Skip to content
HEKA — See First. Defend First. Powered by KRYOS XS Hypercube
Unified overlay architecture

A governed control plane above the systems you already depend on.

KRYOS XS Hypercube is designed to observe, classify, evaluate, review, act, and preserve evidence — without forcing replacement of identity providers, applications, databases, endpoints, cloud services, field devices, or vendor systems.

KRYOS XS Hypercube — governed control planeObserve · Classify · Evaluate · Review · Act · Preserve EvidenceIdentityIdP / directoryunchangedApplicationsLegacy + SaaSunchangedDatabasesOn-prem + cloudunchangedEndpointsManaged / fieldunchangedCloud & vendorsStorage · APIsunchanged
Read-mostly by default
Actions are policy-scoped and reviewable.
Least-privilege
Every decision is bounded by the minimum needed.
Rollback-aware
Executed actions carry rollback tokens where supported.
Interoperable
Adapts to legacy, cloud, hybrid, distributed, and field environments where supported.
Human-governed
High-impact exceptions never auto-approve.
Evidence-first
Every material decision is written to the chain.
Architectural layers

Six operating layers of the overlay

Observation
Read-only telemetry from identity, endpoints, applications, data platforms, cloud services, and vendor connectors.
Classification
Data-sensitivity, jurisdictional, and mission-context tagging using versioned taxonomies.
Evaluation
Policy engine matches signals to documented rules and returns permit, restrict, deny, or escalate.
Review
Named human reviewers act on ambiguous or high-impact requests through the ECIA-7 gates.
Action
Bounded, least-privilege execution with rollback tokens where supported by the underlying system.
Evidence
Immutable, signed chain of decisions and outcomes with composed evidence-pack outputs.
Integration surface

What the overlay connects to

  • Identity providers. SAML/OIDC IdPs, directory services, and MFA/step-up systems for signal capture, not replacement.
  • Applications. SaaS and on-prem applications via existing authorization surfaces; read-mostly by default.
  • Data platforms. Databases, object stores, and analytics platforms for sensitivity classification and access mediation.
  • Endpoints. Managed endpoints and field devices where posture and telemetry are available.
  • Cloud services. Major cloud providers via their audit, IAM, and control-plane APIs.
  • Vendor and third-party systems. Selected connectors, portals, and shared platforms scoped to the beneficiary's mission.
  • Field and constrained environments. Distributed, intermittent-connectivity, or legacy environments where supported.
  • Existing security tooling. SIEM, EDR, DLP, and SOAR stacks — augmented, not replaced.

Decision and evidence flow

Human Review Workflow
  1. Step 1
    Request
  2. Step 2
    Policy eval
  3. Step 3
    Risk threshold
  4. Step 4
    Reviewer assigned
  5. Step 5
    Decision
  6. Step 6
    Execute or block
  7. Step 7
    Evidence seal

Timeouts, escalation, rollback, and emergency pathways are configurable.

Evidence Provenance Chain
EVT-1sealedEVT-2sealedEVT-3sealedEVT-4TAMPEREVT-5sealedEVT-6sealed

Modification visibly breaks the chain. Tamper-evident, not tamper-proof.