Resources
Foundational writing on governed decisioning
Reference material for architects, risk owners, and executives evaluating a decision-control layer.
Articles
Foundational articles
8 minute read
Why Security Operations Fail at Decision Quality
Detection coverage has improved for a decade. The quality of the decisions made on top of that coverage has not.
7 minute read
The Governed Decision Object
The signature artifact of evidence-governed cybersecurity: a complete, replayable record of what was known, what was concluded, and who authorized the action.
8 minute read
Zero Trust Is a Decision Problem
Identity, device, and network controls are enforcement. Zero trust maturity depends on the quality of the decision that precedes enforcement.
9 minute read
Governing Autonomous Agents in Security Operations
Agents are entering security operations faster than the controls that should bound them. Authority, reversibility, and evidence are the prerequisites.
7 minute read
Modeling Blast Radius Before You Act
Containment decisions are consequence decisions. A digital twin of the environment lets teams test the response before it reaches production.
8 minute read
Evidence Standards for Cyber Decisions
Not all telemetry is equal. Reliability, freshness, independence, and corroboration determine what an assertion can support.
9 minute read
What Is Evidence-Governed Decision Infrastructure?
A working definition of the decision-control layer that sits between organization evidence and consequential action.
8 minute read
Why the Agentic Organization Requires a Decision Control Plane
Agents are being connected to production systems faster than institutions can define what those agents may decide, spend, or execute.
10 minute read
From Telemetry to Governed Action
How fragmented signal becomes normalized evidence, adjudicated hypotheses, and a defensible instruction to an existing system.
8 minute read
Human Authority, Reversibility, and Auditability in Automated Systems
Three properties determine whether an institution can defend an automated decision after the fact.
FAQ
Frequently asked questions
Architecture FAQ
- Does ArtOfTheHack replace our existing security or organization systems?
- No. ArtOfTheHack operates above existing systems as a non-intrusive API overlay. Systems of record and enforcement remain unchanged and continue to operate independently if ArtOfTheHack is unavailable.
- How does ArtOfTheHack connect to our environment?
- Through REST APIs, webhooks, event streams, batch ingestion, secure file transfer, message queues, database connectors, grantee organization-controlled gateways, SDKs, and private connectors. Read-only scopes are the default starting point.
- What is the Hypercube?
- KRYOS-XS Hypercube is the reasoning core that evaluates interacting dimensions such as identity, system state, exposure, business impact, policy, time, authority, reversibility, and uncertainty for a single decision.
- What is a governed decision object?
- It is the record the KRYOS Decision Ledger stores for one decision: the determination, evidence, contradictions, risk, confidence, uncertainty, required authority, approval status, controls, validity window, rollback plan, and version information. Every governed decision object is produced by the Hypercube Decision Engine and written to the Ledger.
- Can decisions be replayed later?
- Yes. Decision records retain the evidence set, the policy version, and the model version in force, so an independent reviewer can re-derive the determination.
Product FAQ
- Where should an organization start?
- With one consequential workflow. Connect the relevant systems, run in read-only shadow mode, establish a measurable baseline, then decide which operating mode fits the consequence of that workflow.
- What is the difference between a product and a decision capability?
- A product is where the decision happens. KRYOS-XS Edge decides at the moment of action inside approved work surfaces, and KRYOS-XS Console decides across the organization. A capability is one governed decision sequence inside a product. The reasoning core, the decision record, and the governance rail are identical across all of them.
- Does ArtOfTheHack make decisions automatically?
- Only where the grantee organization explicitly authorizes bounded automatic mode, and only for predefined, reversible, policy-authorized actions within grantee organization-defined limits. Advisory and approval-gated modes are the defaults.
- How are the eleven capabilities related to the two products?
- Edge carries three capabilities that run at the moment a user takes a risky action. The Console carries eight that run across the organization. Every capability runs the same six-stage sequence over authorized evidence, so the platform is one architecture applied to eleven classes of security decision, not eleven separate technology stacks.
- Which product does an organization start with?
- KRYOS-XS Console is the launch product, connected first to Google Workspace. The nonprofit pilot begins read-only, moves to advisory operation, and only reaches approval-gated remediation after a named human authority approves each class of action.
Security FAQ
- Where is our data processed?
- That depends on the deployment model. Options include multi-tenant cloud, dedicated private cloud, deployment inside the organization's own cloud account, and on-premises or isolated installation. Availability depends on the grant tier awarded and the organization's requirements.
- Is our data used to train shared models?
- No, not without explicit written authorization from the grantee organization.
- Which certifications does ArtOfTheHack hold?
- Certification status is provided under contract. ArtOfTheHack does not claim certifications on this website that have not been achieved.
- What happens if ArtOfTheHack is unavailable?
- Existing systems continue operating under their own controls. Native fallback is an architectural requirement, not an optional feature.
- Can automation be stopped immediately?
- Yes. Automation can be halted at workflow, environment, or tenant scope, and connector credentials can be revoked independently.
Partnership FAQ
- What partnership models are available?
- Coalition sponsorship, funder-backed sector awards, connector partnerships, sector policy packs, joint deployment support, and systems-integration partnerships delivered pro bono into the grant program.
- Can a vendor embed ArtOfTheHack capabilities in its own product?
- Yes, through the read-only connector library and authorized APIs, with the governance surface preserved so grantee organizations retain visibility into evidence, authority, and reversibility.
- Who owns the core architecture?
- ArtOfTheHack owns or controls the core architecture, brand, decision ontology, and software. Access for nonprofits is granted, never sold.
- How do systems integrators participate?
- Through implementation partnerships covering connector work, policy design, workflow rollout, and enablement, supported by ArtOfTheHack Academy certification.
