Skip to content

Free for nonprofits, NGOs, think tanks, and institutes. Grant funded by James Scott, administered by the Embassy Row Project.

ArtOfTheHack home

Cybersecurity portfolio

Two Integrated Cybersecurity Products. Eleven Governed Decision Capabilities.

KRYOS-XS is a Cyber Decision Assurance Platform that converts cybersecurity evidence into safe, explainable, authorized and verifiable decisions.

KRYOS-XS protects decisions, not just systems. It detects consequential actions, determines what the evidence justifies, identifies who has authority, recommends the safest response and preserves proof of what the organization decided and why.

Instead of creating another stream of alerts, KRYOS-XS helps organizations understand what is happening, determine what the evidence justifies, identify who has authority, guide the safest response and preserve a complete decision record.

Operating model

A non-replacement cybersecurity intelligence layer

ArtOfTheHack does not install software inside the organization. It authorizes against existing platforms, reads the evidence those platforms already expose, reasons over it, and returns a governed decision. Any consequential action is executed by the source system's own API, only after a named human approves it.

What the platform uses

  • Approved work surfaces and authorized APIs
  • Inline decision support at the moment of action
  • Cross-source correlation of available evidence
  • Explainable recommendations with confidence and uncertainty
  • Approval-gated action in the organization's own systems
  • Complete decision logging in the KRYOS Decision Ledger
  • Outcome verification and board-ready reporting

What the platform never uses

  • Replacement of existing security products
  • Unrelated personal browsing collection
  • Endpoint agents, appliances or packet capture
  • Independent malware detection
  • Hidden or unsupported data access
  • Autonomous consequential action
  • Claims a connected system cannot evidence

KRYOS does not claim evidence that a connected system cannot provide. When data is incomplete, the platform identifies the limitation and requests the appropriate human or technical input.

Shared operating model

Six stages, applied identically to every capability

The platform is one architecture applied to eleven different classes of security decision. The connectors and policies change. The sequence does not.

  1. Stage 01

    Authorize

    Approved integration with the minimum scope the capability requires.

  2. Stage 02

    Detect

    A consequential security action or signal is identified for evaluation.

  3. Stage 03

    Gather

    Available evidence is retrieved from the connected systems and its source and age recorded.

  4. Stage 04

    Reason

    The Hypercube Decision Engine cross-checks facts, compares safe and dangerous explanations and applies policy.

  5. Stage 05

    Authorize action

    Required authority is confirmed and a named human approves anything consequential.

  6. Stage 06

    Verify and record

    The outcome is verified and preserved in the KRYOS Decision Ledger.

Non-negotiable across every capability

  • Read-only advisory operation by default
  • Human approval for high-impact actions
  • Least-privilege, revocable permissions
  • Explicit blind spots instead of assumed facts
  • Reversible enforcement wherever technically available
  • Every action and outcome is verified against the source system

Operating principle

  • Evidence before inference.
  • Authority before action.
  • Verification before assurance.

Launch product

KRYOS-XS Console is the flagship first product

A centralized Cyber Decision Operations Hub that converts alerts, identity risks, access questions, data exposures and response requirements into one prioritized decision queue.

The nonprofit pilot sequence

  1. Days 1 to 5

    Assess and Authorize

    • Initial security assessment
    • Least-privileged Workspace scopes
    • Approved surface definition

    Then Connect and Observe

  2. Days 6 to 12

    Connect and Observe

    • Google Workspace connection
    • Console decision queue populated
    • No recommendations shown yet

    Then Advisory Operation

  3. Days 13 to 20

    Advisory Operation

    • Edge deployed to approved surfaces
    • Inline verdicts delivered
    • Administrator accept or reject rationale

    Then Gated Action

  4. Days 21 to 26

    Gated Action

    • Named human approval
    • Low-complexity supported actions
    • Before and after verification

    Then Prove and Report

  5. Days 27 to 30

    Prove and Report

    • Decision Ledger reconciliation
    • Board and funder report
    • Continue, modify or terminate

    Continue, modify or end

The pilot begins read-only. No consequential API action is permitted without named human approval, and the organization can withdraw the credentials at any point.

Pre-registered pilot targets

These are proposed validation thresholds agreed before a pilot starts. They are success criteria to be measured, not results already achieved and not a guarantee of any outcome.

Pilot target
95% or more
Connected evidence coverage
Pilot target
85% or more
Validated sharing-finding precision
Pilot target
90% or more
Validated OAuth-finding precision
Pilot target
50% or more
Administrator review-time reduction
Pilot target
80% or more
Accepted or justified decisions
Pilot target
Zero
Unauthorized changes or material disruption

Products

Two products, in delivery order

Edge decides at the moment of action inside approved work surfaces. The Console decides across the organization. Both run the same reasoning core, the same decision record, and the same governance rail.

Product 01 / 3 capabilities

KRYOS-XS Edge

A browser-based security decision assistant that helps users evaluate suspicious messages, external data sharing, OAuth approvals and other consequential actions at the moment they occur.

Open KRYOS-XS Edge

Product 02 / 8 capabilities

KRYOS-XS Console

A centralized Cyber Decision Operations Hub that converts alerts, identity risks, access questions, data exposures and response requirements into one prioritized decision queue.

Open KRYOS-XS Console

Service explorer

All 11 governed decision capabilities

Filter by product, expand any capability to read its six-stage sequence and hard boundary, or open the full service page.

Showing 11 of 11 governed capabilities across 2 of 2 products

Product 01 / 3 services

KRYOS-XS Edge

A browser-based security decision assistant that helps users evaluate suspicious messages, external data sharing, OAuth approvals and other consequential actions at the moment they occur.

  • Service 01

    Suspicious Message Adjudication

    Determine whether a message appears legitimate, unwanted or malicious, and present the recommendation beside the message.

  • Service 02

    External Sharing and Data-Movement Governance

    Evaluate a sharing decision before sensitive information leaves the organization, and offer a safer method.

  • Service 03

    Cloud Exposure and Configuration Decisioning

    Identify configuration changes that may create unnecessary exposure, while the change is still being made.

Product 02 / 8 services

KRYOS-XS Console

A centralized Cyber Decision Operations Hub that converts alerts, identity risks, access questions, data exposures and response requirements into one prioritized decision queue.

  • Service 04

    Alert Triage and Incident Adjudication

    Consolidate security alerts into a prioritized decision queue and connect related events so the broader situation is evaluated.

  • Service 05

    Account-Compromise Assessment

    Distinguish legitimate unusual behavior from potential account compromise using available identity evidence.

  • Service 06

    Access and Entitlement Review

    Identify unnecessary, outdated or unusually powerful access and recommend what should change.

  • Service 07

    Privileged-Access Governance

    Understand who holds administrative authority, why it exists, whether it remains necessary and what compromise would cost.

  • Service 08

    External-Party Access Governance

    Decide which external access should be retained, restricted, reviewed or revoked.

  • Service 09

    OAuth and Automation Authority Governance

    Evaluate applications, integrations and automated agents requesting organizational access, before and after the grant.

  • Service 10

    Guided Incident and Response Workflows

    Guide teams through structured response without depending on anyone remembering every step during a crisis.

  • Service 11

    Board, Funder and Framework Reporting

    Turn the accumulated Decision Ledger into clear institutional reporting generated from real decision history.

Every capability in this platform is provided at no cost to eligible nonprofits, NGOs, think tanks, and nonprofit research institutes under a grant funded by James Scott and administered by the Embassy Row Project.