Architecture
The Cybersecurity Decision Control Plane
ArtOfTheHack sits above the security systems already in operation. Evidence flows in through scoped connectors, is reconciled and tested, is reasoned over across interacting dimensions, and leaves as a governed decision that an authorized human or an approved system executes.
What is the ArtOfTheHack architecture?
The ArtOfTheHack architecture is a non-intrusive cybersecurity decision layer. It sits beside the control path rather than inside it: evidence is read from existing security systems through scoped APIs, reasoned over by KRYOS-XS Hypercube, and returned as a governed decision object that a human approves and an existing system enforces.
- How it works
- Connectors read from the systems already in place. Records are normalized to a common schema, scored for reliability and freshness, reasoned across identity, asset, adversary, consequence, and authority dimensions, and returned as a recommendation with confidence and uncertainty stated.
- What it connects to
- Identity and access platforms, endpoint and mobile tooling, email and collaboration suites, cloud posture services, network and DNS logs, backup systems, SIEM, XDR, SOAR, and threat intelligence feeds.
- What it does not replace
- It does not replace your firewall, EDR, identity provider, SIEM, or backup platform, and it does not become the enforcement point. Every existing tool keeps its job.
- Authority boundary
- The overlay recommends. A named person inside the grantee organization authorizes. Actions above the agreed threshold cannot execute without that approval, and no action executes without a defined reversal path.
- Evidence used
- Only telemetry the organization already produces, read under least-privilege scopes: authentication events, device state, mail metadata, cloud configuration, alert records, and asset inventory.
- Outputs
- A governed decision object for each question: the evidence considered, contradictions found, confidence and uncertainty, the recommended action, the authority required, the expiry, and the rollback procedure.
- Deployment
- Read-only integration first, then shadow evaluation against decisions your team is already making, then approval-gated production, and only then bounded automation for reversible actions.
- Limitations
- It cannot see what your tools do not collect, it cannot make an unrecoverable action safe, and it does not replace staff judgment, legal counsel, or an incident response retainer.
End to end
Security Systems, Evidence, Reasoning, Decision, Response, Calibration
The overlay is non-intrusive. Systems of record and enforcement remain authoritative, and every write path runs through a connector the grantee organization can revoke independently.
ArtOfTheHack does not replace SIEM, XDR, EDR, NDR, SOAR, IAM, PAM, ZTNA, CNAPP, DLP, or cloud control planes. It operates above them as a non-intrusive API overlay and returns governed decisions to those systems.
- Telemetry in
- Governed decision
- Approved response
- Outcome and calibration back to evidence
Reference architecture
The Full Stack, Layer by Layer
Select any layer to read what it does, what it refuses to do, and where authority stays with the grantee organization.
Organization cybersecurity architecture
KRYOS-XS Hypercube as a Non-Intrusive Decision Overlay
The overlay sits above the XDR, SIEM, SOAR and Zero Trust stack already in operation and returns evidence-governed decisions to the controls that already hold authority.
Feedback loop: layer 7 outcomes return to layer 3 evidence and recalibrate layer 4 reasoning
Layer 3
KRYOS-XS Hypercube Reasoning Layer
Reasoning is multidimensional rather than rule-by-rule. Competing hypotheses are held simultaneously, dissent is preserved instead of resolved by majority, and candidate responses are compared on blast radius, reversibility, and business impact before one is recommended.
Seven layers
Inspect Each Layer
Switch between the executive view and the technical view. Select a layer to review its inputs, processing, outputs, governance, and security boundaries.
- IdP
- IAM
- PAM
- ZTNA
- EDR
- NDR
- SIEM
- XDR
Governance rail
- Human in the loop
- Approval thresholds
- Separation of duties
- Policy constraints
- Reversibility checks
- Blast-radius limits
- Audit logging
- Compliance mapping
- Kill switch
- Native fallback
Intelligence does not equal authority. KRYOS-XS Hypercube may analyze. Policy determines authority. Approved systems execute.
Layer five
The Governed Decision Object
The decision object is the interface between machine reasoning and human authority.
Governed Decision Object
Illustrative platform visualization
- Decision ID
- DEC-4417-IDENT
- Status
- Awaiting authority
- Risk
- High
- Confidence
- 0.78
- Uncertainty
- Device telemetry gap, 14 minutes
- Identity provider
- Impossible travel, two regions, 41 minutes apart
- Endpoint platform
- No malicious process observed on the registered device
- Network
- Session originated from a residential proxy range
- Data platform
- Access to a regulated dataset attempted twice
- Evidence quality
- Three independent sources, one derived source excluded
Architecture documentation describes structure and governance. Proprietary algorithms, scoring thresholds, model configuration, and prompt design are not published.
