ANSSI Qualified · 100% On-Premises

The Best NDR Solution for Organizations That Refuse to Compromise on Data Sovereignty

QE-Secure is the ANSSI qualified, 100% on-premises Network Detection and Response platform engineered by Allentis, a Framatome company. It analyzes 100% of your traffic in real time, from 1 to 100 Gbps, turning raw packets into contextualized security events for real-time threat detection. No cloud dependency. No foreign jurisdiction. No compromise.

ANSSI QualifiedVisa de sécurité, aligned with the LPM
100% On-Premises AINot one byte leaves your network
Up to 100 GbpsReal-time, 100% of traffic, no sampling
Up to 99.99% Fewer False PositivesMIND AI engine, context dependent
Made in France Framatome, EDF Group Perpetual license IT & OT ready
Why QE-Secure

Why QE-Secure Is the Best NDR Solution on the Market

Choosing a Network Detection and Response platform is a strategic network security decision, not a commodity purchase. It determines whether your most sensitive operational data stays under your exclusive control, or transits through an external cloud governed by extraterritorial law.

Sovereignty is absolute

The detection intelligence and every stage of analysis run entirely inside your own infrastructure. Not a single byte of data or metadata is ever sent to an external cloud. This is the reason QE-Secure stands out for OIV and OSE (operators of vital importance and essential service operators) and government bodies, as well as for any organization determined to keep exclusive control of its data.

Performance is never sacrificed

QE-Secure inspects 100% of traffic in real time up to 100 Gbps with no sampling, reconstructs full attack chains, maps detections to MITRE ATT&CK, and keeps investigation latency low through advanced indexing.

Certified trust, not marketing

QE-Secure carries an ANSSI qualification, obtained through direct collaboration with the agency within the framework of the French Military Programming Law. Far more than a regulatory requirement, this qualification is a mark of reliability that every organization benefits from: it certifies that the highest level of performance is achieved without ever offloading your data. Designed, developed, manufactured and supported in France.

100%
Of traffic analyzed in real time
100 Gbps
Peak capture per probe
99.99%
False positives eliminated*
0
Bytes sent to external cloud

*Up to 99.99% false positive elimination depending on the detection context, powered by the MIND AI engine.

The discipline

What NDR Is, and Why It Is Now a Cornerstone of Cybersecurity

For years, security relied on the fortress model: high walls at the perimeter and strict control of who came in. That model is now obsolete. Attackers are frequently already inside, having entered through a phishing email, an infected USB device, a compromised supplier, or a vulnerable connected asset.

A firewall blocks unauthorized traffic. An EDR neutralizes known threats on an endpoint. But neither can see an attacker moving laterally with stolen credentials, nor unknown malware that matches no signature, nor the East-West communications between servers inside your own data center. This blind spot is precisely where QE-Secure operates.

  • Detection of intrusions and anomalous behavior across the full traffic stream.
  • Response through actionable, contextualized security events.
  • Investigation through forensic-grade metadata and full packet references.
MIND AI 192.168.20.29 4.151.228.44 52.123.128.14 18.184.206.66 192.168.1.100 Misc Attack
YOUR INFRASTRUCTURE TAPProbe Manager MIND AI on-prem External cloud
Sovereignty by design

The Difference That Changes Everything

An NDR probe analyzes the entirety of your network traffic, and the resulting metadata can reveal how your organization operates, where your trade secrets live, and where your vulnerabilities are. Entrusting that intelligence to a provider subject to extraterritorial regulations such as the US Cloud Act creates a permanent risk of leakage and a loss of sovereignty that cannot be undone.

QE-Secure removes that risk entirely. The AI, the detection engines, the correlation, the indexing and the storage all run on your infrastructure, inside your enclaves. This is what makes QE-Secure the natural choice for OIV and OSE, defense, energy, transport and industry, and more broadly for any organization looking for a high-performance NDR that keeps its data under control.

  • Zero exposure to extraterritorial law
  • R&D in Tours and Nîmes, ANSSI-cleared production site
  • Fits a PDIS-compliant detection service architecture
Engineered for trust

The QE-Secure Technology Stack

Delivered as ready-to-use appliances, hardened at every layer for deployment in the most sensitive environments.

