+33 (0)1 87 66 00 65 · Monday to Friday, 9am–6pm Free audit (15 min)
● B2B offer — Cybersecurity & monitoring

Cybersecurity: alerts qualified, events correlated

A security team receives more alerts than it can look into in detail. Your agent, connected to your SIEM, correlates the events, qualifies each alert against your detection rules and documents the signal with the chain of events it rests on. Hosted in France: your technical logs and your infrastructure map stay with you. Any remediation belongs to your security team.

Hosted in France Technical logs protected GDPR & AI Act: governed deployment Human oversight

Updated on

Deployed in a few weeks
Cybersecurity · hosted in France
Which alerts deserve our attention this morning?
Alerts qualified against your detection rules, each with its chain of correlated events.
Three signals bring together several linked events on the same account and the same time window.
The source events and their timestamps are provided.
🔗 Sourced · SIEM logs, correlated events
Can we isolate the account concerned?
The material needed for the decision is gathered: chain of events, apparent extent, systems concerned.
Isolating an account or cutting off access has consequences for the business: that decision belongs to your security team.
✎ Support · material gathered, human remediation
Local inference · no data outside the EU
Logs hosted in France
Sovereign by designLocal inference or hosting in France
GDPR & AI Act: governed deploymentTraceability & human oversight
TurnkeyDesigned, installed and operated for you
Your security team decidesThe agent prepares, never rules
✦ In brief

A Blue Lemon Agent cybersecurity agent, connected to your SIEM, correlates the events, qualifies the alerts against your detection rules and documents every signal with the chain of events and the timestamps it rests on. No remediation is applied automatically. It runs on local inference or is hosted in France: your logs stay with you, architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity.

100%
hosted in France in the target architecture
0
transfer outside the EU in the target architecture
6
security monitoring uses ready to deploy
0
decision taken without human approval

These figures describe our offer, not results measured at a client. How large the gain is on your volume of logs and number of sources is confirmed by a pilot.

The context

What does an AI agent bring to your security monitoring?

A correlated, documented signal can be looked into in minutes; an isolated alert means reconstructing everything.

! The issue

Looking into an alert means gathering the linked events and placing their extent. That correlation work is systematic and lends itself to automation; the remediation decision, on the other hand, commits the business. The agent correlates, qualifies against your rules and provides the full chain with its timestamps.

Our answer

Your security team looks into signals that are already correlated and documented, across all the logs rather than the most closely watched sources. Isolating an account, cutting off access or triggering an incident procedure has consequences for the business: those decisions stay theirs. Local inference or an isolated resource hosted in France: your technical logs, which describe your information system, do not leave the company.

The decisive point

Your technical logs and your security map: sovereignty & compliance

Your technical logs draw the map of your information system: keeping them confidential is a security matter in itself. Here is how that is assured.

Local inference

The agent can run on a machine belonging to your organisation: no technical log and no element of the map leaves the network.

Hosting in France

Otherwise, a dedicated and isolated resource hosted in France, under French law — your event logs and your alerts: processing and access within the European Union targeted by the architecture.

Reduced extraterritorial exposure

For your technical logs and your security map, the architecture aims to reduce exposure to the Cloud Act and FISA 702; being located in France or in the European Union does not, on its own, guarantee immunity.

Isolated resource

No pooling: an environment strictly dedicated to your organisation and its detection rules.

Chain of events kept

Every signal keeps the correlated events and their timestamps; encryption, role-based access and logging that can be used in an investigation.

AI Act: governed deployment

The agent is strictly in support; no account is isolated, no access is cut off and no procedure is triggered automatically; traceability and human oversight from end to end.

What depends on the architecture chosen These points are not general guarantees: they are settled deployment by deployment, in the quotation.

  • The applicable location is that of the architecture set out in the quotation and verified before commissioning.
  • Local execution is announced only for the configuration explicitly described and accepted in the quotation.
  • The applicable isolation depends on the deployment mode set out in the quotation; no dedicated isolation is presumed.
  • Roles and permissions are configured and accepted for the identities and systems actually connected.
  • The events logged, their content, their retention period and who may access them are defined for the deployment chosen.
For investigations in progress and confirmed security incidents, SecNumCloud and reinforced hosting are options depending on your requirements. A single architecture is designed to answer both the GDPR and extraterritorial exposure. Designed for deployment in line with the GDPR and the AI Act, after the processing, roles and context-specific risks have been assessed.
Demonstration

See the agent at work

5 real situations, taken from those that come up most often. Pick one: the exchange unfolds as it would in your organisation.

