Grantee profile 03
Laboratory, data, and collaboration security decided on one geometry.
Nonprofit research institutes run instrument networks, shared compute, and external collaborations that sit outside normal organization controls. The overlay reasons across those environments together instead of leaving each one to its own console.
Pressure
What is forcing the decision layer
- Instrument and laboratory networks cannot tolerate arbitrary isolation
- Collaborations grant external researchers standing access to internal systems
- Research data is valuable to both criminal and state actors
- Grant compliance requires evidence of controls without a compliance department
- Shared compute and code repositories accumulate credentials over years
First workflows
Where instrumentation starts
- External collaborator access review and revocation
- Credential exposure in code repositories and notebooks
- Instrument and laboratory network anomaly adjudication
- Research-data exfiltration triage
- Cloud compute misconfiguration prioritization
- Grant-required control evidence assembly
Integration
Systems ArtOfTheHack reads from and instructs
ArtOfTheHack does not replace these systems. It reads their evidence, adjudicates against it, and returns a governed instruction to the same infrastructure.
Evidence sources
- Identity providers and federated research identity systems
- Cloud control planes and compute audit logs
- Code repository and secret-scanning output
- Network telemetry from laboratory and instrument segments
- Endpoint protection consoles
- Vulnerability and asset inventories
Action targets
- Identity systems for scoped collaborator access changes
- Cloud control planes for reversible configuration correction
- Repository platforms for credential rotation workflows
- Ticketing systems for approval routing and evidence capture
- Reporting systems for funder-ready control evidence
Authority
How authority is constrained
- Safety gate: no automated action against instrument or laboratory control networks
- Principal investigator approval required for actions affecting active experiments
- Blast-radius limits defined per network segment and per action class
- Rollback path validated before any action class becomes eligible for automation
- Every determination replayable with the policy and model versions in force
ArtOfTheHack services are provided at no cost through grants funded by James Scott and administered by the Embassy Row Project. Access begins with a grant application. The overlay is non-intrusive: it reads from the systems the organization already runs and installs nothing.
First 90 days
A typical entry sequence
Days 1 to 15
Grant application and award. Mapping of research environments, instrument segments, and collaboration agreements.
Days 16 to 40
Read-only connection to identity, cloud, and repository systems. Evidence-quality baseline for each source.
Days 41 to 70
Digital twin of the research environment. Monte Carlo scenario ranges for containment options against active experiments.
Days 71 to 90
Advisory operation on collaborator access, plus a funder-ready control evidence package.
Standard applied
What this profile can hold ArtOfTheHack to
- Instrument networks are modeled before any containment option is recommended
- Control evidence is produced as a byproduct of deciding, not as a separate reporting exercise
- Collaborator access decisions carry named authority and an expiry
Applicable
Products, services, and industry context
Products
- KRYOS-XS Console
A centralized Cyber Decision Operations Hub that converts alerts, identity risks, access questions, data exposures and response requirements into one prioritized decision queue.
- KRYOS-XS Edge
A browser-based security decision assistant that helps users evaluate suspicious messages, external data sharing, OAuth approvals and other consequential actions at the moment they occur.
Services
- Cloud Exposure and Configuration Decisioning
KRYOS-XS Edge
- Access and Entitlement Review
KRYOS-XS Console
- Alert Triage and Incident Adjudication
KRYOS-XS Console
- OAuth and Automation Authority Governance
KRYOS-XS Console
