Unified overlay architecture
A governed control plane above the systems you already depend on.
KRYOS XS Hypercube is designed to observe, classify, evaluate, review, act, and preserve evidence — without forcing replacement of identity providers, applications, databases, endpoints, cloud services, field devices, or vendor systems.
Read-mostly by default
Actions are policy-scoped and reviewable.
Least-privilege
Every decision is bounded by the minimum needed.
Rollback-aware
Executed actions carry rollback tokens where supported.
Interoperable
Adapts to legacy, cloud, hybrid, distributed, and field environments where supported.
Human-governed
High-impact exceptions never auto-approve.
Evidence-first
Every material decision is written to the chain.
Architectural layers
Six operating layers of the overlay
Observation
Read-only telemetry from identity, endpoints, applications, data platforms, cloud services, and vendor connectors.
Classification
Data-sensitivity, jurisdictional, and mission-context tagging using versioned taxonomies.
Evaluation
Policy engine matches signals to documented rules and returns permit, restrict, deny, or escalate.
Review
Named human reviewers act on ambiguous or high-impact requests through the ECIA-7 gates.
Action
Bounded, least-privilege execution with rollback tokens where supported by the underlying system.
Evidence
Immutable, signed chain of decisions and outcomes with composed evidence-pack outputs.
Integration surface
What the overlay connects to
- Identity providers. SAML/OIDC IdPs, directory services, and MFA/step-up systems for signal capture, not replacement.
- Applications. SaaS and on-prem applications via existing authorization surfaces; read-mostly by default.
- Data platforms. Databases, object stores, and analytics platforms for sensitivity classification and access mediation.
- Endpoints. Managed endpoints and field devices where posture and telemetry are available.
- Cloud services. Major cloud providers via their audit, IAM, and control-plane APIs.
- Vendor and third-party systems. Selected connectors, portals, and shared platforms scoped to the beneficiary's mission.
- Field and constrained environments. Distributed, intermittent-connectivity, or legacy environments where supported.
- Existing security tooling. SIEM, EDR, DLP, and SOAR stacks — augmented, not replaced.
Decision and evidence flow
Human Review Workflow
- Step 1Request
- Step 2Policy eval
- Step 3Risk threshold
- Step 4Reviewer assigned
- Step 5Decision
- Step 6Execute or block
- Step 7Evidence seal
Timeouts, escalation, rollback, and emergency pathways are configurable.
Evidence Provenance Chain
Modification visibly breaks the chain. Tamper-evident, not tamper-proof.
