
INLYSE
INLYSE is a German cybersecurity vendor whose patented Visual AI turns files into images so that malware shows up structurally, without signatures, and pairs that engine with file sanitization and a human incident response, forensics and pentesting team.
What is INLYSE?
INLYSE is a cybersecurity platform built by INLYSE GmbH, a company registered in Karlsruhe, Germany (Amtsgericht Mannheim, HRB 731836) and run by Julian Ziegler and Christian Boll. Its central idea, marketed as Visual AI, is unusual: rather than matching signatures, the engine converts a file into a graphical representation, where a structural anomaly stands out much as a shadow does on an X-ray. The method is patented — US Patent 9,111,094 B2 is linked straight from the product page, with a European grant in 2024 and Chinese and US grants following.
Analysis is purely static, so the sample never has to be executed. A multi-tier engine combines heuristics, machine learning and deep neural networks; the file is split into correlated chunks and several independent classifiers score it in parallel. INLYSE claims 99.8% detection, under 0.1% false positives, a verdict in less than 50 ms and 50+ supported formats — though the homepage says 99.9% and the CDR page says 100+ formats, so read the numbers as orders of magnitude.
Three blocks are live today. Malware Detection is the engine itself. Malware Analysis turns a verdict into a readable report: object tree, per-classifier confidence scores, named heuristics such as embedded files, JavaScript, open actions or CVE exploitation, and a MITRE ATT&CK matrix — the vendor insists this is deliberately not a black box. INLYSE CDR behaves like an airlock: every document is treated as hostile, macros, scripts, OLE objects and metadata are stripped, and a clean file is rebuilt from legitimate content alone, in under five seconds, as an EU-West cloud API or as an on-premise or air-gapped appliance. Two further products, VulnScan and Darknet Scan, are still labelled Coming Soon.
Around the software sits a services arm covering the before, during and after of an incident: incident response, penetration testing, forensics with chain of custody, malware analysis, ISO 27001, GDPR and BSI-Grundschutz audits, readiness workshops, awareness training and system hardening. Remote incident response starts within four hours on business days and on-site help within 24 hours; the contractual SLA sets monthly availability at 99% or better.
What it does
- Screen a file with static AI analysis and get a verdict plus a confidence score in under 50 ms
- Generate an analysis report with an object tree, per-classifier results, named heuristics and MITRE ATT&CK mapping
- Sanitize documents with CDR, which deconstructs, disarms and rebuilds a clean file in seconds
- Embed detection through a REST API, a native C SDK or Python, Go and JavaScript bindings
- Run the engine on-premise, on an air-gapped appliance or from the EU-West cloud region
- Call in people for incident response, digital forensics, penetration testing, audits and awareness training
- Track CVE exposure and darknet leaks — announced as Coming Soon, not yet available
When to use INLYSE / When not to
A quick filter to help you decide if INLYSE is the right fit.
When to use INLYSE
- Security teams that want a signature-independent detection layer on top of an existing antivirus stack
- Software vendors and integrators embedding a scanning engine through the native C SDK or its Python, Go and JavaScript bindings
- Organizations sanitizing inbound file flows across email gateways, file transfer and collaboration tools
- Companies working under NIS2, GDPR, ISO 27001 or BSI-Grundschutz that need audits, readiness workshops and awareness training
- Public bodies and companies without an in-house SOC that need EU or on-premise deployment and emergency incident response
When not to use INLYSE
- Private individuals: the license covers use within the licensee's professional activity only
- Self-service buyers who expect published prices, an online checkout or a trial without talking to sales
- Teams looking to replace their antivirus outright rather than add a complementary detection layer
- Anyone who needs VulnScan or Darknet Scan today, as both product pages are still marked Coming Soon
- Developers who want to assess the API from public documentation before committing, since none is published
How to use INLYSE
A typical end-to-end flow, from setup to results.
