GLIMPS
GLIMPS is a French cybersecurity platform that analyses files and characterises malware with more than 25 detection engines and eight proprietary AI models, returning a static verdict in roughly three seconds for SOC, CERT, DFIR and CTI teams.
What is GLIMPS?
GLIMPS is a French cybersecurity vendor founded in 2019 by four engineers from the Ministry of the Armed Forces and first incubated at the Cyber Defense Factory. It employs around fifty people from its Cyber Place headquarters in Cesson-Sévigné, near Rennes, and opened a Toronto subsidiary in July 2023.
The whole catalogue rests on a single technical core, GLIMPS Malware, declined into fourteen products. Its signature technology is code conceptualisation, a deep-learning approach the founders developed inside the Ministry of the Armed Forces: instead of matching a signature, it reasons about what the code does, which is how the vendor claims to catch zero-days, variants and APT samples that traditional signatures miss — with an announced detection rate above 99%. Around the Deep Engine sit more than twenty-five detection engines, roughly ten of them AI-based, and eight proprietary models: machine learning for Windows PE and Linux ELF binaries, a multi-script LLM for JavaScript, Python and PowerShell that runs locally with no external connection, classic antivirus engines and the customer's own YARA rules. An anti-phishing engine inspects URLs found inside files.
Analysis is hybrid. The static pass returns a verdict in roughly three seconds; dynamic detonation runs in a CAPE sandbox, and the artefacts it produces — memory dumps included — are re-analysed by the static engines. GLIMPS Malware Expert, the investigation console, centralises submissions from the entire range, adds retrohunt, MITRE ATT&CK mapping, IOC extraction and exportable YARA generation.
The catalogue is organised by intent: Protect (data security, business applications, DevSecOps, network security, PAM, sheep-dip systems, email security for Microsoft 365, SharePoint, OneDrive and Gmail), Investigate (Malware Expert, EDR, Audit), Mobilise (Malware Kiosk) and Control your data (Fortress). Deployment is SaaS or on premises.
The vendor's own figures — over 15 million files analysed per day, more than 100 protected customers, fifteen partners, 70% less investigation time — are claims, not audited metrics. Its public references are more checkable: ANSSI, through a 2022 public contract and a Kiosk portal for civil servants, the French armed forces, and the Hospices Civils de Lyon. Positioning is openly sovereign: a French vendor, hosting in France and Europe, presented as a European alternative.
What it does
- Submit a file by drag-and-drop, automated flow or REST API and get a verdict in about three seconds
- Analyse any file type — Windows PE, Linux ELF, JavaScript, Python and PowerShell scripts, archives, documents — with more than 25 engines
- Detonate a suspicious sample in an isolated CAPE sandbox and retrieve screenshots and memory dumps
- Generate a YARA rule automatically from a Deep Engine detection and export it to an EDR, SIEM or NDR
- Run a retrohunt across the full history of submissions
- Map the threat to MITRE ATT&CK, identify the malware family and extract indicators of compromise
- Push results to MISP, OpenCTI or Splunk, wire the analysis into a SOAR playbook, or quarantine a malicious file automatically on a file server
When to use GLIMPS / When not to
A quick filter to help you decide if GLIMPS is the right fit.
When to use GLIMPS
- SOC teams saturated with alerts, who need triage automated: a file goes in, a verdict comes back in about three seconds.
- CERT/CSIRT and DFIR responders working an incident, who need retrohunt across past submissions and a MITRE ATT&CK reading of the threat.
- CTI analysts who feed MISP or OpenCTI and want a YARA rule generated straight from a detection.
- Organisations bound by sovereignty requirements — public administrations, defence, critical operators, healthcare, energy, banking — including classified or offline environments served by the decontamination airlock mode.
- Engineering and security teams industrialising file analysis inside SOAR playbooks through the REST API and the Python or Go libraries.
