Skip to content
Black Atlas — Powered by KRYOS V6

Connection model

How the API Overlay Works


KRYOS V6 sits on top of the tools you already use. It connects through approved APIs, reads the data it is allowed to read, organises that data into an evidence layer, and helps users query it through a governed reasoning interface. It does not require replacing your current systems.

Definition

A lightweight connection layer

Non-intrusive

What non-intrusive means here

  • does not require replacing your SIEM, IAM, cloud, ticketing or document systems
  • uses approved connectors and scoped API access
  • respects existing ownership and access boundaries
  • can start read-only
  • can operate as advisory-only
  • fails closed when permissions or evidence are insufficient

Flow

From your tools to a released answer

One direction of travel, with a human at the end of it.

  1. Existing tools
  2. API overlay
  3. Normalization and evidence registration
  4. Black Atlas reasoning layer
  5. Chat, dashboards and analyst outputs
  6. Human review and release

Connections

What it connects to

Cloud and infrastructure
Account, workload, network and configuration state as the providers already expose it.
Identity and privilege systems
Directory, entitlement, role and privileged-access records that describe who can reach what.
Vulnerability and exposure tools
Findings, asset coverage and scan currency, treated as edges in a graph rather than a ranked queue.
SIEM and SOC telemetry
Detection, alerting and response history, used as observed behaviour rather than as proof of control.
Policy and compliance repositories
Control claims, standards mappings and audit artefacts, which the model can test rather than assume.
Internal reports, playbooks and threat intelligence
Prior red-team work, incident records, runbooks and external intelligence, registered as cited sources.
Case management and ticketing
Remediation state and ownership, so recommendations land where work is already tracked.

Governance

Governance built in

The full evidence and authorization model is set out on Evidence & Governance.

Architecture

Where the overlay sits

  1. 06

    Human review, approval and release

    Release states, approval gates and escalation. High-risk conclusions do not leave without the review the authorization model requires.

  2. 05

    Cybersecurity RAG chat interface

    A bounded question-and-answer surface for analysts, executives and compliance users, with citations, claim status and uncertainty shown alongside the answer.

  3. 04

    Retrieval, contradiction and reasoning engine

    Hybrid retrieval, reranking by authority and currency, contradiction and gap checks, then adversarial modelling over the resulting state.

  4. 03

    Evidence registration and provenance layer

    Inputs are normalised, registered as sources, versioned, and carried forward with origin, age and confidence attached.

  5. 02

    Non-intrusive API overlay

    Scoped, approved connectors that read what they are permitted to read. Read-only to begin with, and additive rather than replacing anything.

  6. 01

    Existing security and business systems

    The platforms already in place and already owned: cloud, identity, detection, exposure management, compliance, ticketing, internal knowledge.

Black Atlas sits above the existing stack. It connects, normalises, retrieves, reasons, and releases only within approved governance boundaries.

Deployment

How a deployment is scoped

  1. Phase 1

    Connect

    Connect approved systems through scoped APIs and register evidence sources.

  2. Phase 2

    Normalize

    Map incoming data into a governed evidence structure with provenance and version control.

  3. Phase 3

    Retrieve

    Enable hybrid retrieval across documents, telemetry, policies and internal knowledge.

  4. Phase 4

    Answer

    Expose a bounded chat interface for analysts, executives or compliance users.

  5. Phase 5

    Govern

    Apply authorization, logging, contradiction checks, review gates and release controls.