- Start from the contact form or the free initial consultation page — there is no self-service sign-up
- State your topic: malware analysis, a security incident, an audit, a penetration test, darknet monitoring or something else
- Fill in name, email, phone, company, subject and message, and accept the privacy policy; INLYSE promises a reply within 24 hours
- For an initial consultation, expect a callback within four hours on business days, 8am to 6pm, free and without obligation
- In an emergency, call the direct line rather than opening a ticket
- Agree the scope and sign: the contract fixes the number of authorized users and a term of either one or twelve months
- Receive your credentials after signature, plus a license key for the engine
- Use the software in the browser — it is delivered over the internet, with nothing for end users to install
- For the SDK, initialize the engine with a model directory, a thread count and the license key, then call the scan function on a file
- For CDR, instantiate the client with an API key and call disarm_file on each document; user documentation stays available for the whole subscription
Pros & Cons
Pros
- Signature-free detection, claimed to work on zero-day and obfuscated malware that pattern matching misses
- Explainable output: per-classifier scores, named heuristics and MITRE ATT&CK mapping instead of a bare verdict
- Patents granted in Europe (2024), China (2025) and the United States (2026)
- European sovereignty: German vendor, Azure processing guaranteed in EU data centres, on-premise and air-gapped options
- Software and human expertise from one supplier, from automated screening to manual reverse engineering
- Commitments written down and quantified: 99% monthly availability, critical faults handled within two hours, replies within 24 hours, on-site incident response within 24 hours
- A processing agreement is offered as soon as personal data is involved, and the website's subprocessors are named one by one
Cons
- No public pricing whatsoever: no pricing page, no figure and no tier anywhere among the site's 66 sitemap URLs
- No public API documentation and no docs or api subdomain — only code snippets on the product pages
- Two of the four featured products, VulnScan and Darknet Scan, plus two services, are announced rather than available
- The site contradicts itself: 14-day trial on the products page against 30 days in the terms, 99.9% against 99.8% detection, 50+ against 100+ formats
- Terms and privacy policy are still dated 27 June 2022 and describe software supply only, although the services catalogue opened in 2024
- No trust or security page, and no ISO 27001 certification claimed for INLYSE itself even though it audits clients against that standard
- Nothing published on model training with customer data or an opt-out, and no mobile app, self-service trial or online demo
Pricing & Plans
There is no free plan and no published price. INLYSE sells through its sales team: the site carries no pricing page, no amount and no tier, and every call to action leads to the contact form or to a free initial consultation. Under § 10 of the terms, the fee is agreed either monthly or annually, is quoted in EURO net of statutory VAT and is payable before the software is made available, by PayPal or Stripe; INLYSE reserves the right to adjust it, any change taking effect one month after notice and opening a right of termination. Contracts run for one month or twelve months, renewable with one month's notice, and the number of authorized users is fixed in the contract, so cost scales with seats. A free trial is granted once per customer after registration, but its length is stated inconsistently across the site: 14 days on the products page, 30 days in the terms (§ 15 (1)), and three months for VulnScan early access. Initial consultations and the advertised risk analysis are free and without obligation. Expect to negotiate; ask for the trial length and the renewal terms in writing.
- products
- services and training are all quoted individually after a sales conversation
- Licensed products
- billed per authorized user for a term of either one month or twelve months
- renewable with one month's notice
- cloud API in the EU-West region
- or an on-premise appliance
- incident response
- penetration testing
- forensics
- malware analysis
- audits
- workshops and training
- Free one-off trial after registration
- and a launch notification list giving early access to VulnScan and Darknet Scan
Data, GDPR & hosting
A consolidated view of how INLYSE handles your data.
GDPR overview
GDPR implementation is explicit, though self-declared rather than certified. The privacy policy is written expressly under the GDPR, is dated 27 June 2022, and a “DSGVO-konform” badge appears in the footer of every page. Data subject rights are named article by article: access (Art. 15), rectification (16), erasure (17), restriction (18), notification (19), portability (20), withdrawal of consent (Art. 7(3)) and complaint to a supervisory authority (Art. 77), with the right to object under Art. 21(1) and (2) set in capitals. Microsoft is named as an Art. 28 processor guaranteeing processing exclusively in EU data centres; processing agreements are named with Cloudflare and HubSpot, and § 16 (2) of the terms commits INLYSE to one with the customer. As a German controller it needs no Art. 27 representative. No data protection officer is named.
Who owns the data?
The terms leave customer data with the customer. Where INLYSE accesses personal data, § 16 (2) of the AGB requires a processing agreement concluded together with the main contract, after which INLYSE may act only on the licensee's instructions; § 16 (3) extends confidentiality to employees and subcontractors. When the contract ends, the licensee returns or destroys the documentation, use of the software stops and the user account is deleted. § 15 (6) states expressly that INLYSE holds no right of retention or lien over the data. The privacy policy adds that a customer account can be deleted at any time on a simple message to the controller, INLYSE GmbH in Karlsruhe.
Reuse rights
The privacy policy, effective 27 June 2022, ties every collection to a stated purpose and a legal basis. Server logs (URL, timestamp, volume transferred, referrer, browser, operating system and an IP address that may be anonymized) rest on legitimate interest under Art. 6(1)(f), and the policy states plainly that these data are neither passed on nor used for anything else. Contact form entries serve only to answer the enquiry, on legitimate interest or on Art. 6(1)(b) where a contract is at stake, and are erased once the matter has been definitively dealt with. The newsletter runs on double opt-in consent under Art. 6(1)(a), with the subscription IP and timestamp kept as evidence. Marketing and audience measurement go through HubSpot and Matomo Cloud; payments go through PayPal in Luxembourg or Stripe Payments Europe in Dublin, depending on the method chosen; job applications are erased at the latest six months after notification. Nowhere does INLYSE claim a right to reuse customer content beyond delivering the service, and nowhere does the site mention training models on customer data or an opt-out from it.