When not to use GLIMPS
- Buyers who want to compare budgets before speaking to a salesperson: nothing is priced publicly, everything goes through a commercial proposal.
- Individuals and small teams hoping for a permanently free plan or a self-service checkout — access is contractual and B2B.
- Organisations looking to replace their endpoint antivirus or EDR: the vendor's own FAQ positions GLIMPS as a complement to those tools, not a substitute.
- Evaluators who intend to test on real personal data: the terms forbid submitting any personal data during the 30-day trial.
- Users who need a mobile app, a browser extension, or an interface in a language other than French or English.
How to use GLIMPS
A typical end-to-end flow, from setup to results.
- Take the two-minute diagnostic offered on the home page to work out which product in the range fits your situation
- Either start on your own: fill in the form on the GLIMPS Gear Program portal, create an account and open a 30-day trial of GLIMPS Malware Expert
- Or go through sales: request a demo, or use the contact form and pick the product from the drop-down list
- Choose the deployment model — shared or dedicated SaaS, or on premises — announced by the vendor in a few hours with no change to existing infrastructure
- Start submitting files by hand, dragging and dropping them into the Kiosk, or automate the flow
- Wire the analysis into your own applications through the REST API or the open-source Python and Go libraries
- Plug in the ready-made connectors matching your attack surface: web proxy, PAM, EDR, CI/CD, email, file storage, ICAP or the Host Connector
- Read the results in the GLIMPS Malware Expert console, where submissions from the whole range are centralised
- Set up email and SYSLOG alerts, and export PDF reports or JSON for downstream tooling
- Pick up the public packages on github.com/glimps-re — Python (PyPI), Go, and the Cortex XSOAR module
Pros & Cons
Pros
- Detection works on the code itself rather than on signatures, which is what supports the vendor's claim to cover zero-days and variants
- A static verdict in roughly three seconds, fast enough for high-volume, in-line use
- Exportable AI: the generated YARA rule is reusable in the customer's own EDR, SIEM or NDR
- Genuine sovereignty: French vendor, hosting in France and Europe, and analysed files that are never shared or exposed
- Demanding public references — ANSSI, the French armed forces, the Hospices Civils de Lyon — plus recognition such as French Tech 2030 (2025), Scale Up Excellence and the Grand Défi Cyber
- On-premises deployment available with the same performance as SaaS, and an integration ecosystem documented product by product
- A self-service 30-day free trial on the flagship product, with the client libraries published as open source on GitHub
Cons
- No public pricing at all: every purchase goes through a commercial proposal, so no budget can be framed in advance
- No permanent free plan; the trial is a firm 30 days, one per person, with no renewal
- The free trial contractually forbids personal data, which limits how realistic an evaluation can be
- No public API documentation on the site, even though the REST API is central to the product
- No list of sub-processors is published, although the terms provide for informing the customer of any change
- The terms state that GLIMPS does not guarantee exhaustive detection of all threats nor the absence of false positives, and a fourteen-product range needs an upfront diagnostic to navigate
- No security certification of the vendor itself (ISO 27001, SOC 2) is published, and the site and trial portal exist in French and English only
Pricing & Plans
There is no permanent free plan and no published price. Probes on /tarifs/, /pricing/ and /en/pricing/ all return 404, the sitemap lists no pricing page, and no amount in euros appears anywhere on the site other than the share capital in the legal notice. The general terms and conditions state that billing follows a Commercial Proposal, that invoices are issued in euros and payable within thirty days, and that late payment carries interest at the European Central Bank rate plus ten points together with a fixed recovery indemnity. Ordering online through the site is contemplated by the terms, but no tariff is displayed there. The only cost-free access is the trial version: a firm 30 days from account creation, one per person, non-renewable, and requiring no payment. Dedicated SaaS hosting is expressly the subject of a separate commercial proposal, so it carries a premium whose amount is not published. Because no public amount exists, the starting price, the currency and the billing unit are left empty together rather than guessed.
