independent security banner / est. 2026

SoyezSécurisé.

Security tools, adversarial experiments, and field notes—released under one name.

Soyez Sécurisé is not a company or a studio. It is the banner Fahis XD uses to give his security work a shared home.

/bulletin board

Upcoming & announcements

No announcements right now. Check back for updates.

01 / under the banner

Three systems. One security practice.

Each name belongs to a distinct tool. Soyez Sécurisé is the connective tissue: build it, test its assumptions, publish what remains true.

An experimental 3B cybersecurity input classifier fine-tuned from Ministral 3B. Run APEX locally through Ollama, or explore the original Neuris v1.

The model is not production-ready. The useful part right now is understanding exactly where it gets confused.

  • Python
  • SFT + LoRA
  • Ollama
Current
APEX 1.0
Stage
Public experiment
↗

Ayano

research tool

A CLI that turns a CVE into a useful starting point for vulnerability research.

It collects the context I usually need—NVD data, proof-of-concept searches, summaries, and research trails.

  • Python
  • NVD
  • GitHub
  • CLI
Type
CVE analysis
Use
Research
↗

02 / dispatches

Notes from inside the work.

All notes
All notes

/research archive

Writeups & discoveries.

Research, experiments, and lessons from the work.

Loading writeups…

03 / the identity

A banner, not a business.

Soyez Sécurisé—“be secure”—is a shared label for independent security work. It gives tools like Coffre, Neuris, and Ayano a common context without presenting them as products from a company that does not exist.

The person behind it is Fahis Shehandi, or fahisxd online. He builds the systems, runs the experiments, writes the notes, and takes responsibility for the rough edges. The name is larger than a username, but never larger than the truth.

build question break publish
  • Independent
  • Experimental
  • Security-minded
  • Open about limits

04 / simulated lab

Bored? Want to practise SQLi without bothering a real database?

Five small levels about input, queries, and observable behaviour. Entirely fictional. Mildly suspicious.

SQLi intuition / local simulation no external target

Simulated environment

The application has one secret. It will never print it.

Your job is to notice what changes anyway. No real database, host, or account exists behind this interface.