Skip to content

Free for nonprofits, NGOs, think tanks, and institutes. Grant funded by James Scott, administered by the Embassy Row Project.

ArtOfTheHack home

Grant-Funded Cybersecurity for Nonprofits

Security Tools Generate Signals.ArtOfTheHack Determines What They Mean.

KRYOS-XS protects decisions, not just systems. It detects consequential actions, determines what the evidence justifies, identifies who has authority, recommends the safest response and preserves proof of what the organization decided and why.

KRYOS-XS is a Cyber Decision Assurance Platform that converts cybersecurity evidence into safe, explainable, authorized and verifiable decisions.

Cost
No cost within the awarded grant scope.
Eligibility
Nonprofits, NGOs, think tanks, foundations and research institutes.
Funding
Funded by James Scott, administered by the Embassy Row Project.

Powered by KRYOS-XS Hypercube

Fully funded. Non-intrusive API overlay. Cross-vendor. Human-governed. Auditable. Reversible.

EXISTING SECURITY TELEMETRYIDENTITYENDPOINTNETWORKCLOUDSIEMXDRSOARVULNERABILITIESTHREAT INTELLIGENCEDATA SECURITYEVIDENCE FABRICNormalize · Resolve · Score · ContradictKRYOS-XSHYPERCUBEGOVERNED CYBER DECISIONEvidence · Confidence · Authority · RollbackADVISORYAPPROVAL-GATEDBOUNDED AUTONO EXECUTIONAPPROVED RESPONSEExecuted in existing enforcement systemsOUTCOME + CALIBRATION
  • Telemetry in
  • Governed decision
  • Approved response
  • Outcome and calibration back to evidence

What is ArtOfTheHack?

ArtOfTheHack is a cybersecurity company that provides grant-funded cybersecurity decision intelligence to eligible nonprofit organizations, NGOs, think tanks and nonprofit institutes, using KRYOS-XS Hypercube as a non-intrusive API overlay on the security systems those organizations already operate. The services are provided at no cost within the awarded scope. Grants are funded by James Scott and administered by the Embassy Row Project.

Instead of creating another stream of alerts, KRYOS-XS helps organizations understand what is happening, determine what the evidence justifies, identify who has authority, guide the safest response and preserve a complete decision record.

Does ArtOfTheHack replace our current cybersecurity stack?
No. ArtOfTheHack uses KRYOS-XS Hypercube as a non-intrusive API overlay above the cybersecurity systems your organization already runs. Those systems remain the systems of record and the systems of enforcement.
What does it cost an approved nonprofit?
Approved nonprofit organizations are not charged for ArtOfTheHack services provided within the authorized grant scope.
Who funds the program?
James Scott funds the ArtOfTheHack cybersecurity grants.
Who manages the program?
The Embassy Row Project manages the cybersecurity grant program, including intake, award scope, and reporting.
Who is eligible?
Nonprofit organizations, NGOs, policy think tanks, nonprofit research institutes, foundations, and civil society and nonprofit journalism organizations. Eligibility detail is on the grant eligibility page.
Who decides what happens?
Your team does. Every recommendation names the human authority required, states its confidence and uncertainty, and carries a reversal path before anything is executed.

The problem

The Security Stack Is Powerful. The Decision Layer Is Fragmented.

Organizations already operate sophisticated security technologies. What those technologies rarely produce together is a single defensible answer to what the combined evidence means and what should be done about it.

  • Security systems operate in isolation and cannot evaluate each other
  • Duplicate alerts describe the same event with different identifiers
  • Detections reach conflicting conclusions about the same identity or host
  • Risk models are incompatible across identity, endpoint, cloud, and data
  • Business consequence is absent from most technical severity scores
  • Escalation volume exceeds the adjudication capacity of the analyst team
  • Automation executes without complete cross-system context
  • The full basis for a response decision is rarely preserved
  • Confidence and certainty are treated as the same property
  • Cross-vendor adjudication depends on individual analyst memory

Before ArtOfTheHack

  • SIEM
  • EDR
  • NDR
  • IAM
  • CNAPP
  • TIP
  • SOAR
Human analystManual correlationResponse

Fragmented evidence

With ArtOfTheHack

  1. Security stack
  2. ArtOfTheHack
  3. Validated evidence
  4. Governed decision
  5. Approved response

Evidence-governed cyber decisioning

How access works

Free for Nonprofits. Funded by Grant. Applied as an Overlay.

