Product 01 / 3 capabilities
KRYOS-XS Edge
A browser-based security decision assistant that helps users evaluate suspicious messages, external data sharing, OAuth approvals and other consequential actions at the moment they occur.
Open KRYOS-XS EdgeFree for nonprofits, NGOs, think tanks, and institutes. Grant funded by James Scott, administered by the Embassy Row Project.
Cybersecurity portfolio
KRYOS-XS is a Cyber Decision Assurance Platform that converts cybersecurity evidence into safe, explainable, authorized and verifiable decisions.
KRYOS-XS protects decisions, not just systems. It detects consequential actions, determines what the evidence justifies, identifies who has authority, recommends the safest response and preserves proof of what the organization decided and why.
Instead of creating another stream of alerts, KRYOS-XS helps organizations understand what is happening, determine what the evidence justifies, identify who has authority, guide the safest response and preserve a complete decision record.
Operating model
ArtOfTheHack does not install software inside the organization. It authorizes against existing platforms, reads the evidence those platforms already expose, reasons over it, and returns a governed decision. Any consequential action is executed by the source system's own API, only after a named human approves it.
KRYOS does not claim evidence that a connected system cannot provide. When data is incomplete, the platform identifies the limitation and requests the appropriate human or technical input.
Shared operating model
The platform is one architecture applied to eleven different classes of security decision. The connectors and policies change. The sequence does not.
Stage 01
Approved integration with the minimum scope the capability requires.
Stage 02
A consequential security action or signal is identified for evaluation.
Stage 03
Available evidence is retrieved from the connected systems and its source and age recorded.
Stage 04
The Hypercube Decision Engine cross-checks facts, compares safe and dangerous explanations and applies policy.
Stage 05
Required authority is confirmed and a named human approves anything consequential.
Stage 06
The outcome is verified and preserved in the KRYOS Decision Ledger.
Launch product
A centralized Cyber Decision Operations Hub that converts alerts, identity risks, access questions, data exposures and response requirements into one prioritized decision queue.
Days 1 to 5
Then Connect and Observe
Days 6 to 12
Then Advisory Operation
Days 13 to 20
Then Gated Action
Days 21 to 26
Then Prove and Report
Days 27 to 30
Continue, modify or end
The pilot begins read-only. No consequential API action is permitted without named human approval, and the organization can withdraw the credentials at any point.
These are proposed validation thresholds agreed before a pilot starts. They are success criteria to be measured, not results already achieved and not a guarantee of any outcome.
Products
Edge decides at the moment of action inside approved work surfaces. The Console decides across the organization. Both run the same reasoning core, the same decision record, and the same governance rail.
Product 01 / 3 capabilities
A browser-based security decision assistant that helps users evaluate suspicious messages, external data sharing, OAuth approvals and other consequential actions at the moment they occur.
Open KRYOS-XS EdgeProduct 02 / 8 capabilities
A centralized Cyber Decision Operations Hub that converts alerts, identity risks, access questions, data exposures and response requirements into one prioritized decision queue.
Open KRYOS-XS ConsoleService explorer
Filter by product, expand any capability to read its six-stage sequence and hard boundary, or open the full service page.
Showing 11 of 11 governed capabilities across 2 of 2 products
Product 01 / 3 services
A browser-based security decision assistant that helps users evaluate suspicious messages, external data sharing, OAuth approvals and other consequential actions at the moment they occur.
Service 01
Determine whether a message appears legitimate, unwanted or malicious, and present the recommendation beside the message.
Boundary. Edge evaluates messages on approved work surfaces only. It does not inspect unrelated personal mail, and it does not replace the organization's mail platform or email security gateway.
Open the Suspicious Message Adjudication service pageService 02
Evaluate a sharing decision before sensitive information leaves the organization, and offer a safer method.
Boundary. Edge acts on approved collaboration surfaces and authorized API evidence only. Enforcement remains with the organization's own platform, and the visible interface never substitutes for authoritative security state.
Open the External Sharing and Data-Movement Governance service pageService 03
Identify configuration changes that may create unnecessary exposure, while the change is still being made.
Boundary. Edge combines the action a user is taking with authoritative API evidence when available. Where a connected system cannot evidence the configuration, the limitation is stated rather than inferred.
Open the Cloud Exposure and Configuration Decisioning service pageProduct 02 / 8 services
A centralized Cyber Decision Operations Hub that converts alerts, identity risks, access questions, data exposures and response requirements into one prioritized decision queue.
Service 04
Consolidate security alerts into a prioritized decision queue and connect related events so the broader situation is evaluated.
Boundary. KRYOS does not create raw telemetry and does not detect. It organizes and adjudicates what connected systems already report.
Open the Alert Triage and Incident Adjudication service pageService 05
Distinguish legitimate unusual behavior from potential account compromise using available identity evidence.
Boundary. Where evidence is insufficient, KRYOS escalates rather than creating false certainty. Enforcement runs in the organization's own identity platform.
Open the Account-Compromise Assessment service pageService 06
Identify unnecessary, outdated or unusually powerful access and recommend what should change.
Boundary. Only access exposed by a connected system can be reviewed. Access held on platforms without a supported API is stated as a coverage gap.
Open the Access and Entitlement Review service pageService 07
Understand who holds administrative authority, why it exists, whether it remains necessary and what compromise would cost.
Boundary. Privileged accounts absent from connected administrative APIs cannot be assessed. KRYOS does not replace an IAM or PAM platform.
Open the Privileged-Access Governance service pageService 08
Decide which external access should be retained, restricted, reviewed or revoked.
Boundary. External access on systems that expose no API is out of scope and is reported as a gap rather than assumed to be absent.
Open the External-Party Access Governance service pageService 09
Evaluate applications, integrations and automated agents requesting organizational access, before and after the grant.
Boundary. Grants absent from connected administrative APIs cannot be assessed, and no secret or token material is collected.
Open the OAuth and Automation Authority Governance service pageService 10
Guide teams through structured response without depending on anyone remembering every step during a crisis.
Boundary. Every consequential action requires human authorization, and action is possible only where the existing platform exposes a supported API.
Open the Guided Incident and Response Workflows service pageService 11
Turn the accumulated Decision Ledger into clear institutional reporting generated from real decision history.
Boundary. Reports are generated from the organization's actual decision history. KRYOS does not assert compliance and does not reconstruct evidence that was never recorded.
Open the Board, Funder and Framework Reporting service pageEvery capability in this platform is provided at no cost to eligible nonprofits, NGOs, think tanks, and nonprofit research institutes under a grant funded by James Scott and administered by the Embassy Row Project.