
MIND AI is the artificial intelligence engine developed in-house by Allentis, and it is the reason QE-Secure delivers a signal-to-noise ratio that analysts trust. It operates in two complementary modes.
Supervised mode performs behavioral analysis of network and application assets, learning what normal interaction looks like and flagging deviations. Unsupervised mode surfaces anomalies with no predefined rules, generating an independent family of alerts that exists outside traditional signature logic.
Every view in the platform is dynamically linked to every other view. An analyst can move from a summary dashboard to an event list, to an attack chain map, to a fully detailed event, and back again without losing context. Filtering choices and detection strategies propagate across the entire interface.
MIND AI alerts, majors, warnings and informational events consolidated in one view, with top victims and top offenders surfaced instantly.
A radar view and a detection map give an immediate visual grasp of where threats concentrate and how they propagate across your assets.
Recurring hunts such as potential data exfiltration, suspicious user agents or Log4j-related events become one-click investigation and incident response strategies.
Reconnaissance, initial access, execution, persistence, privilege escalation, lateral movement, command and control, exfiltration and impact, all mapped.
Detected exploit attempts are correlated with the assets under attack and reconstructed into a step-by-step attack sequence.
Source, destination, timestamps, protocols, HTTP metadata, flow data, byte and packet counts, file hashes and GeoIP down to organization and ASN.
QE-Secure is built around two components. The QESEC probes acquire and analyze traffic. The QEMAN manager centralizes supervision, connects to probes through secure VPN tunnels, and is accessible from a browser by authorized personnel only.
Depending on its version, a single manager supports up to 30 probes, based on the intensity of the security event flow. QE-Secure operates fully autonomously or integrates natively into an existing SOC, feeding a SIEM through standard outputs including syslog, Lumberjack and dedicated event streaming.
The dominant NDR platforms are powerful, but almost all share the same structural weakness: they rely on a cloud back end operated under foreign jurisdiction. QE-Secure answers every concern at once.
| Criterion | QE-Secure | US cloud NDR | Zeek-based / log tooling |
|---|---|---|---|
| Data sovereignty | 100% on-premises | Cloud Act exposure | Depends on setup |
| AI processing location | On your infrastructure | External cloud | Not integrated |
| National certification | ANSSI qualified | None (EU) | None |
| Real-time throughput | Up to 100 Gbps | High | High |
| Transparency of alerts | Explainable + AI | Black box | Raw logs |
| Turnkey investigation UI | Fully integrated | Yes | Requires build |
| Licensing model | Perpetual, no forced fee | Recurring subscription | Variable |
Comparison reflects the architectural positioning of QE-Secure against common NDR categories, based on publicly documented characteristics.
Identifies suspicious behavior, lateral movement, command and control, ransomware activity, and data exfiltration at the closest point to the network, producing contextualized events.
Native IT, OT and IoT visibility protects industrial and critical infrastructures across East-West and North-South flows in sensitive networks.
Runs standalone or connects to your existing SIEM and SOAR tools, centralizing enriched detection events in established workflows.
MIND AI prioritizes the alerts that matter, cuts operational noise and shortens qualification time, directly addressing analyst fatigue.
Dynamically linked views trace an intrusion from origin to spread, confirming complete eradication in a fast, repeatable process.
ANSSI qualification and a fully on-premises architecture support LPM, GDPR and the confidentiality demands of vital and sensitive sectors.
QE-Secure and the Allentis QE suite are deployed by large enterprises and state organizations that operate under the highest security standards, across telecommunications, energy, banking, space and government.
QE-Secure gives you sovereign, high-performance, ANSSI qualified Network Detection and Response, with intelligence that runs entirely on your own infrastructure. See it in action on your own environment.