Skip to content

Free for nonprofits, NGOs, think tanks, and institutes. Grant funded by James Scott, administered by the Embassy Row Project.

ArtOfTheHack home

Product 01 / 3 services

KRYOS-XS Edge

A browser-based security decision assistant that helps users evaluate suspicious messages, external data sharing, OAuth approvals and other consequential actions at the moment they occur.

KRYOS-XS protects decisions, not just systems. It detects consequential actions, determines what the evidence justifies, identifies who has authority, recommends the safest response and preserves proof of what the organization decided and why.

Point of action

3 services

  • Allow

    The evidence supports the action. Proceed as intended.

  • Warn

    The action carries risk the person should understand before continuing.

  • Approval Required

    The action exceeds the authority of the person performing it and needs a named approver.

  • Stop

    The evidence indicates the action would cause harm or breach policy.

  • Insufficient Evidence

    The available evidence cannot support a verdict. The gap is named rather than guessed at.

Prevention before completion

Paired product

The other half of the same decision layer

Edge works at the moment of action. Console works across the organization. Both write to the same KRYOS Decision Ledger and are evaluated by the same Hypercube Decision Engine.

KRYOS-XS Console

A centralized Cyber Decision Operations Hub that converts alerts, identity risks, access questions, data exposures and response requirements into one prioritized decision queue.

Explore KRYOS-XS Console

Positioning

What this product is

A browser-based cybersecurity decision assistant that works inside approved tools such as email, cloud-management consoles and collaboration applications, evaluating a decision while the user is still making it.

The problem it addresses

Most security controls report a risky action after it has happened. By then credentials have been surrendered, a donor file is public, or a storage bucket has been opened. The person who could have prevented it was the user, and they had no evidence, no policy context and no way to know who could approve an exception.

Operating model

  • Install and authorize: the organization deploys the extension and authorizes specific work surfaces under least-privilege permissions.
  • Dormant outside approved surfaces: Edge activates only on approved work applications and defined security decision points.
  • Detect a consequential action such as reporting a suspicious email, creating an external sharing link, approving third-party access or changing a cloud permission.
  • Gather context and evidence: the user, object, intended action and application context, plus authoritative evidence from approved integrations.
  • Apply Hypercube decisioning, then deliver one of five verdicts inline and record the decision in the Console.

Evidence and authority

The shared model across this product

  • Approved work surfaces only, with no unrelated browsing collection.
  • Read-only advisory operation by default and human approval for high-impact actions.
  • Encrypted communications and organization-controlled policies.
  • Complete decision logging, with reversible enforcement wherever technically available.
  • Clear escalation when evidence is incomplete, instead of a manufactured verdict.

Limitations

What this product does not do

  • Edge evaluates only the approved applications and decision points the organization authorizes.
  • The visible interface supplies action context; authoritative security state requires a connected system.
  • Where an approved integration cannot evidence a fact, Edge returns Insufficient Evidence rather than assuming one.
  • Edge does not replace the mail platform, the cloud provider's controls or an email security gateway.
  • Users are not asked to become analysts; Edge explains, it does not transfer responsibility for enforcement.

Capabilities

What KRYOS-XS Edge does

Each capability is delivered through authorized connections to systems the organization already runs.

Suspicious email adjudication

When a message asks a person to move money, change payroll details, reset credentials or open an unexpected attachment, Edge examines the sender history, authentication results, domain age and prior organizational contact, then states whether the request is safe to act on.

External file-sharing protection

Before a document leaves the organization, Edge checks the sensitivity of the file, the recipient domain, the sharing scope and the applicable policy, and explains what the share would expose.

OAuth application review

When a third-party application requests access to organizational data, Edge reports the scopes being granted, the publisher, the verification status and the data the application would be able to read or change.

Cloud configuration guidance

When an administrator is about to change a setting that widens access, disables logging or weakens a control, Edge describes the consequence of the change and the safer alternative before it is saved.

Policy and authority checks

Edge compares the pending action against the organization's own written policy and identifies whether the person performing it holds the authority to complete it alone.

Inline verdicts

Every evaluation resolves to one of five plain-language verdicts, shown in the same place the person is working, with the reasoning and the evidence behind it.

Automatic Console logging

Completed decisions are forwarded to KRYOS-XS Console and preserved in the KRYOS Decision Ledger, so the organization retains a record without asking users to file reports.

Privacy and permission safeguards

Edge activates only on the work surfaces the organization approves, requests the minimum permissions each check requires, and does not collect browsing activity unrelated to those surfaces.

Verdicts

Five plain-language answers

Every evaluation resolves to one of five verdicts, shown where the person is working, with the reasoning behind it.

Allow

The evidence supports the action. Proceed as intended.

Warn

The action carries risk the person should understand before continuing.

Approval Required

The action exceeds the authority of the person performing it and needs a named approver.

Stop

The evidence indicates the action would cause harm or breach policy.

Insufficient Evidence

The available evidence cannot support a verdict. The gap is named rather than guessed at.

Guarantees

What the product will and will not do

  • Operates only on the work surfaces the organization has approved
  • Remains dormant everywhere else
  • Requests least-privilege permissions for each check it performs
  • Does not collect browsing activity unrelated to approved surfaces
  • Uses authoritative API evidence from connected systems where it is available
  • Requires human authorization before any high-impact action proceeds
  • Sends completed decisions to KRYOS-XS Console and the KRYOS Decision Ledger

Operating model

How every workflow in this product runs

  1. Stage 01

    Authorize

    Approved integration with the minimum scope the capability requires.

  2. Stage 02

    Detect

    A consequential security action or signal is identified for evaluation.

  3. Stage 03

    Gather

    Available evidence is retrieved from the connected systems and its source and age recorded.

  4. Stage 04

    Reason

    The Hypercube Decision Engine cross-checks facts, compares safe and dangerous explanations and applies policy.

  5. Stage 05

    Authorize action

    Required authority is confirmed and a named human approves anything consequential.

  6. Stage 06

    Verify and record

    The outcome is verified and preserved in the KRYOS Decision Ledger.

KRYOS does not claim evidence that a connected system cannot provide. When data is incomplete, the platform identifies the limitation and requests the appropriate human or technical input.