Core concepts
The ideas the model runs on
- Adversarial digital twin
- A living model of the enterprise as an attacker experiences it: assets, identities, trust relationships, network reachability, cloud posture, code and build paths, data location, and the controls claimed over each. The twin is where attacks are rehearsed so they are not rehearsed in production.
- Attack-path intelligence
- Individual weaknesses are treated as edges, not verdicts. What matters is whether a chain of them connects an entry point to something that would actually hurt. A critical-severity finding on an unreachable host can rank below a medium one that completes a path.
- Crown-jewel inversion
- Reasoning runs backwards from the assets whose loss would be material — payment authority, customer data, safety systems, the ability to operate — to every route that reaches them, rather than forwards from whatever the scanners happened to find.
- Security hypercube
- Exposure is evaluated across simultaneous dimensions — identity, network, cloud, application, data, supply chain, human, and agentic AI — so risk that only appears at an intersection of two domains is not lost between two teams.
- Minimal cut sets
- The smallest set of changes that severs the largest number of material pathways. This is the difference between a remediation backlog of thousands of items and a short list of interventions that measurably alters the graph.
- Evidence ledger and provenance
- Every input carries its origin, age and confidence. Conclusions inherit the weakest evidence beneath them. Where an input is stale, partial or unverified, the output says so instead of averaging the doubt away.
Every term above is also defined in two registers in the glossary.