HodeiShield: The European TPRM platform with native NIS2, ENS, and DORA
We design and build specialized products and AI-native systems for cybersecurity companies: multi-tenant SaaS platforms, detection engines, SOC copilots, security stack integrations, and autonomous agents. We understand your domain because we operate it every day.
Every release ships signed, evaluable and auditable →
Generalist engineering teams that don't understand SIEM, SOAR (security orchestration via rules and playbooks), EDR, or MITRE ATT&CK — every feature takes twice as long and ships with domain gaps
You have a promising AI PoC (detection, triage, hunting) but no internal capacity to take it to a multi-tenant, evaluable, secure production
Your product is a security tool — it can't be the weak link. You need a real SSDLC, SOC 2 / ISO 27001 compliance, and secure-by-design architecture
Integrating with Splunk, Sentinel, QRadar, Elastic, XSOAR, MISP, OpenCTI, TAXII, and a dozen more eats up your entire roadmap velocity
Four pillars that apply to every service and every solution, not a one-off slogan.
The same team that attacks in the pentest runs the SOC and builds the AI models. Offensive insight informs defense, and AI is applied where we already operate, not bolted on as an extra layer.
HodeiShield, our own platform, automates continuous assessment, control mapping, and evidence generation — so manual work no longer sets the pace of regulatory compliance.
Infrastructure on OVHcloud (France/EU). You speak with the people who sign off on the work, not an account manager who forwards your request to another department.
HodeiShield isn't a third-party product we resell: we build and operate it ourselves, and that's what lets us offer faster compliance and evidence that's always current.
Deliverables and results you will receive with this service.
End-to-end product with tenant isolation, RBAC, billing, customer portal, and admin panel. Modern stack (Next.js, Node/Go, Postgres, Kubernetes) ready to scale.
Anomaly detection, alert classification, UEBA (user and entity behavior analytics), NLP over threat intel, and embedding-based correlation. Reproducible pipelines with MLOps, A/B testing, and drift control.
LLM-based assistants for triage, incident summaries, report writing, and conversational hunting. Autonomous agents with tools integrated into the customer stack.
Production-grade connectors for Splunk, Sentinel, QRadar, Elastic, Wazuh, Chronicle, Cortex XSOAR, Shuffle, MISP, OpenCTI, TAXII/STIX, leading EDRs, and standard webhooks.
Threat modeling, SAST/DAST/IaC scanning in CI, secrets management, cloud hardening, security-focused code review, and product SOC 2 / ISO 27001 readiness.
Evaluation harness for models and prompts, AI red teaming, quality/cost telemetry, guardrails, and AI Act-aligned documentation for high-risk systems.
Discovery, execution, delivery, and follow-up — the framework we follow on every project.
We understand your product, your user, and your use cases, and define architecture, stack, data model, and evaluation plan before building anything.
We build with iterative sprints: an evaluable PoC first, then the product, with CI/CD, automated tests, and continuous hardening in every delivery.
We connect to your customers' stack, evaluate the models in production, and deploy with runbooks after pentesting the product itself.
Evolutionary maintenance, retraining, and cost optimization, with support to open new product verticals when it's time to scale.
Structured methodology to ensure measurable and repeatable results.
We understand your product, your user (analyst, CISO, responder), and your use cases. We define architecture, stack, data model, integration surface, and evaluation plan.
Working prototype in 2-4 weeks with representative datasets. Clear metrics (precision, recall, latency, cost per query) and stakeholder-ready demo.
Iterative sprints with a closed squad or team extension. CI/CD, automated tests, continuous hardening, and useful deliverables every two weeks.
Customer stack connectors, continuous model evaluation, prompt tuning, product pentesting, and production rollout with runbooks.
Evolutionary maintenance, retraining, per-token/per-tenant cost optimization, SLOs, and support to open new product verticals.
A real scenario of how we work, not a marketing figure.
An MDR vendor wants to add a copilot that summarizes incidents for its analysts. We build an evaluable PoC over a representative dataset of their own tickets, measure precision and cost per query, and only after validating those metrics with their team do we take it to multi-tenant production connected to their platform.
This service is designed for organizations that identify with these profiles.
No names — here's how we work differently, with verifiable facts.
| Criteria | Generalist integrator | Hodeitek |
|---|---|---|
| Focus | Dozens of business lines; cybersecurity is just one of them | 100% cybersecurity and AI |
| Point of contact | An account manager who forwards your request to another department | Direct contact with the founders |
| Regulatory compliance | One-off reports per regulation, manual evidence management | HodeiShield automates evidence and cross-framework NIS2/ENS/DORA mapping |
| Product | Resells third-party licenses | Builds and operates HodeiShield, its own platform |
How what this service already includes relates to NIS2, DORA, and the AI Act — article by article, with no invented coverage.
| Framework | Article | What it requires | How this service helps |
|---|---|---|---|
| NIS2 | Art. 21(2)(e) | Apply security in the acquisition, development and maintenance of network and information systems, including vulnerability handling. | Secure-by-Design & SSDLC covers threat modeling, SAST/DAST/IaC scanning in CI, and secrets management — it applies this article's secure-development practice to the product we build for you. |
| AI Act | Art. 15 | Ensure the accuracy, robustness and cybersecurity of high-risk AI systems throughout their lifecycle. | AI Evals, Observability & Governance delivers the evaluation harness, AI red teaming, and the AI Act-aligned documentation for high-risk systems already listed among the deliverables — it provides evidence for Article 15, not the certification itself. |
Informational mapping, not legal advice: it describes how what we already do in this service helps comply with or provides evidence for each article — it doesn't replace a compliance assessment tailored to your organization.
Talk to our team of experts to design a plan tailored to your organization's needs.
Response within 24h
How we've applied this service in real projects.
The Digital Operational Resilience Act requires 22,000+ financial entities to actively manage third-party ICT risk since January 2025. HodeiShield automates the Information Register, classifies incidents automatically, and keeps evidence ready for ESA inspection.
Inventory, classify, and govern your AI systems under the EU AI Act, with security controls proportional to each system's risk tier.