GLIMPS logo
Privacy Security · Security Fraud

GLIMPS

GLIMPS is a French cybersecurity platform that analyses files and characterises malware with more than 25 detection engines and eight proprietary AI models, returning a static verdict in roughly three seconds for SOC, CERT, DFIR and CTI teams.

Active GDPR compliant Free trial Contact Sales API available Verified by Guidaio
Overview

What is GLIMPS?

GLIMPS is a French cybersecurity vendor founded in 2019 by four engineers from the Ministry of the Armed Forces and first incubated at the Cyber Defense Factory. It employs around fifty people from its Cyber Place headquarters in Cesson-Sévigné, near Rennes, and opened a Toronto subsidiary in July 2023.

The whole catalogue rests on a single technical core, GLIMPS Malware, declined into fourteen products. Its signature technology is code conceptualisation, a deep-learning approach the founders developed inside the Ministry of the Armed Forces: instead of matching a signature, it reasons about what the code does, which is how the vendor claims to catch zero-days, variants and APT samples that traditional signatures miss — with an announced detection rate above 99%. Around the Deep Engine sit more than twenty-five detection engines, roughly ten of them AI-based, and eight proprietary models: machine learning for Windows PE and Linux ELF binaries, a multi-script LLM for JavaScript, Python and PowerShell that runs locally with no external connection, classic antivirus engines and the customer's own YARA rules. An anti-phishing engine inspects URLs found inside files.

Analysis is hybrid. The static pass returns a verdict in roughly three seconds; dynamic detonation runs in a CAPE sandbox, and the artefacts it produces — memory dumps included — are re-analysed by the static engines. GLIMPS Malware Expert, the investigation console, centralises submissions from the entire range, adds retrohunt, MITRE ATT&CK mapping, IOC extraction and exportable YARA generation.

The catalogue is organised by intent: Protect (data security, business applications, DevSecOps, network security, PAM, sheep-dip systems, email security for Microsoft 365, SharePoint, OneDrive and Gmail), Investigate (Malware Expert, EDR, Audit), Mobilise (Malware Kiosk) and Control your data (Fortress). Deployment is SaaS or on premises.

The vendor's own figures — over 15 million files analysed per day, more than 100 protected customers, fifteen partners, 70% less investigation time — are claims, not audited metrics. Its public references are more checkable: ANSSI, through a 2022 public contract and a Kiosk portal for civil servants, the French armed forces, and the Hospices Civils de Lyon. Positioning is openly sovereign: a French vendor, hosting in France and Europe, presented as a European alternative.

What it does

  • Submit a file by drag-and-drop, automated flow or REST API and get a verdict in about three seconds
  • Analyse any file type — Windows PE, Linux ELF, JavaScript, Python and PowerShell scripts, archives, documents — with more than 25 engines
  • Detonate a suspicious sample in an isolated CAPE sandbox and retrieve screenshots and memory dumps
  • Generate a YARA rule automatically from a Deep Engine detection and export it to an EDR, SIEM or NDR
  • Run a retrohunt across the full history of submissions
  • Map the threat to MITRE ATT&CK, identify the malware family and extract indicators of compromise
  • Push results to MISP, OpenCTI or Splunk, wire the analysis into a SOAR playbook, or quarantine a malicious file automatically on a file server
Audience

When to use GLIMPS / When not to

A quick filter to help you decide if GLIMPS is the right fit.

When to use GLIMPS

  • SOC teams saturated with alerts, who need triage automated: a file goes in, a verdict comes back in about three seconds.
  • CERT/CSIRT and DFIR responders working an incident, who need retrohunt across past submissions and a MITRE ATT&CK reading of the threat.
  • CTI analysts who feed MISP or OpenCTI and want a YARA rule generated straight from a detection.
  • Organisations bound by sovereignty requirements — public administrations, defence, critical operators, healthcare, energy, banking — including classified or offline environments served by the decontamination airlock mode.
  • Engineering and security teams industrialising file analysis inside SOAR playbooks through the REST API and the Python or Go libraries.

