Product 01 / 3 services
KRYOS-XS Edge
A browser-based security decision assistant that helps users evaluate suspicious messages, external data sharing, OAuth approvals and other consequential actions at the moment they occur.
KRYOS-XS protects decisions, not just systems. It detects consequential actions, determines what the evidence justifies, identifies who has authority, recommends the safest response and preserves proof of what the organization decided and why.
Point of action
3 services
Allow
The evidence supports the action. Proceed as intended.
Warn
The action carries risk the person should understand before continuing.
Approval Required
The action exceeds the authority of the person performing it and needs a named approver.
Stop
The evidence indicates the action would cause harm or breach policy.
Insufficient Evidence
The available evidence cannot support a verdict. The gap is named rather than guessed at.
Prevention before completion
Paired product
The other half of the same decision layer
Edge works at the moment of action. Console works across the organization. Both write to the same KRYOS Decision Ledger and are evaluated by the same Hypercube Decision Engine.
KRYOS-XS Console
A centralized Cyber Decision Operations Hub that converts alerts, identity risks, access questions, data exposures and response requirements into one prioritized decision queue.
Explore KRYOS-XS ConsolePositioning
What this product is
A browser-based cybersecurity decision assistant that works inside approved tools such as email, cloud-management consoles and collaboration applications, evaluating a decision while the user is still making it.
The problem it addresses
Most security controls report a risky action after it has happened. By then credentials have been surrendered, a donor file is public, or a storage bucket has been opened. The person who could have prevented it was the user, and they had no evidence, no policy context and no way to know who could approve an exception.
Operating model
- Install and authorize: the organization deploys the extension and authorizes specific work surfaces under least-privilege permissions.
- Dormant outside approved surfaces: Edge activates only on approved work applications and defined security decision points.
- Detect a consequential action such as reporting a suspicious email, creating an external sharing link, approving third-party access or changing a cloud permission.
- Gather context and evidence: the user, object, intended action and application context, plus authoritative evidence from approved integrations.
- Apply Hypercube decisioning, then deliver one of five verdicts inline and record the decision in the Console.
Evidence and authority
The shared model across this product
- Approved work surfaces only, with no unrelated browsing collection.
- Read-only advisory operation by default and human approval for high-impact actions.
- Encrypted communications and organization-controlled policies.
- Complete decision logging, with reversible enforcement wherever technically available.
- Clear escalation when evidence is incomplete, instead of a manufactured verdict.
Limitations
What this product does not do
- Edge evaluates only the approved applications and decision points the organization authorizes.
- The visible interface supplies action context; authoritative security state requires a connected system.
- Where an approved integration cannot evidence a fact, Edge returns Insufficient Evidence rather than assuming one.
- Edge does not replace the mail platform, the cloud provider's controls or an email security gateway.
- Users are not asked to become analysts; Edge explains, it does not transfer responsibility for enforcement.
Capabilities
What KRYOS-XS Edge does
Each capability is delivered through authorized connections to systems the organization already runs.
Suspicious email adjudication
When a message asks a person to move money, change payroll details, reset credentials or open an unexpected attachment, Edge examines the sender history, authentication results, domain age and prior organizational contact, then states whether the request is safe to act on.
External file-sharing protection
Before a document leaves the organization, Edge checks the sensitivity of the file, the recipient domain, the sharing scope and the applicable policy, and explains what the share would expose.
OAuth application review
When a third-party application requests access to organizational data, Edge reports the scopes being granted, the publisher, the verification status and the data the application would be able to read or change.
Cloud configuration guidance
When an administrator is about to change a setting that widens access, disables logging or weakens a control, Edge describes the consequence of the change and the safer alternative before it is saved.
Policy and authority checks
Edge compares the pending action against the organization's own written policy and identifies whether the person performing it holds the authority to complete it alone.
Inline verdicts
Every evaluation resolves to one of five plain-language verdicts, shown in the same place the person is working, with the reasoning and the evidence behind it.
Automatic Console logging
Completed decisions are forwarded to KRYOS-XS Console and preserved in the KRYOS Decision Ledger, so the organization retains a record without asking users to file reports.
Privacy and permission safeguards
Edge activates only on the work surfaces the organization approves, requests the minimum permissions each check requires, and does not collect browsing activity unrelated to those surfaces.
Verdicts
Five plain-language answers
Every evaluation resolves to one of five verdicts, shown where the person is working, with the reasoning behind it.
Allow
The evidence supports the action. Proceed as intended.
Warn
The action carries risk the person should understand before continuing.
Approval Required
The action exceeds the authority of the person performing it and needs a named approver.
Stop
The evidence indicates the action would cause harm or breach policy.
Insufficient Evidence
The available evidence cannot support a verdict. The gap is named rather than guessed at.
Guarantees
What the product will and will not do
- Operates only on the work surfaces the organization has approved
- Remains dormant everywhere else
- Requests least-privilege permissions for each check it performs
- Does not collect browsing activity unrelated to approved surfaces
- Uses authoritative API evidence from connected systems where it is available
- Requires human authorization before any high-impact action proceeds
- Sends completed decisions to KRYOS-XS Console and the KRYOS Decision Ledger
Workflows
The 3 governed capabilities in this product
Each workflow follows the same six-stage operating model and states its own hard boundary.
Service 01
Suspicious Message Adjudication
Determine whether a message appears legitimate, unwanted or malicious, and present the recommendation beside the message.
Service 02
External Sharing and Data-Movement Governance
Evaluate a sharing decision before sensitive information leaves the organization, and offer a safer method.
Service 03
Cloud Exposure and Configuration Decisioning
Identify configuration changes that may create unnecessary exposure, while the change is still being made.
Operating model
How every workflow in this product runs
Stage 01
Authorize
Approved integration with the minimum scope the capability requires.
Stage 02
Detect
A consequential security action or signal is identified for evaluation.
Stage 03
Gather
Available evidence is retrieved from the connected systems and its source and age recorded.
Stage 04
Reason
The Hypercube Decision Engine cross-checks facts, compares safe and dangerous explanations and applies policy.
Stage 05
Authorize action
Required authority is confirmed and a named human approves anything consequential.
Stage 06
Verify and record
The outcome is verified and preserved in the KRYOS Decision Ledger.
KRYOS does not claim evidence that a connected system cannot provide. When data is incomplete, the platform identifies the limitation and requests the appropriate human or technical input.
