Domain 1
Adversarial Assurance
Authorization, baseline reconstruction, threat modeling, retest, and audit-ready assurance lifecycle.
Questions it answers
- What is our actual exposure baseline, on evidence?
- Which control gaps require executive action now?
- Is this assurance claim releasable, qualified, or blocked?
Flagship service →Domain 2
Attack-Path and Exposure Intelligence
System-level paths, crown jewels, shadow exposure, vulnerability chains, choke points, and remediation compression.
Questions it answers
- What are the real routes from the internet to our most sensitive data?
- Which single choke point appears on the most paths?
- What is the smallest change that breaks the most pathways?
Flagship service →Domain 3
Identity and Privilege Intelligence
Human, machine, service, and agent identities; effective privilege; delegation; escalation; and least privilege.
Questions it answers
- Which identity creates the largest privilege amplification?
- Where does delegation quietly bridge two trust domains?
- What would least privilege actually cost operationally?
Flagship service →Domain 4
Cloud, Application, API, and Infrastructure Security
Cloud architecture, APIs, applications, infrastructure as code, CI/CD, secrets, drift, updates, and recovery.
Questions it answers
- Can the build pipeline reach production without a human in the path?
- Which secrets are reachable from a compromised worker?
- Where has the deployed state drifted from the approved baseline?
Flagship service →Domain 5
AI, RAG, Model, and Agentic Security
Models, prompts, retrieval, corpora, vector stores, memory, tools, agents, identity, autonomy, evaluators, and consensus.
Questions it answers
- What is the maximum blast radius of each deployed agent?
- Where can untrusted input reach a privileged action?
- Which agent actions are irreversible and therefore need approval?
Flagship service →Domain 6
Supply-Chain and Third-Party Security
Software dependencies, SBOMs, connectors, vendors, concentration, provenance, and M&A integration.
Questions it answers
- What happens to us if this vendor is compromised?
- Do our independent suppliers share one hidden dependency?
- What cyber exposure are we acquiring with this company?
Flagship service →Domain 7
Cyber Risk, Causal Intelligence, and Simulation
Causal reasoning, Bayesian updating, Monte Carlo, temporal graphs, counterfactuals, and loss scenarios.
Questions it answers
- Which attack paths exist only during maintenance windows?
- How does modelled risk change under this environmental shift?
- What loss scenarios dominate, and under which assumptions?
Domain 8
Security Control Assurance and Falsification
Control validation, claim falsification, assurance cases, failure analysis, and executable policy constraints.
Questions it answers
- Does this control actually hold, or is it only documented?
- What evidence would falsify our own security claim?
- Which policies can be expressed as continuously checked constraints?
Flagship service →Domain 9
Resilience, Architecture, and Systemic Failure Analysis
Fragility, common-mode failure, defense independence, segmentation, recovery, and observability.
Questions it answers
- Are our layered controls genuinely independent of each other?
- What are the minimal combinations of failures that cause a material breach?
- Where would segmentation cut the most cross-community attack edges?
Domain 10
Threat Intelligence, SOC, Incident, and Forensic Intelligence
Threat contextualization, alert prioritization, incident reconstruction, forensic hypotheses, near misses, and terrain shaping.
Questions it answers
- Which alerts matter given our actual topology?
- What sequence best explains the evidence we hold?
- What did this near miss reveal about structural weakness?
Domain 11
Compliance and Regulatory Assurance
Continuous compliance, control mapping, privacy, currentness, audit replay, deficiency closure, and evidence governance.
Questions it answers
- Which controls have live technical evidence rather than screenshots?
- Where does compliance status diverge from actual security state?
- Can we replay the evidence behind last quarter's attestation?
Domain 12
Critical Infrastructure and Cyber-Physical Assurance
OT, ICS, critical infrastructure, healthcare, finance, defense, aerospace, robotics, and autonomous systems.
Questions it answers
- Which cyber paths lead to a physical or clinical consequence?
- How does the objective change when safety outranks confidentiality?
- Which unsafe control interactions are possible, not just which components fail?
Domain 13
Executive, Board, and Capital-Allocation Intelligence
Decision compression, risk appetite, capital allocation, maturity, and transformation roadmaps.
Questions it answers
- Where should the next tranche of security budget go?
- Does our architecture satisfy the board's stated risk appetite?
- What is the traceable line from board risk to technical evidence?
Flagship service →Domain 14
Continuous Security Operations
Twin operations, recurring adversarial assurance, laboratories, synthetic data, continuous learning, and model governance.
Questions it answers
- How do we keep the twin current against ephemeral infrastructure?
- What recurring assurance cadence does this environment need?
- How is the reasoning model itself governed and reviewed?