When not to use GLIMPS

  • Buyers who want to compare budgets before speaking to a salesperson: nothing is priced publicly, everything goes through a commercial proposal.
  • Individuals and small teams hoping for a permanently free plan or a self-service checkout — access is contractual and B2B.
  • Organisations looking to replace their endpoint antivirus or EDR: the vendor's own FAQ positions GLIMPS as a complement to those tools, not a substitute.
  • Evaluators who intend to test on real personal data: the terms forbid submitting any personal data during the 30-day trial.
  • Users who need a mobile app, a browser extension, or an interface in a language other than French or English.
Get started

How to use GLIMPS

A typical end-to-end flow, from setup to results.

  1. Take the two-minute diagnostic offered on the home page to work out which product in the range fits your situation
  2. Either start on your own: fill in the form on the GLIMPS Gear Program portal, create an account and open a 30-day trial of GLIMPS Malware Expert
  3. Or go through sales: request a demo, or use the contact form and pick the product from the drop-down list
  4. Choose the deployment model — shared or dedicated SaaS, or on premises — announced by the vendor in a few hours with no change to existing infrastructure
  5. Start submitting files by hand, dragging and dropping them into the Kiosk, or automate the flow
  6. Wire the analysis into your own applications through the REST API or the open-source Python and Go libraries
  7. Plug in the ready-made connectors matching your attack surface: web proxy, PAM, EDR, CI/CD, email, file storage, ICAP or the Host Connector
  8. Read the results in the GLIMPS Malware Expert console, where submissions from the whole range are centralised
  9. Set up email and SYSLOG alerts, and export PDF reports or JSON for downstream tooling
  10. Pick up the public packages on github.com/glimps-re — Python (PyPI), Go, and the Cortex XSOAR module
Quick read

Pros & Cons

Pros

  • Detection works on the code itself rather than on signatures, which is what supports the vendor's claim to cover zero-days and variants
  • A static verdict in roughly three seconds, fast enough for high-volume, in-line use
  • Exportable AI: the generated YARA rule is reusable in the customer's own EDR, SIEM or NDR
  • Genuine sovereignty: French vendor, hosting in France and Europe, and analysed files that are never shared or exposed
  • Demanding public references — ANSSI, the French armed forces, the Hospices Civils de Lyon — plus recognition such as French Tech 2030 (2025), Scale Up Excellence and the Grand Défi Cyber
  • On-premises deployment available with the same performance as SaaS, and an integration ecosystem documented product by product
  • A self-service 30-day free trial on the flagship product, with the client libraries published as open source on GitHub

Cons

  • No public pricing at all: every purchase goes through a commercial proposal, so no budget can be framed in advance
  • No permanent free plan; the trial is a firm 30 days, one per person, with no renewal
  • The free trial contractually forbids personal data, which limits how realistic an evaluation can be
  • No public API documentation on the site, even though the REST API is central to the product
  • No list of sub-processors is published, although the terms provide for informing the customer of any change
  • The terms state that GLIMPS does not guarantee exhaustive detection of all threats nor the absence of false positives, and a fourteen-product range needs an upfront diagnostic to navigate
  • No security certification of the vendor itself (ISO 27001, SOC 2) is published, and the site and trial portal exist in French and English only
Pricing

Pricing & Plans

There is no permanent free plan and no published price. Probes on /tarifs/, /pricing/ and /en/pricing/ all return 404, the sitemap lists no pricing page, and no amount in euros appears anywhere on the site other than the share capital in the legal notice. The general terms and conditions state that billing follows a Commercial Proposal, that invoices are issued in euros and payable within thirty days, and that late payment carries interest at the European Central Bank rate plus ten points together with a fixed recovery indemnity. Ordering online through the site is contemplated by the terms, but no tariff is displayed there. The only cost-free access is the trial version: a firm 30 days from account creation, one per person, non-renewable, and requiring no payment. Dedicated SaaS hosting is expressly the subject of a separate commercial proposal, so it carries a premium whose amount is not published. Because no public amount exists, the starting price, the currency and the billing unit are left empty together rather than guessed.

