Skip to content

Free for nonprofits, NGOs, think tanks, and institutes. Grant funded by James Scott, administered by the Embassy Row Project.

ArtOfTheHack home

Architecture

The Cybersecurity Decision Control Plane

ArtOfTheHack sits above the security systems already in operation. Evidence flows in through scoped connectors, is reconciled and tested, is reasoned over across interacting dimensions, and leaves as a governed decision that an authorized human or an approved system executes.

What is the ArtOfTheHack architecture?

The ArtOfTheHack architecture is a non-intrusive cybersecurity decision layer. It sits beside the control path rather than inside it: evidence is read from existing security systems through scoped APIs, reasoned over by KRYOS-XS Hypercube, and returned as a governed decision object that a human approves and an existing system enforces.

How it works
Connectors read from the systems already in place. Records are normalized to a common schema, scored for reliability and freshness, reasoned across identity, asset, adversary, consequence, and authority dimensions, and returned as a recommendation with confidence and uncertainty stated.
What it connects to
Identity and access platforms, endpoint and mobile tooling, email and collaboration suites, cloud posture services, network and DNS logs, backup systems, SIEM, XDR, SOAR, and threat intelligence feeds.
What it does not replace
It does not replace your firewall, EDR, identity provider, SIEM, or backup platform, and it does not become the enforcement point. Every existing tool keeps its job.
Authority boundary
The overlay recommends. A named person inside the grantee organization authorizes. Actions above the agreed threshold cannot execute without that approval, and no action executes without a defined reversal path.
Evidence used
Only telemetry the organization already produces, read under least-privilege scopes: authentication events, device state, mail metadata, cloud configuration, alert records, and asset inventory.
Outputs
A governed decision object for each question: the evidence considered, contradictions found, confidence and uncertainty, the recommended action, the authority required, the expiry, and the rollback procedure.
Deployment
Read-only integration first, then shadow evaluation against decisions your team is already making, then approval-gated production, and only then bounded automation for reversible actions.
Limitations
It cannot see what your tools do not collect, it cannot make an unrecoverable action safe, and it does not replace staff judgment, legal counsel, or an incident response retainer.

End to end

Security Systems, Evidence, Reasoning, Decision, Response, Calibration

The overlay is non-intrusive. Systems of record and enforcement remain authoritative, and every write path runs through a connector the grantee organization can revoke independently.

ArtOfTheHack does not replace SIEM, XDR, EDR, NDR, SOAR, IAM, PAM, ZTNA, CNAPP, DLP, or cloud control planes. It operates above them as a non-intrusive API overlay and returns governed decisions to those systems.

EXISTING SECURITY TELEMETRYIDENTITYENDPOINTNETWORKCLOUDSIEMXDRSOARVULNERABILITIESTHREAT INTELLIGENCEDATA SECURITYEVIDENCE FABRICNormalize · Resolve · Score · ContradictKRYOS-XSHYPERCUBEGOVERNED CYBER DECISIONEvidence · Confidence · Authority · RollbackADVISORYAPPROVAL-GATEDBOUNDED AUTONO EXECUTIONAPPROVED RESPONSEExecuted in existing enforcement systemsOUTCOME + CALIBRATION
  • Telemetry in
  • Governed decision
  • Approved response
  • Outcome and calibration back to evidence

Reference architecture

The Full Stack, Layer by Layer

Select any layer to read what it does, what it refuses to do, and where authority stays with the grantee organization.

Organization cybersecurity architecture

KRYOS-XS Hypercube as a Non-Intrusive Decision Overlay

The overlay sits above the XDR, SIEM, SOAR and Zero Trust stack already in operation and returns evidence-governed decisions to the controls that already hold authority.

Feedback loop: layer 7 outcomes return to layer 3 evidence and recalibrate layer 4 reasoning

Layer 3

KRYOS-XS Hypercube Reasoning Layer

Reasoning is multidimensional rather than rule-by-rule. Competing hypotheses are held simultaneously, dissent is preserved instead of resolved by majority, and candidate responses are compared on blast radius, reversibility, and business impact before one is recommended.

Seven layers

Inspect Each Layer

Switch between the executive view and the technical view. Select a layer to review its inputs, processing, outputs, governance, and security boundaries.

View
    • IdP
    • IAM
    • PAM
    • ZTNA
    • EDR
    • NDR
    • SIEM
    • XDR

Governance rail

  • Human in the loop
  • Approval thresholds
  • Separation of duties
  • Policy constraints
  • Reversibility checks
  • Blast-radius limits
  • Audit logging
  • Compliance mapping
  • Kill switch
  • Native fallback

Intelligence does not equal authority. KRYOS-XS Hypercube may analyze. Policy determines authority. Approved systems execute.

Layer five

The Governed Decision Object

The decision object is the interface between machine reasoning and human authority.

Governed Decision Object

Illustrative platform visualization

Decision ID
DEC-4417-IDENT
Status
Awaiting authority
Risk
High
Confidence
0.78
Uncertainty
Device telemetry gap, 14 minutes
Identity provider
Impossible travel, two regions, 41 minutes apart
Endpoint platform
No malicious process observed on the registered device
Network
Session originated from a residential proxy range
Data platform
Access to a regulated dataset attempted twice
Evidence quality
Three independent sources, one derived source excluded

Architecture documentation describes structure and governance. Proprietary algorithms, scoring thresholds, model configuration, and prompt design are not published.