A scripted demonstration. These exchanges show how the agent behaves — its sources, its refusals, what it leaves to your teams. Nothing is sent from this page, no model is queried here, and the matters named are fictional. That is precisely what we promise your data.
The behaviours shown here — monitoring, automation rules, routing and reminders — are configured with you during deployment, from your tools, your rules and your thresholds.
The architecture points named in these exchanges — location, local execution, isolation, encryption, role-based access, logging — are not a guarantee attached to the demonstration: they are those of the architecture set out in your quotation, and verified before commissioning.

The company in this demonstration

Fictional company

Maldeau Groupe — specialist retail, 84 stores and an online shop

Sector
Specialist retail — 84 stores, an online shop, two warehouses
Headcount
1,900 staff, including 4 in security: 1 CISO and 3 analysts, office hours
Public served
2.1 million loyalty-card holders, payment in store and online
Volume monitored
2.4 billion events a month, 11 log sources, 1,400 alerts a week
Tools in place
SIEM live for 4 years, directory, firewalls, monitored endpoints, ticketing tool — the agent plugs in read-only, nothing is replaced
Who decides
The CISO settles remediation gestures; operations approve any access cut-off; the three analysts investigate
Room for improvement
41 alerts investigated in depth each week out of 1,400 received; correlation takes 65 % of the time spent on an alert

Maldeau Groupe receives twenty times more alerts each week than its three analysts can investigate, and nobody has ever been able to say what the other 1,359 contained. The agent runs on local inference on a machine at the group and reads the SIEM, the directory, the ticketing tool and the change calendar: it correlates, qualifies, quantifies the noise set aside and prepares every gesture with its effect on production. The CISO decides, and what he decides executes within minutes. The exchanges below cover one quarter, from the first triage to the review.

This company, its figures and the exchanges that follow were invented for the demonstration. They illustrate a common situation; they describe no real client.

Cybersecurity · hosted in France
This week's 1,400 alerts are sorted. Three deserve your morning, and I tell you exactly why the other 1,397 do not.
Correlation means bringing together the linked events of one account, one machine or one time window, so an alert stops being an isolated dot.
The three signals, by reach:
· Signal 1 — 214 failed authentication attempts on 38 accounts, from 3 addresses, in 11 minutes, then one success on a test account. 34 events correlated across 4 sources.
· Signal 2 — a service account authenticating from an office workstation. A service account is a technical account used by a program, never by a person. Zero occurrences of that behaviour across the previous 90 days.
· Signal 3 — an export volume multiplied by 22 on an account at the north warehouse, between 22:40 and 23:05, outside any declared maintenance window.
What happens to the other 1,397, and nothing disappears:
· 1,240 are set aside with a written reason, viewable and reversible in one click. 620 of them — half — come from three detection rules whose threshold has never been reviewed since it was written.
· 157 are grouped into 9 families and await a tuning decision, not an investigation.
The time this moves: correlation took 65 % of the time spent on an alert; it now takes 7 %. Your analysts used to investigate 41 alerts a week out of 1,400; all 1,400 are now sifted, and they investigate the ones that deserve it.
What I propose: I show you how I checked that this triage lets nothing through — by replaying it across twelve months of your own logs. weekly-triage_1400-alerts.pdf3 signals, 1,240 written reasons, 620 from 3 rules
⛓ Sourced · SIEM (2.4 billion events/month, 11 sources), directory, change calendar
Setting 1,240 alerts aside is exactly what worries us.
I checked that before proposing it: I replayed the triage across twelve months of your logs, and all three of the year's real incidents come out, at the top of their list.
What the replay measured, rule by rule: for each of your 47 detection rulesthe written condition that makes an alert appear — I counted across twelve months how many alerts it produced, how many were confirmed after investigation, and what it would have let through.
· 3 rules produce 44 % of your alerts and 0 confirmations in twelve months.
· 9 rules produce fewer than 5 alerts a month and 61 % of the confirmations. Those are your best ones, and they are drowned.
· The year's 3 real incidents were raised by 2 rules, and the triage places them among the top three signals of their week.
What I propose, written and already tested: four tightened rules, drafted in the form of your existing ones. For each, here is what twelve months of logs give:
· Failed-authentication rule: 84 alerts become 19, the 3 confirmed ones are kept, and 65 pointless investigations disappear.
· Out-of-hours connection rule: 310 become 41, the 2 confirmed ones kept.
· Share-access rule: 240 become 58, the single confirmation kept.
· Application-error rule: 186 become 12, no confirmation lost.
You sign them and they are live tonightand each one is withdrawn in one word, on its own, without touching the other forty-six. The count of alerts set aside stays viewable at all times: an alert set aside is not an alert deleted. rules-replayed_over-12-months.pdf4 tightened rules, 84 → 19, 3 confirmations kept
⛓ Sourced · 12 months of archived logs, 47 detection rules, history of investigations and confirmations
And what no rule describes? An attack we have never seen slips through.
That is why I do not work from your rules alone: I also measure the gap to habitual behaviour, and that is how I found two of this morning's three signals.
The baseline is the habitual behaviour of an account, a machine or a time slot, measured over a period long enough for the exception to show. Mine covers 90 rolling days, and it is computed per account, per machine and per time slot — a company-wide average would have shown nothing.
The two behaviours none of your 47 rules described:
· The service account authenticating from an office workstation. Over 90 days that account authenticated 4,100 times, always from the same two servers. This morning, once, from a workstation. No rule saw it, because no rule states where a service account is allowed to come from.
· The export volume multiplied by 22. That account's baseline is 4 to 11 MB an evening; yesterday, 214 MB in 25 minutes.
What I draw from it, and propose writing into your rules: three new detection rules, drafted, each with what twelve months of history makes it produce:
· « A service account authenticates from a machine absent from its list » — 6 firings over 12 months, 4 of them confirmed after investigation.
· « An account exceeds ten times its usual export volume » — 11 firings, 3 of them confirmed.
· « An authentication succeeds after more than 50 failures in the same window » — 4 firings, 2 of them confirmed.
Those three rules would have produced 21 alerts in a yearfewer than one a fortnight for your analystsand nine of them would have been confirmed. You review them, you sign them, and this morning's behaviour becomes a rule of the house. behavioural-detection_3-rules-proposed.pdf21 alerts a year, 9 confirmed against history
⛓ Sourced · 90 days of per-account and per-machine baselines, 12 months of archived logs
Local inference · no data outside the EU