Plan 1
  • Trial version — a firm 30 days from account creation
  • free of charge
  • one per person
  • non-renewable
  • no payment required
Plan 3
  • Shared SaaS hosting — the standard contractual arrangement
Plan 4
  • Dedicated SaaS hosting — available under a separate commercial proposal
  • amount not published
Plan 5
  • On-premises deployment — the alternative to SaaS
  • likewise covered by a commercial proposal
No pricing tiers exist
  • the offer is structured by product (fourteen references)
  • not by price level
Special offers — A 30-day free trial of GLIMPS Malware Expert through the GLIMPS Gear Program portal, with access to the analysis modules and the Deep Engine — one per person, non-renewable · A personalised demonstration run by GLIMPS experts, on request · A free two-minute diagnostic on the website to identify which product in the range fits your situation · No discount, promotional code or targeted pricing offer (students, non-profits, start-ups) is published
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how GLIMPS handles your data.

GDPR overview

GDPR implementation is concrete rather than declarative, but the two scopes must not be confused: the privacy policy governs the marketing website, while the product commitments sit in Article 12 of the terms and conditions. That article is built on Regulation (EU) 2016/679 and the French Data Protection Act and reads as an Article 28 processing clause — documented instructions, confidentiality, notification of sub-processor changes with a right to object, breach notification, assistance with data-subject rights and impact assessments. A data protection officer answers at dpo@glimps.re; the supervisory authority cited is the French CNIL. Rights listed are access, rectification, portability, objection, erasure, restriction and post-mortem instructions, with a thirty-day maximum response time. Established in France, the company needs no Article 27 representative and designates none. The product FAQ claims GDPR compliance and NIS2 compatibility. Privacy policy updated 6 May 2026; legal notice 18 December 2025.

Who owns the data?

Article 12 of the general terms and conditions is explicit: the customer is the data controller for everything it imports, enters or generates through the solution, and GLIMPS acts exclusively as a processor, handling that data on the customer's behalf and on its documented instructions alone. The vendor's FAQ states that GLIMPS does not exploit customer data in any way, and the product pages add that analysed files are never shared or exposed — the stated contrast with VirusTotal. On premises, nothing leaves the customer's infrastructure. Note the different scope of the privacy policy: it governs the marketing website, where form data is kept for three years and not passed to third parties.

Reuse rights

The customer keeps control of what it submits and of what comes back: verdicts, reports, indicators and generated YARA rules can be reused in its own tooling without asking GLIMPS for permission — exporting a rule into an EDR, SIEM or NDR is a documented feature, not a tolerated side use. On the vendor's side the use is deliberately narrow. Article 12 of the terms limits processing to the purposes strictly necessary to perform the contract, imposes confidentiality on everyone authorised to handle the data, requires GLIMPS to notify the customer of any addition or replacement of a sub-processor with a right to object, and to report personal-data breaches without undue delay while assisting with data-subject requests and impact assessments. Commercial reuse is ruled out: the single declared purpose is analysing the submitted file and returning an enriched verdict, and analysed files are neither shared nor exposed. One restriction runs the other way — during the 30-day trial the customer undertakes to submit no personal data at all.

Data retention & training

Retention summary
For the product, retention is presented as fully configurable: the FAQ on the GLIMPS Malware Expert page says the retention of data and analyses can be set as the customer wishes. No figure is published — the site names no default period and no maximum, and the terms contain no retention clause with a duration in it. On premises, retention is entirely the customer's business, since no data leaves its infrastructure. One implication is worth noting: retrohunt searches the full history of submissions, which implies submissions are kept over time, again without a stated duration. The marketing website is a separate matter and does carry figures: contact-form data is kept for three years, and cookie consent stays valid for thirteen months. Nothing is published about anonymisation or about a deletion procedure for the solution itself.
Trains on customer data
No
DPA available
Yes
GDPR contact

Hosting summary

In SaaS, GLIMPS states that hosting takes place in France, and its product pages widen that to France and Europe. The FAQ presents SecNumCloud hosting as possible in SaaS mode — an option offered, not a qualification the company holds. The terms name two contractual SaaS arrangements: shared servers by default, or dedicated servers under a separate commercial proposal. The host acts as a sub-processor of GLIMPS, on written instruction, with no right to use the data. On premises, the question is settled differently: nothing leaves the customer's own infrastructure. One boundary matters for due diligence — the privacy policy describes the marketing website, not the solution. That site is hosted by OVH, 2 rue Kellermann, 59100 Roubaix, and its data is, in the policy's words, hosted and processed exclusively within the European Union. Finally, a gap worth noting: although the terms undertake to inform customers of any addition or replacement of a sub-processor, GLIMPS publishes no list of sub-processors.