- Trial version — a firm 30 days from account creation
- free of charge
- one per person
- non-renewable
- no payment required
- Order on Commercial Proposal — the only paid route
- quoted per product and invoiced in euros
- no tier and no rate card is published
- Shared SaaS hosting — the standard contractual arrangement
- Dedicated SaaS hosting — available under a separate commercial proposal
- amount not published
- On-premises deployment — the alternative to SaaS
- likewise covered by a commercial proposal
- the offer is structured by product (fourteen references)
- not by price level
Data, GDPR & hosting
A consolidated view of how GLIMPS handles your data.
GDPR overview
GDPR implementation is concrete rather than declarative, but the two scopes must not be confused: the privacy policy governs the marketing website, while the product commitments sit in Article 12 of the terms and conditions. That article is built on Regulation (EU) 2016/679 and the French Data Protection Act and reads as an Article 28 processing clause — documented instructions, confidentiality, notification of sub-processor changes with a right to object, breach notification, assistance with data-subject rights and impact assessments. A data protection officer answers at dpo@glimps.re; the supervisory authority cited is the French CNIL. Rights listed are access, rectification, portability, objection, erasure, restriction and post-mortem instructions, with a thirty-day maximum response time. Established in France, the company needs no Article 27 representative and designates none. The product FAQ claims GDPR compliance and NIS2 compatibility. Privacy policy updated 6 May 2026; legal notice 18 December 2025.
Who owns the data?
Article 12 of the general terms and conditions is explicit: the customer is the data controller for everything it imports, enters or generates through the solution, and GLIMPS acts exclusively as a processor, handling that data on the customer's behalf and on its documented instructions alone. The vendor's FAQ states that GLIMPS does not exploit customer data in any way, and the product pages add that analysed files are never shared or exposed — the stated contrast with VirusTotal. On premises, nothing leaves the customer's infrastructure. Note the different scope of the privacy policy: it governs the marketing website, where form data is kept for three years and not passed to third parties.
Reuse rights
The customer keeps control of what it submits and of what comes back: verdicts, reports, indicators and generated YARA rules can be reused in its own tooling without asking GLIMPS for permission — exporting a rule into an EDR, SIEM or NDR is a documented feature, not a tolerated side use. On the vendor's side the use is deliberately narrow. Article 12 of the terms limits processing to the purposes strictly necessary to perform the contract, imposes confidentiality on everyone authorised to handle the data, requires GLIMPS to notify the customer of any addition or replacement of a sub-processor with a right to object, and to report personal-data breaches without undue delay while assisting with data-subject requests and impact assessments. Commercial reuse is ruled out: the single declared purpose is analysing the submitted file and returning an enriched verdict, and analysed files are neither shared nor exposed. One restriction runs the other way — during the 30-day trial the customer undertakes to submit no personal data at all.
Data retention & training
Hosting summary
In SaaS, GLIMPS states that hosting takes place in France, and its product pages widen that to France and Europe. The FAQ presents SecNumCloud hosting as possible in SaaS mode — an option offered, not a qualification the company holds. The terms name two contractual SaaS arrangements: shared servers by default, or dedicated servers under a separate commercial proposal. The host acts as a sub-processor of GLIMPS, on written instruction, with no right to use the data. On premises, the question is settled differently: nothing leaves the customer's own infrastructure. One boundary matters for due diligence — the privacy policy describes the marketing website, not the solution. That site is hosted by OVH, 2 rue Kellermann, 59100 Roubaix, and its data is, in the policy's words, hosted and processed exclusively within the European Union. Finally, a gap worth noting: although the terms undertake to inform customers of any addition or replacement of a sub-processor, GLIMPS publishes no list of sub-processors.
Things to keep in mind
Risks and trade-offs to weigh before adopting GLIMPS.
