Frequently asked questions.
Does KRYOS XS Hypercube replace our existing security tools?+
No. It is a governed overlay that connects to your existing identity provider, applications, databases, endpoints, cloud services, field devices, and vendor systems without forcing replacement. Existing SIEM, EDR, DLP, and SOAR investments are augmented, not displaced.
Is the program really at no cost?+
Yes, for eligible, approved beneficiaries. Access is provided through grants administered by Embassy Row Project and fully funded by James Scott through the Strategic Capability Philanthropy model. Nothing on this site constitutes automatic eligibility or guaranteed approval.
Who is James Scott and how is the program funded?+
James Scott is a technologist and systems architect, founder of the Embassy Row Project and the Institute for Critical Infrastructure Cybersecurity (ICIC). He personally underwrites the program through Strategic Capability Philanthropy — a model that transfers permanent infrastructure rather than recurring financial grants. No donations are accepted across the ecosystem.
What is Strategic Capability Philanthropy?+
SCP is a philanthropic model in which recipients receive permanent, enterprise-grade capability — AI, cybersecurity, compliance, and governance systems — rather than temporary financial grants. The intent is durable operational sovereignty, not recurring dependency.
Do you use post-quantum encryption today?+
Cryptographic exposure discovery and PQC readiness mapping is a discovery, exposure-classification, prioritization, and crypto-agility service. It does not imply completed post-quantum migration, and the overlay itself is not a universally deployed post-quantum encryption layer.
Where does human review occur?+
At elevated access requests, ambiguous classifications, cross-border transfers, containment decisions, cryptographic migrations, evidence-pack release, and any action beyond a documented risk threshold. Reviews pass through the ECIA-7 gate model.
What are the ECIA-7 gates?+
Seven checkpoints — Eligibility, Classification, Intent, Approval, Action, Evidence, and Audit — through which consequential actions pass. Each is a documented decision with named reviewer identity, timestamp, rationale, and policy state recorded on the chain.
How are approvals signed and recorded?+
Approvals and exception workflows are cryptographically signed and chained to an immutable evidence ledger. Reviewer identity, timestamp, and policy version are captured for each decision.
How is oversight structured?+
Quarterly assurance reviews and periodic audits analyze approval latency, exception frequency, rollback usage, and gate effectiveness. Beneficiaries retain ultimate authority over approval chains, exception thresholds, and evidence access.
Do you guarantee compliance?+
No. The program supports informed decision-making and preserves evidence. It is not a substitute for qualified legal counsel and does not guarantee compliance with any specific regulation or jurisdiction.
How is evidence protected?+
Events are timestamped and linked into a chain, with cryptographic signing or sealing where supported. Modifications become visibly detectable — tamper-evident, not tamper-proof.
What obligations do beneficiaries take on?+
Named reviewers, current taxonomies and rosters, ratification of policy and evidence release, and coordination with counsel where legal decisions are required. Beneficiaries also nominate the approval chain for their environment.
Can we operate the overlay in field environments?+
Where supported by connectivity and endpoint constraints. The overlay is designed to be appropriate for legacy, cloud, hybrid, distributed, and field environments where supported.
Do you accept donations?+
No. No donations are accepted across the Embassy Row Project ecosystem. The program is fully underwritten by the founder.
Is my data monetized in any way?+
No. There is no data-monetization path. Beneficiaries retain ownership of their systems, data, and decisions at every step.
What are the biggest claims you deliberately do not make?+
We do not claim full protocol-level PQC across all beneficiary systems, drop-in replacement for existing TLS or PKI stacks, guaranteed quantum resistance across every dependency, certification without validation, security across integrations without integration testing, or that the program is a substitute for human incident responders or legal counsel.
