Skip to content

Free for nonprofits, NGOs, think tanks, and institutes. Grant funded by James Scott, administered by the Embassy Row Project.

ArtOfTheHack home

Trust Center

Governance is architectural, not a reporting feature.

ArtOfTheHack is built so that institutions can defend a decision after the fact: what the evidence was, who was permitted to approve it, whether it could be reversed, and whether the outcome matched the hypothesis.

Trust architecture

What the overlay does, and what it will never do

Twelve commitments that apply to every grant-funded deployment, stated so a nontechnical executive, a systems administrator, and an employee whose browser it runs in can all check them.

  • Default product behavior

    Approved work surfaces

    Edge is active only on the work applications the organization authorizes, such as its mail, drive, and administration consoles. Any other site is out of scope.

  • Default product behavior

    No unrelated browser monitoring

    Personal browsing, unrelated tabs, and non-work accounts are not read, recorded, or sent anywhere. There is no general web-history collection.

  • Default product behavior

    Least-privilege permissions

    Each connection requests the narrowest scope the workflow needs, and the organization can review or revoke any scope at any time from its own admin console.

  • Default product behavior

    Read-only advisory operation by default

    Every deployment starts without write capability. KRYOS-XS explains and recommends; it changes nothing until the organization decides to enable a bounded action.

  • Default product behavior

    Human authorization for high-impact actions

    Consequential actions such as disabling an account or revoking access require a named human with the authority to approve them. That authority is never assumed by the system.

  • Default product behavior

    Evidence provenance

    Every determination carries the evidence behind it, where each item came from, and when it was observed, so a reviewer can retrace the reasoning later.

  • Default product behavior

    Uncertainty and escalation

    Confidence and missing evidence are reported with the decision. When evidence is insufficient or contradictory, the workflow escalates to a person instead of guessing.

  • Default product behavior

    Reversible actions

    Any action eligible for bounded execution must have a validated way to undo it, recorded alongside the decision that authorized it.

  • Default product behavior

    Decision logging

    The KRYOS Decision Ledger records what was decided, on what evidence, under which policy version, and who approved it. Records are exportable in structured form.

  • Default product behavior

    Organization-controlled policies

    Thresholds, approval roles, escalation rules, and the limits of any automated action are defined by the organization, not preset by ArtOfTheHack.

  • Set in the award agreement

    Data isolation

    Each organization's evidence, policy, and decision records are kept separate from every other organization's. Stronger separation, including dedicated or organization-hosted deployment, is available where the award scope supports it.

  • Set in the award agreement

    Configurable retention

    Retention periods for evidence and decision records are chosen by the organization, along with the deletion process that applies when a period ends.

These are the operating commitments of the platform and the award agreement, described as designed and delivered. They are not a certification, an independent security audit, or a compliance attestation, and ArtOfTheHack does not claim any. Protections that depend on the deployment model are scoped in writing with each grantee before connection.

Principles

What holds in every deployment

  • Evidence before assertion
  • Visible uncertainty
  • Human authority
  • Reversibility by design
  • Grantee data ownership
  • Data minimization
  • Vendor neutrality
  • Independent replay
  • Native-system fallback
  • No unsupported performance claims

Documentation

Trust Center sections

ArtOfTheHack provides governance, evidence, and control infrastructure. It does not automatically make a grantee compliant with any law, regulation, or framework. Compliance depends on the organization's implementation, policies, controls, jurisdiction, and professional advice.

KRYOS-XS Hypercube is designed to augment qualified security teams and existing security systems. It does not independently replace security analysts, incident responders, legal counsel, or regulatory professionals.