ArtOfTheHack is not sold. Eligible organizations apply for a grant, and an approved award provisions the KRYOS-XS Hypercube overlay against the security systems they already run.

01

Apply

A nonprofit, NGO, think tank, or nonprofit institute submits a grant application describing its mission and the systems it operates.

02

Review

The Embassy Row Project reviews eligibility, mission risk, and available grant capacity. Funding comes from James Scott, not from the organization.

03

Overlay

KRYOS-XS Hypercube is attached through read-only APIs to the existing identity, endpoint, cloud, and email systems. Nothing is installed and nothing is replaced.

04

Govern

Decisions run in shadow mode, then advisory, then approval-gated action executed by the organization's own systems under its own authority.

Every capability on this site, including dimensional geometric reasoning, adversarial red teaming, cyber digital twins, advanced Monte Carlo scenario sampling, and cryptographic decision provenance, is made possible exclusively by applying the KRYOS-XS non-intrusive API overlay to the organization's existing cybersecurity architecture.

The concept

The Art Is Not Breaking the System. The Art Is Understanding It Completely.

Sophisticated defense requires the same completeness of understanding that a capable adversary develops, applied lawfully and in service of the organization.

ArtOfTheHack converts adversarial thinking into governed defensive intelligence. The objective is not intrusion. The objective is to understand the environment well enough that every response is proportionate, defensible, and reversible.

What complete understanding requires

  • How an adversary sees the environment rather than how the org chart describes it
  • Which identity relationships create reachable privilege
  • Which attack paths are viable against current configuration
  • Which controls actually interrupt those paths rather than merely observing them
  • Which telemetry is trustworthy at the moment of the decision
  • Which evidence contradicts another source and why
  • Which vulnerabilities are exploitable in this specific context
  • Which response produces the greatest measurable risk reduction
  • Which response creates unacceptable operational disruption
  • Which action requires named human authority
  • Which action can safely execute inside bounded automation

How KRYOS-XS works

A Non-Intrusive API Overlay on the Security Architecture You Already Have

KRYOS-XS Hypercube is not a replacement stack and not another agent on your endpoints. It attaches to your existing tools through read-only APIs, reasons across the evidence they already produce, and hands a governed decision back to the systems that are authorized to act.

Step 01

Connect through read-only APIs

The overlay authenticates to the identity provider, endpoint protection, email security, cloud control plane, network and VPN logs, SaaS admin APIs, ticketing, and any SIEM or XDR already in place. Connections use least-privilege read credentials scoped to the organization's own tenant.

  • No agents installed on laptops, servers, or field devices
  • No inline network appliance and no traffic interception
  • No configuration changes to existing security products
  • Typical connection is measured in hours, not migration projects

Step 02

Normalize, correlate, and reason

Events from every connected system are normalized into a common schema, resolved to the same identity, asset, and session, and evaluated together. Dimensional geometric reasoning weighs interacting dimensions at once instead of scoring each tool's alerts in isolation, with Monte Carlo sampling used to test how the situation could develop.

  • Cross-vendor correlation and contradiction analysis
  • Evidence quality, freshness, and independence scoring
  • Digital twin simulation of containment and its business cost
  • Explicit confidence and uncertainty carried to the decision

Step 03

Return a governed decision to your systems

The output is a Governed Decision Object: the recommended action, the evidence behind it, the alternatives considered, the required authority, the validity window, the rollback plan, and a cryptographic hash of the whole record. Execution happens in your systems, under your approval, never by an ArtOfTheHack agent acting on its own.

