Paris-based collaborative IPS and behaviour detection; open-source core with paid threat intelligence.
A curated list of cybersecurity vendors headquartered in the European Union, in the SIEM & observability category. A sovereign alternative to foreign SIEM and log analytics platforms.
4 vendors listed · last reviewed July 2026
Paris-based collaborative IPS and behaviour detection; open-source core with paid threat intelligence.
Copenhagen-based SIEM and SOAR vendor with EU-resident SaaS option.
Polish security operations platform combining SIEM, SOAR, UEBA and risk-based vulnerability management.
Paris-based detection and response platform combining SIEM, SOAR and threat intelligence.
CipherCue tracks 4 vendors headquartered in the European Union or EEA in the SIEM & observability category. Listings are editorial; inclusion criteria, ownership, and certification details are visible on each card.
EU-headquartered vendors keep customer data inside the European Union by default, sit fully under GDPR jurisdiction, and align procurement with NIS2 and DORA sovereignty expectations. Replacing foreign SIEM and log analytics platforms also reduces exposure to extra-territorial data requests under non-EU legal regimes such as the US CLOUD Act.
The SIEM & observability vendors in this directory are headquartered in Denmark, France, and Poland. Use the country filter at the top of the page to narrow the list to a specific jurisdiction.
If you run or know an EU-headquartered SIEM & observability vendor that should be here, email hello@ciphercue.com with the name and HQ country.
Listings are editorial and not a recommendation. Inclusion, amendment, and removal are at CipherCue's discretion. See our directory listing terms.
← Back to all European cybersecurity vendors