Hosting countries
🇫🇷 France
Hosting regions
EU
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting GLIMPS.

  • No security certification of the vendor itself is published — no ISO 27001, no SOC 2. The page headed "certifications" lists awards; SecNumCloud appears as a possible hosting option and as a 2024 project prize, never as a qualification GLIMPS holds, and the CSPN/ANSSI mentions concern partner products, not GLIMPS.
  • The home-page figures — over 15 million files a day, 100+ customers, 70% less investigation time, a detection rate above 99% — are declarative and unaudited. The terms themselves state that GLIMPS guarantees neither exhaustive detection nor the absence of false positives, so a clean verdict must never be read as proof of harmlessness.
  • Automation invites over-trust. A three-second verdict is easy to accept without review; the tool is built to relieve analysts of triage, not to replace their judgement, and investigative skill erodes when the machine is never questioned.
  • No price is published, so no budget can be estimated before a commercial conversation — a structural asymmetry in the buyer's negotiating position.
  • Several reading traps around scope: the privacy policy covers the marketing website while the commitments applying to your submitted files sit in Article 12 of the terms; the policy names "www.glimps.fr" twice although it applies to www.glimps.re; and the domain uses the .re country code of Réunion even though the company operates from mainland France.
  • No list of sub-processors is published, even though the terms provide for informing the customer of any addition or replacement.
  • Submitting files means submitting content: in SaaS, business documents and potentially sensitive artefacts leave your perimeter. The terms forbid personal data outright during the free trial, and the on-premises option exists precisely for cases where nothing may leave.
Setup

Setup & Integrations

Technical difficulty

Difficulty varies with the mode of use. The free trial needs nothing technical: a web form, an account, and you are analysing files. The Kiosk is drag-and-drop from a browser, designed for non-specialists. Application integration is moderate: a REST API and Python or Go libraries, announced as a few lines of code. No-code routes exist too: a UBIKA reverse proxy or an ICAP connector. Deployment, SaaS or on premises, is announced in a few hours with no change to existing infrastructure. Heavier integrations — PAM, EDR, CI/CD, data diodes — do require a security or infrastructure team.

Deployment

Web appAPI

Integrations

MISP OpenCTI Splunk SEKOIA.IO Cortex XSOAR TheHive SentinelOne HarfangLab Gatewatcher WALLIX BeyondTrust UBIKA TYREX HOGO Thales ELIPS Moabi Nextcloud Jenkins GitLab CI GitHub Actions F5 Squid Microsoft 365 SharePoint OneDrive Google Workspace Gmail

Supported languages

FrenchEnglish
Company

Behind GLIMPS

Company name
GLIMPS
Founded
15/11/2019
Country of origin
🇫🇷 France
Headquarters
Cyber Place, 1179 Avenue des Champs Blancs, 35510 Cesson-Sevigne, France
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇫🇷 France
Support contact

Fundraising

Spring 2021: GLIMPS raised 6 million euros, a figure stated on the company's own About page.
Off-site sources place the announcement on 13 April 2021, with a round led by Ace Capital Partners alongside Breizh Up, the Brittany region's co-investment fund backed by the ERDF and managed by Sofimac Innovation.
Share capital stood at 159,706 euros in the legal notice dated 18 December 2025; BODACC records capital changes published on 27 January 2021, 18 August 2021 and 21 July 2023.
No later round was found. The Filigran partnership announced on 30 September 2025 is commercial, not financial.
Financial aggregators contradict each other on the amount (6.5 million euros, 1.50 million euros, 7.38 million US dollars) and are set aside: only the 6 million euro first-party figure is retained.

Social

Official links

Resources

All the official URLs gathered for verification and reference.

Compare

Alternatives

Tools that compete with or complement GLIMPS.