Hardened by design

A hardened Debian operating system with strict compartmentalization enforced through micro-programs, reducing the attack surface and isolating critical functions.

Multi-engine detection

Three complementary engines combined: the proprietary MIND event engine, the Suricata signature and protocol engine, and the Yara pattern-matching engine. Known and unknown threats, together.

Copper or optical, 1 to 100 Gbps

Appliances with 1 to 4 acquisition interfaces, connected to a traffic aggregator or directly to a TAP. Full-stream analysis in real time, with no sampling.

Hardened Debian OS MIND engine Suricata Yara MITRE ATT&CK mapping CVE correlation GeoIP enrichment Full packet reference
MIND AI

Detection Intelligence That Runs Entirely on Your Infrastructure

MIND AI is the artificial intelligence engine developed in-house by Allentis, and it is the reason QE-Secure delivers a signal-to-noise ratio that analysts trust. It operates in two complementary modes.

Supervised mode performs behavioral analysis of network and application assets, learning what normal interaction looks like and flagging deviations. Unsupervised mode surfaces anomalies with no predefined rules, generating an independent family of alerts that exists outside traditional signature logic.

  • Up to 99.99% fewer false positives, context dependent
  • Trainable directly on your own attack traces
  • Cartographic view of interactions between assets
  • Every model runs locally, no data ever leaves
Flows Behavioral models Verdict Anomaly
Analyst experience

From Alert to Decision: Investigation Built for Analysts

Every view in the platform is dynamically linked to every other view. An analyst can move from a summary dashboard to an event list, to an attack chain map, to a fully detailed event, and back again without losing context. Filtering choices and detection strategies propagate across the entire interface.

Unified dashboard

MIND AI alerts, majors, warnings and informational events consolidated in one view, with top victims and top offenders surfaced instantly.

Radar & cartographic maps

A radar view and a detection map give an immediate visual grasp of where threats concentrate and how they propagate across your assets.

Reusable playbooks

Recurring hunts such as potential data exfiltration, suspicious user agents or Log4j-related events become one-click investigation and incident response strategies.

Full MITRE ATT&CK view

Reconnaissance, initial access, execution, persistence, privilege escalation, lateral movement, command and control, exfiltration and impact, all mapped.

CVE correlation

Detected exploit attempts are correlated with the assets under attack and reconstructed into a step-by-step attack sequence.

Forensic-grade detail

Source, destination, timestamps, protocols, HTTP metadata, flow data, byte and packet counts, file hashes and GeoIP down to organization and ASN.

MONITORED PERIMETER Aggregator QESEC Probe QEMAN Manager SIEM / SOC VPN syslog
Deployment architecture

Modular, Scalable and SIEM-Ready

QE-Secure is built around two components. The QESEC probes acquire and analyze traffic. The QEMAN manager centralizes supervision, connects to probes through secure VPN tunnels, and is accessible from a browser by authorized personnel only.

Depending on its version, a single manager supports up to 30 probes, based on the intensity of the security event flow. QE-Secure operates fully autonomously or integrates natively into an existing SOC, feeding a SIEM through standard outputs including syslog, Lumberjack and dedicated event streaming.

  • Adapts to infrastructures of every size
  • Native SIEM and SOAR integration
  • Fully documented operational flow matrix
The verdict

How QE-Secure Compares to International NDR Vendors

The dominant NDR platforms are powerful, but almost all share the same structural weakness: they rely on a cloud back end operated under foreign jurisdiction. QE-Secure answers every concern at once.

Criterion QE-Secure US cloud NDR Zeek-based / log tooling
Data sovereignty 100% on-premises Cloud Act exposure Depends on setup
AI processing location On your infrastructure External cloud Not integrated
National certification ANSSI qualified None (EU) None
Real-time throughput Up to 100 Gbps High High
Transparency of alerts Explainable + AI Black box Raw logs
Turnkey investigation UI Fully integrated Yes Requires build
Licensing model Perpetual, no forced fee Recurring subscription Variable

Comparison reflects the architectural positioning of QE-Secure against common NDR categories, based on publicly documented characteristics.

