Skip to content

Free for nonprofits, NGOs, think tanks, and institutes. Grant funded by James Scott, administered by the Embassy Row Project.

ArtOfTheHack home

KRYOS-XS Edge / Service 01

Suspicious Message Adjudication

Determine whether a message appears legitimate, unwanted or malicious, and present the recommendation beside the message.

What this service does

The problem, the evidence, and what stays with you

The problem addressed

Staff cannot reliably tell a routine solicitation from a credential-theft attempt aimed at the mission, and a verdict that arrives in a security report the following week arrives too late to matter.

Authorized information required

Sender identity, message content, links and attachments, available email headers, organizational relationships, known threat intelligence and similar reported messages.

The intelligence layer ArtOfTheHack adds

Impersonation indicators and credential-harvesting patterns are compared against the organization's own communication patterns and the department being targeted, so the safe explanation is tested before any verdict is formed.

The decision value you receive

A clear recommendation shown beside the message: safe, treat cautiously, escalate, strong evidence of phishing, or additional evidence required.

What remains under your control

The mail platform stays the point of enforcement. Edge advises, the user or the named security authority decides, and the outcome is recorded.

Workflow

The six-stage governed sequence

Nothing in this sequence is skipped. Evidence precedes inference, authority precedes action, and verification precedes assurance.

  1. Stage 01

    Detect

    The user opens or reports a suspicious message inside an approved mail surface.

    Output feeds stage 02: Gather

  2. Stage 02

    Gather

    Sender identity, message content, links, attachments and available email headers are collected with the application context.

    Output feeds stage 03: Cross-check

  3. Stage 03

    Cross-check

    Impersonation indicators, credential-harvesting patterns, organizational relationships, known threat intelligence and similar reported messages are compared.

    Output feeds stage 04: Evaluate

  4. Stage 04

    Evaluate

    The user or department being targeted is weighed against the competing safe explanation before any verdict is formed.

    Output feeds stage 05: Recommend

  5. Stage 05

    Recommend

    A clear verdict is presented inline: safe, treat cautiously, escalate for review, strong evidence of phishing, or additional evidence required.

    Output feeds stage 06: Record

  6. Stage 06

    Record

    Evidence, verdict, user response and final outcome are sent to the Console and preserved in the Decision Ledger.

    Closes the sequence and returns evidence to the decision record

Hard boundary

Edge evaluates messages on approved work surfaces only. It does not inspect unrelated personal mail, and it does not replace the organization's mail platform or email security gateway.

Evidence in

What the workflow reads

  • Sender identity
  • Message content
  • Links and attachments
  • Available email headers
  • Organizational relationships
  • Known threat intelligence
  • Similar reported messages

Decision out

What the workflow returns

  • The message appears safe
  • The message should be treated cautiously
  • The message should be escalated for security review
  • The message shows strong evidence of phishing or credential theft
  • Additional evidence is required before a safe verdict

Authority and action

Who decides, who acts, how it is verified

Service posture
Advisory with approval-gated action
Acting API
The organization's own mail platform, where it supports the action.
Approving authority
The user for low-consequence outcomes, and the named mail or security authority for escalation.
Verification
The verdict, user response and final outcome are reconciled in the Decision Ledger.
Rollback and reversal
Advisory verdicts change nothing on their own; escalation and quarantine are reversible in the mail platform.

Connection

What must be authorized

  • Approved mail surface in the browser
  • Google Workspace connection for authoritative evidence
Delivery
Authorized API integration, webhooks, or structured evidence submissions. No endpoint agent, no appliance, no product replacement.
System of record
The connected source platform remains the system of record and the point of enforcement. ArtOfTheHack proposes; the source system acts.
Cost to the grantee
KRYOS-XS is provided at no cost to eligible nonprofits under a grant funded by James Scott and administered by the Embassy Row Project.
  • Read-only advisory operation by default
  • Human approval for high-impact actions
  • Least-privilege, revocable permissions
  • Explicit blind spots instead of assumed facts
  • Reversible enforcement wherever technically available