V VirusTotal
FAQ

Frequently asked questions

What exactly is GLIMPS Malware?
It is the technical core shared by the whole GLIMPS range: more than 25 detection engines, about ten of them AI-based, and eight proprietary AI models. Every product in the catalogue, from email security to the investigation console, calls that same engine.
Which file types can it analyse?
Any type. An orchestrator picks the engines suited to the file: Windows PE and Linux ELF binaries, JavaScript, Python and PowerShell scripts, archives and documents. An anti-phishing engine additionally inspects the URLs contained in the files.
How does it differ from an antivirus?
An antivirus still works from signatures and misses what it has never seen. GLIMPS analyses the code itself, which is how it claims to characterise unknown threats, variants and zero-days. The vendor positions it as a complement to antivirus and EDR, not a replacement.
How does it differ from a sandbox?
A sandbox observes behaviour over several minutes. GLIMPS returns a static verdict in about three seconds and embeds a CAPE sandbox as well, so dynamic detonation stays available when it is worth the wait. Artefacts from that detonation, memory dumps included, are then re-analysed by the static engines.
What does it add compared with VirusTotal?
Sovereignty first: analysed files are never shared or exposed, whereas a public multiscanner makes submissions visible to others. Then depth of analysis, and operational integration into SOC, SIEM, EDR and CTI tooling.
SaaS or on premises?
Both, with the same performance according to the vendor. In SaaS, hosting is in France and SecNumCloud hosting is presented as possible. On premises, no data leaves your own infrastructure.
Is it GDPR-compliant, and is GLIMPS certified?
The vendor states that GLIMPS Malware Expert is GDPR-compliant and NIS2-compatible, with fully configurable retention and French hosting in SaaS; Article 12 of the terms carries the Article 28 processing clause. On certification, be precise: GLIMPS publishes none of its own — no ISO 27001, no SOC 2. The page headed "certifications" lists awards, and SecNumCloud appears there as a hosting option and a project prize, never as a qualification the company holds.
How do I integrate it into my existing stack?
Through the REST API, the open-source Python and Go libraries, an ICAP connector or the Host Connector, plus native connectors for SOAR, SIEM, EDR and CTI platforms — SEKOIA.IO, Cortex XSOAR, TheHive, Splunk, MISP, OpenCTI, SentinelOne and HarfangLab among them. Alerts can be delivered by email and SYSLOG, results as PDF reports or JSON exports.
Is there a free trial?
Yes: 30 days on GLIMPS Malware Expert through the GLIMPS Gear Program portal, with access to the analysis modules and the Deep Engine. It is one per person and non-renewable, and the terms forbid submitting personal data during it. There is no permanent free plan.
How much does it cost?
No price is published. There is no pricing page on the site and no amount is quoted; every purchase goes through a commercial proposal, with invoices issued in euros and payable within thirty days.
Conclusion

Should you pick GLIMPS?

GLIMPS makes an unusual bet for a malware detection vendor: analyse the code rather than match a signature. That choice, born of work the founders carried out inside the French Ministry of the Armed Forces, is what supports the claim of catching zero-days and variants that signature-based tooling misses, and it comes with an assumed sovereignty stance — a French vendor, hosting in France and Europe, and submitted files that are never shared or exposed.

The credibility rests less on the marketing figures than on the references. The home-page numbers — over 15 million files a day, more than 100 customers, 70% less investigation time, a detection rate above 99% — are the vendor's own claims and have not been audited. The customers named, on the other hand, are checkable and demanding: ANSSI, the French armed forces, the Hospices Civils de Lyon.

The fit is clear. SOC, CERT/CSIRT, DFIR and CTI teams get a three-second verdict, a CAPE sandbox, retrohunt, MITRE ATT&CK mapping and YARA rules they can export into their own EDR, SIEM or NDR. Organisations under sovereignty or NIS2 pressure get an on-premises option in which nothing leaves their infrastructure.

Two reservations deserve to be stated plainly. Pricing is entirely opaque: no rate card, no starting price, no billing unit — a commercial proposal is the only way to learn what this costs. And despite a REST API that sits at the centre of the product, no public API documentation exists on the site, which makes technical scoping harder than it should be. Note too that GLIMPS publishes no security certification of its own.

A 30-day free trial on GLIMPS Malware Expert allows an evaluation without commitment — though the terms forbid submitting personal data during it.