Data retention & training
Hosting summary
The website, order handling and customer management run on Microsoft Azure. Microsoft is named as an Art. 28 processor acting on instructions and, per the privacy policy, guarantees that processing takes place exclusively in data centres located inside the European Union, though no individual country is named. Content delivery uses Cloudflare Inc. in San Francisco, covered by a processing agreement, with EU-US transfers relying on the European Commission's standard contractual clauses, and KeyCDN, operated by proinity GmbH in Winterthur, Switzerland. For the product itself, the CDR page advertises a single cloud region, EU-West. The site's own server resolves to 45.129.183.242, hosted by netcup GmbH in Nuremberg, Germany. Customers who cannot use shared infrastructure can request an on-premise installation in their own data centre, a hardware appliance or virtual machine, or a fully air-gapped deployment. In short: an EU region guaranteed contractually for the website and customer data, EU-West for the CDR API, US and Swiss providers in the delivery chain, and a sovereign option on request. The policy carries an effective date of 27 June 2022.
Things to keep in mind
Risks and trade-offs to weigh before adopting INLYSE.
- The free trial length contradicts itself across the site: 14 days on the products page, 30 days in the terms, three months for VulnScan early access. Get the duration written into your contract
- Headline figures shift between pages (99.9% against 99.8% detection, 50+ against 100+ formats), and the homepage counters are decorative animations that display zero without JavaScript
- VulnScan and Darknet Scan are laid out like shipping products but carry a Coming Soon label; two services are marked Soon. Do not build a roadmap on them
- Market statistics quoted on the site (EUR 4.5 million per incident, 277 days to detection, 83% of companies attacked) are given without any source
- § 17 of the terms allows INLYSE to change the conditions unilaterally, with tacit acceptance if you do not object within four weeks, and § 10 (2) allows a unilateral price adjustment after one month's notice
- The terms and privacy policy date from 27 June 2022 and cover software supply only, so the services opened in 2024 sit outside what the published documents describe
- INLYSE audits clients against ISO 27001 and BSI-Grundschutz but publishes no certification of its own, and says nothing about whether submitted files feed model training. No detection layer, however accurate, removes the need for patching, backups and staff who still think before clicking
Setup & Integrations
Technical difficulty
Moderate, and gated by contract rather than by complexity. There is no self-service sign-up: you sign first, then receive credentials and a license key. Day-to-day use is browser-based, so end users install nothing. The work sits in integration: compiling against a native C library or calling the REST API, deploying a model directory, setting a thread count and supplying the license key for the on-premise engine, or instantiating a CDR client with an API key. Expect developer involvement, and note that user documentation only becomes accessible once the service is subscribed.
Deployment
Behind INLYSE
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
Which INLYSE products can I actually buy today?
How does the detection engine work without signatures?
How fast is INLYSE, and how accurate?
Is there a free trial?
How much does INLYSE cost?
How do I integrate it into my own systems?
Where is the data hosted?
Is a data processing agreement available?
What happens to my data when the contract ends?
How quickly does the team react to an incident?
Should you pick INLYSE?
INLYSE is easier to place once you accept what it is not: it does not claim to replace your antivirus. It sells a complementary, signature-free detection layer, an analysis report you can actually read, and a sanitization service that rebuilds documents rather than merely scanning them. The technical credibility is real — patents granted in Europe, China and the United States, a method that is explained rather than hinted at, and results deliberately exposed classifier by classifier instead of a single opaque verdict.
What makes the vendor unusual at its size is the pairing of software with people: the same company that ships an engine also sends forensic specialists and ethical hackers, with response times written down. For a mid-sized company or a public body in German-speaking Europe looking for a local partner — and for software vendors who want to embed a scanning engine via SDK — that combination is genuinely hard to find elsewhere.
The reservations are commercial rather than technical. Nothing is priced, nothing is documented publicly for developers, and there is no way in except through a sales conversation, which makes any comparison with competitors slow. Maturity is uneven: two of the four showcased products are still announcements. And the legal documents have been frozen since 27 June 2022, while the catalogue has expanded considerably since — they describe software supply, not the services arm opened in 2024.
Treat INLYSE as a supplier to talk to rather than a tool to try. Come with your file formats, your volumes and your deployment constraints, ask for the trial length in writing, and ask what happens to the files you submit. On those terms, it is a serious and specific option.
- Choosing a selection results in a full page refresh.
- Opens in a new window.