  • Advisory, approval-gated, or bounded automatic by policy
  • Named human authority approves consequential action
  • Every action carries a validated reversal path
  • Hash-chained audit record for boards, funders, and regulators

What changes inside the nonprofit

Nothing is removed and no license is cancelled. Microsoft 365 or Google Workspace, whichever endpoint tool is in place, the donated firewall, the identity provider, and the ticketing system all keep running exactly as they do today. What is added is a reasoning layer above them and a decision record beneath every response.

What happens if the overlay is unavailable

The organization's security stack continues to operate unchanged. KRYOS-XS sits beside the control path rather than inside it, so a loss of availability removes the decision support and never removes the organization's ability to detect, block, or respond with its native tools.

Red teaming, digital twin simulation, advanced Monte Carlo scenario sampling, dimensional geometric reasoning, and cryptographic decision provenance are all delivered exclusively through this overlay applied to the organization's existing cybersecurity architecture.

Edge and Console

One platform. Two different jobs. Zero rip-and-replace.

Your SIEM, identity provider, endpoint protection and cloud-security tools keep doing their jobs. KRYOS-XS connects their approved signals and turns fragmented alerts into governed decisions: Edge protects the person at the moment of action, Console governs and remembers the decision.

Read how Edge and Console fit together

Reasoning methods

Ten Methods Applied Through One Overlay

Every method below runs on evidence read from the systems the organization already operates. None of them require new agents, new appliances, or a replacement security stack.

High-Dimensional Geometric Reasoning

Security evidence from separate consoles is placed into one high-dimensional space so signals that were never comparable can be compared.

Adversarial Red Teaming

The organization's own architecture, policy, and response plan are attacked analytically across eight dimensions before a real adversary attempts it.

Digital Twin Simulation

A model of the organization's systems, dependencies, and field operations is used to test a decision before it is executed for real.

Advanced Monte Carlo Scenario Sampling

Thousands of variations of an incident and its response are sampled to produce probability ranges, tail cases, and the point where a recommendation stops being correct.

Contradiction Detection and Evidence Validation

Sources that disagree are surfaced rather than averaged, and every contributing record is scored for reliability, freshness, independence, and completeness.

Scenario Branching and Strategic Actor Modeling

Candidate responses are branched forward against modeled adversaries so the second move is visible before the first one is made.

Cryptographic Provenance and Hash Chaining

Every decision carries a tamper-evident digest of its inputs, policy state, model versions, and outputs, so it can be replayed and verified independently.

Policy and Authority Evaluation

Before any action is prepared, the engine determines whether policy permits it and which named role is entitled to approve it.

Reversibility and Rollback Modeling

No action is recommended for automatic execution unless a validated reversal path exists and has been recorded in advance.

Calibration and Outcome Feedback

Observed outcomes are fed back into the engine so confidence scores are measured against reality rather than asserted.

KRYOS-XS Hypercube

Multidimensional Cybersecurity Reasoning

Conventional platforms analyze separate projections of the environment. ArtOfTheHack evaluates interacting dimensions simultaneously. Select a dimension to see the relationships it carries.

Interacting dimension

Identity state

Human and machine identity posture, privilege, entitlements, and session context.

Highlighted relationships

  • Privilege
  • Device state
  • Network state
  • Application state
  • Threat intelligence
  • Policy
  • Confidence

Architecture

The Cybersecurity Decision Control Plane

Seven separated layers, from the security systems you already run through to outcome calibration. Switch views and select a layer to inspect it.

View
    • IdP
    • IAM
    • PAM
    • ZTNA
    • EDR
    • NDR
    • SIEM
    • XDR

Governance rail

  • Human in the loop
  • Approval thresholds
  • Separation of duties
  • Policy constraints
  • Reversibility checks
  • Blast-radius limits
  • Audit logging
  • Compliance mapping
  • Kill switch
  • Native fallback

Intelligence does not equal authority. KRYOS-XS Hypercube may analyze. Policy determines authority. Approved systems execute.

Signature artifact

Every Recommendation Arrives as a Governed Decision Object

The governed decision object is the record the Hypercube Decision Engine produces and the KRYOS Decision Ledger stores. Evidence, reasoning, alternatives, controls, authority, audit, and outcome are all part of the same record.