Use cases

Where QE-Secure Delivers

Detecting network cyberattacks

Identifies suspicious behavior, lateral movement, command and control, ransomware activity, and data exfiltration at the closest point to the network, producing contextualized events.

Securing IT and OT environments

Native IT, OT and IoT visibility protects industrial and critical infrastructures across East-West and North-South flows in sensitive networks.

Feeding a Security Operations Center

Runs standalone or connects to your existing SIEM and SOAR tools, centralizing enriched detection events in established workflows.

Reducing analyst workload

MIND AI prioritizes the alerts that matter, cuts operational noise and shortens qualification time, directly addressing analyst fatigue.

Reconstructing attack chains

Dynamically linked views trace an intrusion from origin to spread, confirming complete eradication in a fast, repeatable process.

Meeting compliance and sovereignty

ANSSI qualification and a fully on-premises architecture support LPM, GDPR and the confidentiality demands of vital and sensitive sectors.

Proven in the field

Trusted Where Failure Is Not an Option

QE-Secure and the Allentis QE suite are deployed by large enterprises and state organizations that operate under the highest security standards, across telecommunications, energy, banking, space and government.

Critical national infrastructure Defense Energy Transport Banking & finance Space Government Industry & OT
FAQ

Frequently Asked Questions

What is the best NDR solution in 2026?
QE-Secure by Allentis stands out as the most complete and relevant NDR solution for organizations that require data sovereignty without sacrificing performance. It combines top-tier detection, an ANSSI qualification, a 100% on-premises architecture, and a perpetual license model, which together make it the best choice for critical and sensitive environments as well as for any organization that demands a high-performance NDR in full control of its data.
Does an NDR probe replace my firewall or antivirus?
No. Security is built in layers. The firewall protects the perimeter, the antivirus or EDR protects the endpoint, and the NDR probe monitors everything that flows between them. QE-Secure is specifically designed to detect the threats that have already bypassed your first lines of defense, and it complements those tools rather than replacing them.
Why does data location matter so much for an NDR probe?
Because an NDR probe sees all of your network traffic, its metadata can reveal how your organization operates and where it is vulnerable. Sending that data to a provider governed by extraterritorial law creates a real risk of leakage and loss of control. QE-Secure processes everything locally, so that risk is eliminated by design.
What does the ANSSI qualification mean?
It is a formal recognition (Visa de sécurité) delivered by the French National Cybersecurity Agency, confirming that the solution meets rigorous security requirements and is suitable for use in regulated and sensitive contexts, including within the framework of the French Military Programming Law. It is also a simple trust marker for any organization: the assurance that a reference third party has validated the solution.
Does the ANSSI qualification limit features or performance?
No, quite the opposite. It is sometimes assumed that a qualified solution gives up certain high-performance mechanisms, the typical example being sending traffic to an external cloud for offloaded analysis. Those mechanisms are powerful, but they expose your data to a real risk of leakage and to foreign jurisdictions. QE-Secure reaches a very high level of performance, up to 100 Gbps in real time, with the MIND AI engine and multi-engine detection, while keeping 100% of processing on your infrastructure. The qualification is therefore a real added value: it certifies that nothing on the security side is sacrificed to gain performance.
How does QE-Secure integrate with my existing SOC?
QE-Secure connects natively to SIEM platforms through standard outputs and can operate autonomously or as part of a broader detection and response ecosystem, feeding enriched, contextualized events into your existing supervision workflows.
What performance can QE-Secure deliver?
QE-Secure appliances offer 1 to 4 acquisition interfaces in copper or optical, with capture rates from 1 to 100 Gbps, analyzing 100% of traffic in real time with no sampling.
Take control

Take Control of Your Network Detection with Our NDR Probe

QE-Secure gives you sovereign, high-performance, ANSSI qualified Network Detection and Response, with intelligence that runs entirely on your own infrastructure. See it in action on your own environment.