- No security certification of the vendor itself is published — no ISO 27001, no SOC 2. The page headed "certifications" lists awards; SecNumCloud appears as a possible hosting option and as a 2024 project prize, never as a qualification GLIMPS holds, and the CSPN/ANSSI mentions concern partner products, not GLIMPS.
- The home-page figures — over 15 million files a day, 100+ customers, 70% less investigation time, a detection rate above 99% — are declarative and unaudited. The terms themselves state that GLIMPS guarantees neither exhaustive detection nor the absence of false positives, so a clean verdict must never be read as proof of harmlessness.
- Automation invites over-trust. A three-second verdict is easy to accept without review; the tool is built to relieve analysts of triage, not to replace their judgement, and investigative skill erodes when the machine is never questioned.
- No price is published, so no budget can be estimated before a commercial conversation — a structural asymmetry in the buyer's negotiating position.
- Several reading traps around scope: the privacy policy covers the marketing website while the commitments applying to your submitted files sit in Article 12 of the terms; the policy names "www.glimps.fr" twice although it applies to www.glimps.re; and the domain uses the .re country code of Réunion even though the company operates from mainland France.
- No list of sub-processors is published, even though the terms provide for informing the customer of any addition or replacement.
- Submitting files means submitting content: in SaaS, business documents and potentially sensitive artefacts leave your perimeter. The terms forbid personal data outright during the free trial, and the on-premises option exists precisely for cases where nothing may leave.
Setup & Integrations
Technical difficulty
Difficulty varies with the mode of use. The free trial needs nothing technical: a web form, an account, and you are analysing files. The Kiosk is drag-and-drop from a browser, designed for non-specialists. Application integration is moderate: a REST API and Python or Go libraries, announced as a few lines of code. No-code routes exist too: a UBIKA reverse proxy or an ICAP connector. Deployment, SaaS or on premises, is announced in a few hours with no change to existing infrastructure. Heavier integrations — PAM, EDR, CI/CD, data diodes — do require a security or infrastructure team.
Deployment
Integrations
Supported languages
Behind GLIMPS
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement GLIMPS.
Frequently asked questions
What exactly is GLIMPS Malware?
Which file types can it analyse?
How does it differ from an antivirus?
How does it differ from a sandbox?
What does it add compared with VirusTotal?
SaaS or on premises?
Is it GDPR-compliant, and is GLIMPS certified?
How do I integrate it into my existing stack?
Is there a free trial?
How much does it cost?
Should you pick GLIMPS?
GLIMPS makes an unusual bet for a malware detection vendor: analyse the code rather than match a signature. That choice, born of work the founders carried out inside the French Ministry of the Armed Forces, is what supports the claim of catching zero-days and variants that signature-based tooling misses, and it comes with an assumed sovereignty stance — a French vendor, hosting in France and Europe, and submitted files that are never shared or exposed.
The credibility rests less on the marketing figures than on the references. The home-page numbers — over 15 million files a day, more than 100 customers, 70% less investigation time, a detection rate above 99% — are the vendor's own claims and have not been audited. The customers named, on the other hand, are checkable and demanding: ANSSI, the French armed forces, the Hospices Civils de Lyon.
The fit is clear. SOC, CERT/CSIRT, DFIR and CTI teams get a three-second verdict, a CAPE sandbox, retrohunt, MITRE ATT&CK mapping and YARA rules they can export into their own EDR, SIEM or NDR. Organisations under sovereignty or NIS2 pressure get an on-premises option in which nothing leaves their infrastructure.
Two reservations deserve to be stated plainly. Pricing is entirely opaque: no rate card, no starting price, no billing unit — a commercial proposal is the only way to learn what this costs. And despite a REST API that sits at the centre of the product, no public API documentation exists on the site, which makes technical scoping harder than it should be. Note too that GLIMPS publishes no security certification of its own.
A 30-day free trial on GLIMPS Malware Expert allows an evaluation without commitment — though the terms forbid submitting personal data during it.
- Choosing a selection results in a full page refresh.
- Opens in a new window.