Governed Decision Object

Illustrative platform visualization

Decision ID
DEC-4417-IDENT
Status
Awaiting authority
Risk
High
Confidence
0.78
Uncertainty
Device telemetry gap, 14 minutes
Identity provider
Impossible travel, two regions, 41 minutes apart
Endpoint platform
No malicious process observed on the registered device
Network
Session originated from a residential proxy range
Data platform
Access to a regulated dataset attempted twice
Evidence quality
Three independent sources, one derived source excluded

Response modes

Automation Should Scale With Certainty and Consequence.

Advisory

ArtOfTheHack analyzes evidence and recommends an action to a named analyst.

No write capability is required. Recommendations are compared against current practice.

Approval-Gated

ArtOfTheHack prepares the action. An authorized human approves execution.

Authority is resolved from policy, and the request expires if evidence goes stale.

Bounded Automatic

Only predefined, reversible, policy-approved actions execute automatically.

Every automatic class requires a validated rollback path and a blast-radius ceiling.

Unrestricted autonomous remediation is not an objective of this platform. Authority remains with named humans unless a bounded, reversible class of action has been expressly approved.

Capability status

What is current, what is in pilot, what is planned

Every capability described anywhere on this site carries one of four statuses. Nothing outside the Current column should be read as available today.

Current

Built and operable inside a grant deployment today, on the surfaces the organization has authorized.

  • Google Workspace evidence connection
  • KRYOS-XS Edge on approved mail, sharing and cloud-console surfaces
  • KRYOS-XS Console decision queue and KRYOS Decision Ledger records

Pilot

Operated inside a bounded, time-limited grant pilot with pre-registered success criteria. Results are measured with the organization and are not published as product claims.

  • Guided response workflows under named human approval
  • Approval-gated actions on low-complexity action classes
  • Board and funder decision reporting from the Ledger

Planned

Designed and specified, but not connected until the relevant vendor API is authorized by the organization and validated by ArtOfTheHack. No such connection is claimed as live.

  • Identity-provider evidence, including Okta and Entra ID
  • SIEM, EDR and MDM alert evidence
  • Vulnerability, backup and cloud estate evidence

Long term

Platform direction. Not scheduled, not implied to exist, and never presented as available capability.

  • Broader cross-vendor decision fabric coverage
  • Sector policy packs co-developed with mission networks
  • Coalition-wide decision reporting across member organizations

Nothing on this site describes a customer, a completed pilot outcome, an accuracy rate, a certification, an award or an existing partnership. Integrations exist only where an organization has authorized a real technical connection.

Services

Two Integrated Products. 11 Governed Decision Capabilities.

Every workflow operates through authorized APIs against the systems the organization already runs. The connected source stays the system of record and the point of enforcement.

  • Product 01 / 3 services

    KRYOS-XS Edge

    A browser-based security decision assistant that helps users evaluate suspicious messages, external data sharing, OAuth approvals and other consequential actions at the moment they occur.

  • Product 02 / 8 services

    KRYOS-XS Console

    A centralized Cyber Decision Operations Hub that converts alerts, identity risks, access questions, data exposures and response requirements into one prioritized decision queue.

Delivery boundary

API-Only. Supported and Excluded, Stated Up Front.

ArtOfTheHack is a non-intrusive intelligence layer over the cybersecurity systems an organization already runs. It reads what those systems expose through authorized APIs, and it says so when they expose nothing.

  • Evidence before inference.
  • Authority before action.
  • Verification before assurance.

Supported

What ArtOfTheHack uses

  • Approved work surfaces and authorized APIs
  • Inline decision support at the moment of action
  • Cross-source correlation of available evidence
  • Explainable recommendations with confidence and uncertainty
  • Approval-gated action in the organization's own systems
  • Complete decision logging in the KRYOS Decision Ledger
  • Outcome verification and board-ready reporting

Excluded

What ArtOfTheHack never uses

  • Replacement of existing security products
  • Unrelated personal browsing collection
  • Endpoint agents, appliances or packet capture
  • Independent malware detection
  • Hidden or unsupported data access
  • Autonomous consequential action
  • Claims a connected system cannot evidence

KRYOS does not claim evidence that a connected system cannot provide. When data is incomplete, the platform identifies the limitation and requests the appropriate human or technical input.

