×
Hub Forge AI
|
AI-driven cyber transformation: operational agents inside your IT system
Innovation, sovereignty, control. The complete pipeline from audit to action — deployed within your infrastructure.
// Confidential — Credit Agricole · March 2026
Cyber transformation: the challenges of a banking group.
Generic AI does not meet the requirements of a banking group — neither in sovereignty, nor in integration, nor in control.
Alert volume
Thousands of daily SIEM alerts. Analysts spend 80% of their time on false positives. The average detection time remains too high.
Regulatory pressure
DORA requires resilience testing, NIS2 imposes notification deadlines. Each framework demands documented evidence — done manually, it is a bottomless pit.
AI = leak risk
Cloud AI tools send your data outside. It is impossible to validate the compliance of a chatbot that transits through a third-party server.
Siloed tools
SIEM, SOAR, ITSM, GRC — each in its own corner. No cross-functional intelligence. Correlations are done manually.
Agents under your control.
AI agents that understand your business, deployed within your infrastructure, connected to your tools — under human supervision.
Audit
Scoring of your processes
Correlation
Gaps × available expertise
Monitoring
CVE + tools, continuously
Agent
Business-specialized
MCP
Connected to your tools
Action
Under supervision
Every action is logged, auditable, and subject to human validation. Nothing executes without your consent.
Use cases for your daily operations.
SIEM alert triage
The agent reads your alerts via MCP connector, correlates events, eliminates false positives, enriches IOCs. The analyst receives a dashboard sorted by criticality — not a raw queue.
Regulatory compliance
The CompliForge agent produces DORA and NIS2 gap analyses, generates the missing policies, prepares documented evidence. With a GRC connector: automatic verification within your tools.
Incident response
The agent guides evidence collection, builds the timeline, generates the preliminary report. With a SOAR connector: execution of containment playbooks under human validation.
Entity audit
A standardized framework to assess the cyber maturity of each regional bank. Automatic scoring on 12 axes, detection of critical gaps, remediation plan.
Active Directory hygiene
The agent detects inactive accounts, excessive permissions, dangerous configurations. With an AD connector: automatic scan and periodic report.
ACPR permanent controls
The agent generates control sheets, analyzes policy/field gaps, produces compliance dashboards for regulatory reporting.
Transformation, Innovation, Awareness.
Axes that map directly to your scope.
Industrialize cyber operations
The audit → agent → MCP pipeline turns manual processes into AI-assisted workflows. SOC triage, compliance, entity audits — each process is structured and accelerated without losing human control.
Agentic AI — the next step
Beyond the chatbot: agents specialized by domain, enriched by 770+ open source skills, connected to your tools via MCP. This is AI that understands the business, not just the language. A market-leading position.
Incident response agents
In a crisis situation, the agent guides the response team: evidence collection, timeline, internal communication, regulatory report. With a SOAR connector: execution of containment playbooks under validation. Reaction time is cut in half.
Shared expertise capital
Skills and playbooks are centralized in the Forges. Every team member accesses the same level of expertise. Juniors ramp up faster. Knowledge is no longer stuck in the head of a single expert.
Your team's data/AI background is an asset: Hub Forge AI speaks both languages — data engineering and cybersecurity — within a single ecosystem.
The agent acts, you stay in control.
Without a connector, the agent advises. With an MCP connector, it acts within your tools — always under supervision.
Advisory mode (default)
- Guides your teams step by step
- Proposes commands and configs
- Generates reports and policies
- Analyzes what you provide it
Action mode (MCP connector)
- Reads your SIEM alerts in real time
- Triages and qualifies automatically
- Verifies compliance in your GRC
- Acts under human validation
Read-only by default
Each connector starts in read-only mode. Write actions require explicit activation.
Human validation
Any critical action (closing an alert, changing a config, running a playbook) requires a confirmation.
Complete audit trail
Every call, every parameter, every result is logged. CSV export for your ACPR/ECB obligations.
Granular permissions
Each agent has rights defined per connector. No global access — the principle of least privilege.
Connectors for your environment.
| Tool | Connector | Agent | Mode |
|---|---|---|---|
| SIEM | Alert reading, correlation, enrichment | SOC agent — automated triage | Read |
| SOAR | Playbook triggering, tracking | Incident response agent | Read+Write |
| ITSM (ServiceNow) | Tickets, assignment, tracking | Support agent — diagnostics | Read |
| GRC (RSA Archer, OneTrust) | Registers, controls, evidence | DORA/NIS2 compliance agent | Read |
| Active Directory | Accounts, groups, permissions | AD audit agent | Read |
| Monitoring | Metrics, thresholds, anomalies | Supervision agent | Read |
Custom engagementEach connector is developed and configured by Cyclad for your specific environment.
Zero externalized data.
The platform runs within your infrastructure. You can prove it.
VM in your infra
Pre-configured Docker image. Compatible with VMware, Proxmox, Hyper-V. All services isolated in containers.
100% local AI
The AI model runs inside the VM (DeepSeek, Qwen, Llama, Mistral). No prompt ever leaves your network.
Verifiable traffic
The VM is a single point. Your security team can sniff every packet and confirm: nothing leaves.
Total visibility.
Every action of every agent, in real time. Export for your ACPR audits and permanent controls.
Real-time dashboard
Active agents and their status
Actions of the day (read / write)
Success rate per agent
Latest activity + trends
Alerts on anomaly
Audit trail
Every call: date, agent, tool, parameters, result
Filterable by date, agent, action type
Native CSV export (UTF-8 / Excel)
Configurable retention
Compatible with ACPR / ECB obligations
Your security team sees exactly what each agent does, when, on which tool, with which parameters. Nothing is opaque.
Progressive, controlled, measurable.
We start small and expand based on results.
Scoping
Identify your tools and priorities
POC
1 agent + 1 connector on a target scope
Pilot
Limited team, real-world conditions
Measurement
KPIs: time, quality, coverage
Rollout
New connectors + teams
Suggested POC: SOC triage
An agent connected read-only to your SIEM. It triages the night's alerts and presents an ordered dashboard to the SOC team in the morning. Zero risk, immediate value, measurable in 2 weeks.
Alternative POC: DORA compliance
A CompliForge agent loaded with the DORA framework. It produces the gap analysis of your current setup and generates the action plan. No connection to the IT system required — purely document generation.
Cyber expertise, MCP connector development, guidance, training, ongoing support.
Platform, agent engine, 770+ cyber skills, connector SDK, continuous monitoring, Agent Monitor.
A 30-minute technical conversation.
To identify the scope of the POC and show you an agent in action.
Week 1
Technical scoping
Weeks 2-4
POC on your SIEM or DORA
Month 2
SOC team pilot
×
Hub Forge AI
|
// Confidential — Credit Agricole · March 2026