Your case is not here? That is exactly what a 15-minute conversation is for. Book the free audit

Use cases

What does the agent actually do?

One agent, several stages of monitoring. All these uses work in support, subject to your approval.

Included in your agent The 4 capabilities essential to this promise are included, at no extra cost.
From 601 € excl. VAT / month

Correlating events

Brings together the linked events on the same account or in the same time window.

Qualifying alerts

Applies your detection rules and presents the result obtained.

Investigation documentation

Keeps the chain of events and the timestamps of every signal.

Sovereign AI

The hosting and confidentiality foundation the agent rests on.

Controls and safeguards These 5 controls are built into the agent: they frame what it does, whatever plan you pick. They are not chosen and are not added to your order.
Human validation, exceptions and escalation Status, safe closure and audit trail Access the technical context with least-privilege permissions Run tests, security analysis and human review before any change Version, log, roll back and measure quality

Need to go further?

These agents handle a different business process, with their own owner and their own price. They are added to this one.

Does your need fall outside this?

In 15 minutes we identify the most relevant agent — without oversizing the project.

Book the free audit Build your agent
The gain

How many alerts can a team look into?

By taking on the correlation, the effort shifts towards investigation and remediation. How large the gain is depends on your volume and remains to be confirmed by a pilot.

Correlating the events
Today · done by hand
Events correlated
Qualifying an alert
Today · done by hand
Alert qualified
Building the investigation file
Today · done by hand
Chain documented
Indicative figures, not contractual, to be confirmed by a pilot on your volume of logs and number of sources. Isolating an account, cutting off access or triggering an incident procedure has consequences for the business: those decisions belong to your security team.
How it works

The stages of your AI agent project

1

Audit & scoping

15 minutes to target the use case with the best return.

2

Quote or direct sign-up

A catalogue offer is bought online; a specific need gets a costed quote.

3

Design

We design the agent and its guardrails.

4

Integration & testing

We connect your tools to the agent, which is itself hosted in France.

5

Rollout

Going live and training your team.

6

Operation

Continuous supervision and improvement.

Pricing

One package, one agent

A security monitoring agent (correlation, qualification, documentation), installed and operated for you.

