KRYOS-XS Edge / Service 01
Suspicious Message Adjudication
Determine whether a message appears legitimate, unwanted or malicious, and present the recommendation beside the message.
What this service does
The problem, the evidence, and what stays with you
The problem addressed
Staff cannot reliably tell a routine solicitation from a credential-theft attempt aimed at the mission, and a verdict that arrives in a security report the following week arrives too late to matter.
Authorized information required
Sender identity, message content, links and attachments, available email headers, organizational relationships, known threat intelligence and similar reported messages.
The intelligence layer ArtOfTheHack adds
Impersonation indicators and credential-harvesting patterns are compared against the organization's own communication patterns and the department being targeted, so the safe explanation is tested before any verdict is formed.
The decision value you receive
A clear recommendation shown beside the message: safe, treat cautiously, escalate, strong evidence of phishing, or additional evidence required.
What remains under your control
The mail platform stays the point of enforcement. Edge advises, the user or the named security authority decides, and the outcome is recorded.
Workflow
The six-stage governed sequence
Nothing in this sequence is skipped. Evidence precedes inference, authority precedes action, and verification precedes assurance.
Stage 01
Detect
The user opens or reports a suspicious message inside an approved mail surface.
Output feeds stage 02: Gather
Stage 02
Gather
Sender identity, message content, links, attachments and available email headers are collected with the application context.
Output feeds stage 03: Cross-check
Stage 03
Cross-check
Impersonation indicators, credential-harvesting patterns, organizational relationships, known threat intelligence and similar reported messages are compared.
Output feeds stage 04: Evaluate
Stage 04
Evaluate
The user or department being targeted is weighed against the competing safe explanation before any verdict is formed.
Output feeds stage 05: Recommend
Stage 05
Recommend
A clear verdict is presented inline: safe, treat cautiously, escalate for review, strong evidence of phishing, or additional evidence required.
Output feeds stage 06: Record
Stage 06
Record
Evidence, verdict, user response and final outcome are sent to the Console and preserved in the Decision Ledger.
Closes the sequence and returns evidence to the decision record
Hard boundary
Edge evaluates messages on approved work surfaces only. It does not inspect unrelated personal mail, and it does not replace the organization's mail platform or email security gateway.
Evidence in
What the workflow reads
- Sender identity
- Message content
- Links and attachments
- Available email headers
- Organizational relationships
- Known threat intelligence
- Similar reported messages
Decision out
What the workflow returns
- The message appears safe
- The message should be treated cautiously
- The message should be escalated for security review
- The message shows strong evidence of phishing or credential theft
- Additional evidence is required before a safe verdict
Authority and action
Who decides, who acts, how it is verified
- Service posture
- Advisory with approval-gated action
- Acting API
- The organization's own mail platform, where it supports the action.
- Approving authority
- The user for low-consequence outcomes, and the named mail or security authority for escalation.
- Verification
- The verdict, user response and final outcome are reconciled in the Decision Ledger.
- Rollback and reversal
- Advisory verdicts change nothing on their own; escalation and quarantine are reversible in the mail platform.
Connection
What must be authorized
- Approved mail surface in the browser
- Google Workspace connection for authoritative evidence
- Delivery
- Authorized API integration, webhooks, or structured evidence submissions. No endpoint agent, no appliance, no product replacement.
- System of record
- The connected source platform remains the system of record and the point of enforcement. ArtOfTheHack proposes; the source system acts.
- Cost to the grantee
- KRYOS-XS is provided at no cost to eligible nonprofits under a grant funded by James Scott and administered by the Embassy Row Project.
- Read-only advisory operation by default
- Human approval for high-impact actions
- Least-privilege, revocable permissions
- Explicit blind spots instead of assumed facts
- Reversible enforcement wherever technically available
Product
Where this capability sits
Product 01
KRYOS-XS Edge
A browser-based security decision assistant that helps users evaluate suspicious messages, external data sharing, OAuth approvals and other consequential actions at the moment they occur.
Adjacent capabilities
Other capabilities in this product
External Sharing and Data-Movement Governance
Evaluate a sharing decision before sensitive information leaves the organization, and offer a safer method.
Cloud Exposure and Configuration Decisioning
Identify configuration changes that may create unnecessary exposure, while the change is still being made.