Launch product

KRYOS-XS Console is the flagship first product

A centralized Cyber Decision Operations Hub that converts alerts, identity risks, access questions, data exposures and response requirements into one prioritized decision queue.

The nonprofit pilot sequence

  1. Days 1 to 5

    Assess and Authorize

    • Initial security assessment
    • Least-privileged Workspace scopes
    • Approved surface definition

    Then Connect and Observe

  2. Days 6 to 12

    Connect and Observe

    • Google Workspace connection
    • Console decision queue populated
    • No recommendations shown yet

    Then Advisory Operation

  3. Days 13 to 20

    Advisory Operation

    • Edge deployed to approved surfaces
    • Inline verdicts delivered
    • Administrator accept or reject rationale

    Then Gated Action

  4. Days 21 to 26

    Gated Action

    • Named human approval
    • Low-complexity supported actions
    • Before and after verification

    Then Prove and Report

  5. Days 27 to 30

    Prove and Report

    • Decision Ledger reconciliation
    • Board and funder report
    • Continue, modify or terminate

    Continue, modify or end

The pilot begins read-only. No consequential API action is permitted without named human approval, and the organization can withdraw the credentials at any point.

Pre-registered pilot targets

These are proposed validation thresholds agreed before a pilot starts. They are success criteria to be measured, not results already achieved and not a guarantee of any outcome.

Pilot target
95% or more
Connected evidence coverage
Pilot target
85% or more
Validated sharing-finding precision
Pilot target
90% or more
Validated OAuth-finding precision
Pilot target
50% or more
Administrator review-time reduction
Pilot target
80% or more
Accepted or justified decisions
Pilot target
Zero
Unauthorized changes or material disruption

Environments

One Cyber Decision Layer Across High-Consequence Environments.

  • Human Rights NGOs

    • Targeted phishing
    • Account compromise
    • Field device risk
    • Source protection
  • Policy Think Tanks

    • Scholar accounts
    • Pre-publication exfiltration
    • Impersonation
    • Event infrastructure
  • Research Institutes

    • Instrument networks
    • Collaborator access
    • Shared computing
    • Recovery sequencing
  • Foundations and Grantmakers

    • Disbursement fraud
    • Grantee network risk
    • Privileged access
    • Board evidence
  • Civil Society and Journalism

    • Targeted spyware
    • Publishing availability
    • Contributor access
    • Emergency containment
  • Humanitarian Operations

    • Field devices
    • Break-glass access
    • Low connectivity
    • Program continuity

Who we serve

Built for Institutions That Must Defend Their Decisions

Go deeper

The Technical Record

Placement, contracts, framework alignment, and the measurement plan are published rather than reserved for a sales conversation.

  • Policy-Based Access Mediation

    The flagship application: adaptive Zero Trust decisioning for IAM, PAM, CIEM, ZTNA, APIs, and machine identities.

    Read the detail
  • Integration and API

    Connectors, OCSF and STIX normalization, cyber decision endpoints, and native-system fallback.

    Read the detail
  • Framework Alignment

    CSF 2.0 across all six functions, the Zero Trust reference model, ATT&CK, and D3FEND.

    Read the detail
  • Optimization and Measurement

    What improves in each product you own, the decision logic, and the eight-domain scorecard.

    Read the detail

Trust

Institutional Commitments, Stated Plainly

These commitments constrain the product. They are published so they can be held against us.

  • Evidence before assertion
  • Visible uncertainty
  • Human authority
  • Reversibility by design
  • Grantee data ownership
  • Data minimization
  • Vendor neutrality
  • Independent replay
  • Native-system fallback
  • No unsupported performance claims

KRYOS-XS Hypercube is designed to augment qualified security teams and existing security systems. It does not independently replace security analysts, incident responders, legal counsel, or regulatory professionals.