Agility

Setup + controlled subscription

6,545 € excl. VAT setup
then 601 € excl. VAT/month — you invest at installation and pay a reduced subscription. Ideal for keeping the cost under control over time.
  • Installation, configuration and training for your teams
  • Operation, human oversight, updates and support
  • Sovereign hosting in France, a dedicated and isolated resource
Order →
The simplest Serenity

All inclusive, no setup fee

961 € excl. VAT /month
all inclusive, immediate start. No upfront investment: a single subscription. Ideal for starting quickly and simply.
  • Setup included (installation, configuration, training)
  • Operation, human oversight, updates and support
  • Sovereign hosting in France, managed end to end
Order →
100% Sovereign

On site, you own it

10,370 € excl. VAT setup
then 816 € excl. VAT/month · + hardware from 1,058 € (one-off purchase, in addition) — a sovereign computer installed on your premises, maintained remotely. Models run locally, your data returned at the end of the contract. 36-month commitment.
  • Hardware installed on your premises (you own it)
  • French / European AI models run locally
  • Secure remote maintenance (Pro support included)
Order →
Not included in the packages: AI consumption (model tokens), re-invoiced at real cost with no margin, and tracked in real time in your client area. Maintenance and supervision subscription for an initial term of 12 months for the Agility package, 24 months for the Serenity package and 36 months for the 100% Sovereign package, renewable; support levels (SLA 72 h / 24 h / 4 h) optional. Bespoke development, additional integrations or exceptional volumes are quoted separately. Support Monday to Friday, 9am to 6pm. Prices exclude VAT.
AI model: none of the AI models offered currently carries a fixed surcharge. When the selected model carries a cost, that cost is shown when you choose it, before you order, and re-invoiced at the cost incurred, with no mark-up; usage is billed at the publisher's price. Publishers' prices are published in US dollars: the amount re-invoiced is the amount in euros actually borne by Blue Lemon Agent on the publisher's invoice, at that invoice's exchange rate, with no commission or mark-up.
Included components and additional components Components included in the base offer: the Blue Lemon Agent software foundation, the AI models listed in the order journey, the standard channels (Microsoft Teams, Slack, WhatsApp Business, email, website chat, calendars, Microsoft 365 / Google Workspace, file storage, market VoIP telephony, professional social-media pages and accounts, Google Business Profile), hosting in France for the package chosen, backups, supervision, updates and support. If adapting the AI agent to your constraints, your needs or your requests requires other paid components — a third-party publisher's software licence, paid API access to one of your applications, hosting of health data, for which French law requires an HDS-certified host (art. L. 1111-8 of the French Public Health Code), SecNumCloud-qualified hosting, a speech synthesis service, particular hardware —, they are offered to you as an option or on quotation and re-invoiced at the cost incurred; nothing is committed without your written agreement. Where the artificial intelligence model you choose entails an additional cost, that cost is shown to you before you order and re-invoiced to you at the cost incurred, with no margin.
What to expect
Go-live 2 to 3 weeks
Agent designed, channels connected, team trained.
Steady state 4 to 7 weeks
After a few weeks of real use, once the agent's behaviour matches what you expect. Indicative estimate, adjusted to the options you keep. It is not a delivery commitment.
Our commitment

Four guarantees that matter to your security

Your technical logs stay with youLocal inference or an isolated resource hosted in France; no log entrusted to a third party, no data used to train a model.
Data in France, under French lawYour technical logs and your security map: minimisation and location in France, architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity.
Your security team keeps the decisionThe agent produces alerts that are qualified and documented, which can be checked and altered; no approval is automated.
Human oversight & traceabilityOn your volume of logs and number of sources: systematic logging and tracking, in line with the AI Act.
Frequently asked questions

Your questions, our answers

Does the agent apply remediation measures?
No. It correlates, qualifies and documents. Isolating an account or cutting off access has consequences for the business: those acts belong to your security team.
What is the qualification based on?
On your detection rules, applied as they stand. The result is presented with the chain of events that produced it.
What sources does it connect to?
To your SIEM and the log sources you open to it, read-only. The scope is settled at the design stage.
Can the signals be used in an investigation?
Yes: correlated events and timestamps are kept for every signal, which makes it possible to reconstruct the sequence afterwards.
Are our logs protected?
Yes. The agent is hosted in France, on local inference or an isolated resource, with the deployment objective of processing and access operated within the European Union and an architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity. Your logs are not used to train a third-party model.
How long does it take to deploy this agent?
A few months as a rule, depending on the volume of logs, the number of sources and your detection rules, after a free audit then phases of design, integration and testing.
Let's talk

Let's size up the potential in your security monitoring

15 minutes to frame your sources and your detection rules — hosted in France, supervised, with no commitment.