Connection model
How the API Overlay Works
KRYOS V6 sits on top of the tools you already use. It connects through approved APIs, reads the data it is allowed to read, organises that data into an evidence layer, and helps users query it through a governed reasoning interface. It does not require replacing your current systems.
Definition
A lightweight connection layer
Non-intrusive
What non-intrusive means here
Flow
From your tools to a released answer
One direction of travel, with a human at the end of it.
- Existing tools
- API overlay
- Normalization and evidence registration
- Black Atlas reasoning layer
- Chat, dashboards and analyst outputs
- Human review and release
Connections
What it connects to
- Cloud and infrastructure
- Account, workload, network and configuration state as the providers already expose it.
- Identity and privilege systems
- Directory, entitlement, role and privileged-access records that describe who can reach what.
- Vulnerability and exposure tools
- Findings, asset coverage and scan currency, treated as edges in a graph rather than a ranked queue.
- SIEM and SOC telemetry
- Detection, alerting and response history, used as observed behaviour rather than as proof of control.
- Policy and compliance repositories
- Control claims, standards mappings and audit artefacts, which the model can test rather than assume.
- Internal reports, playbooks and threat intelligence
- Prior red-team work, incident records, runbooks and external intelligence, registered as cited sources.
- Case management and ticketing
- Remediation state and ownership, so recommendations land where work is already tracked.
Governance
Governance built in
The full evidence and authorization model is set out on Evidence & Governance.
Architecture
Where the overlay sits
Deployment

