DETERMINISTIC INTELLIGENCE · CYBERSECURITY

Reconstruct technical exposure from assets, identities and controls.

Know the asset. Know the exposure. Know what changed.

Cybersecurity Intelligence reconstructs asset state, identity paths, findings, controls, remediation and verification from governed security Ground without turning exposure into proof of attack.

Asset · Identity · Exposure · Control · Finding · Verification

01

CYBERSECURITY GROUND

Establish the technical asset, identity and observed state before interpreting exposure.

Asset inventories, IAM, vulnerability scanners, endpoint systems, cloud-security platforms, configuration records, controls, alerts, tickets and verification observations can establish governed technical security Ground.

Asset inventories Identities & privileges Services & ports Vulnerability findings Configuration observations Control observations Security events Remediation records Verification records Effective timestamps

02

SEMANTIC DISCIPLINE

Exposure is not compromise. Control presence is not control effectiveness.

An asset is not an exposure. A vulnerability is not automatically exploitable. A finding is not automatically compromise. An alert is not automatically an incident. A remediation task is not proof of remediated technical state.

ASSET

The governed technical object

A host, workload, cloud resource, application or service remains a distinct technical identity across source systems.

EXPOSURE

An observed technical relationship

Exposure represents reachable, vulnerable or insufficiently controlled state under explicit technical semantics.

CONTROL

A safeguard with observable state

Control presence and configuration can be observed. Claimed effectiveness requires its own Evidence.

03

QUESTIONS

Security questions answered from Ground.

Which assets are in scope?

Resolve technical identity across inventories, hosts, workloads, services and cloud resources.

Which services are externally reachable?

Reconstruct reachability under an explicit network and service definition.

Which identities can reach this asset?

Trace governed accounts, privileges and access relationships.

Which findings still affect this asset?

Relate findings to observed technical state instead of ticket status alone.

Which remediation has verification Evidence?

Separate a recorded action from a post-change observation proving the condition changed.

What cannot be established?

Exposure, findings and scores do not by themselves establish exploitation, compromise, attacker intent or future attack.

04

MEASURES

Define the technical population, observation period and security semantics behind every measure.

Open findings

Findings whose governed state remains open

Count findings only inside an explicit asset population, observation period and finding-state definition.

Ground: finding · asset · observation · state

Exposed services

Services reachable under the selected definition

Exposure depends on service identity, reachability and relevant technical control Ground.

Ground: asset · service · reachability · control

Unverified remediations

Recorded actions without closing verification Evidence

A remediation action remains unverified until governed post-change observation demonstrates the relevant condition changed.

Ground: finding · remediation · post-change observation

05

FINDING TO VERIFICATION · ILLUSTRATIVE EXAMPLE — SYNTHETIC DATA

A remediation record becomes verified only when the technical condition changes.

FINDING F-1842 Unsupported package version
AFFECTED ASSET srv-pay-04 Governed asset identity
OBSERVED CONDITION v3.1 present Scanner observation
REMEDIATION Upgrade recorded Ticket marked complete
VERIFICATION v3.4 observed Post-change Evidence

Ticket completion and verified technical state are different facts. Verification requires Ground showing that the relevant condition changed.

06

EXPOSURE GRAPH · ILLUSTRATIVE EXAMPLE — SYNTHETIC DATA

Trace technical exposure as a relationship instead of reducing it to a score.

EXTERNAL SURFACE Internet edge Observed reachable boundary
SERVICE HTTPS :443 Published service
IDENTITY / PATH svc-api-prod Privileged service identity
CONTROL STATE MFA not applicable Observed control context
PROTECTED ASSET api-prod-02 Governed technical asset

Reachability and dependency can be reconstructed deterministically. They do not automatically establish an attack path, exploit success or attacker intent.

07

SECURITY STATE THROUGH TIME · ILLUSTRATIVE EXAMPLE — SYNTHETIC DATA

Follow exposure, remediation and verification through actual technical chronology.

08:10 Asset observed Service inventory refreshed
08:14 Finding opened Scanner observation linked
08:18 Exposure reconstructed Reachability established
10:42 Control changed Configuration updated
11:03 Verification observed Post-change scan confirms state
11:06 Finding closed Closure follows verification

Historical security state remains inspectable instead of being overwritten by the latest scanner or ticket status.

08

DATA SUFFICIENCY

See what the available Cybersecurity Ground can establish.

Asset exposure

Asset, service, reachability and control Ground are present.

AVAILABLE

Exposure can be reconstructed under the selected technical definition.

Remediation state

A remediation action exists but verification Ground is incomplete.

PARTIAL

Recorded remediation remains distinct from demonstrated post-change state.

Compromise

No governed Evidence establishes successful unauthorized access or execution.

NOT_ESTABLISHED

Findings and exposure do not automatically establish compromise.

09

WHY THIS EXPOSURE?

Trace reconstructed exposure back to technical observations and source records.

RESULT Asset Exposure
ASSET Governed Asset
SERVICE Observed Service
OBSERVATION Reachability + Control State
GROUND Source Record

Findings, exposure and remediation state remain connected to the scanner observations, configurations, controls and verification records that establish them.

10

SECURITY / JUDGMENT BOUNDARY

Technical exposure is not proof of attack or autonomous security authority.

Cybersecurity Intelligence may establish asset identity, identity relationships, services, observed configuration, findings, observed vulnerabilities, defined exposure state, observed control state, remediation chronology, verification chronology and security-event chronology.

It does not silently infer successful exploitation, compromise, attacker identity, attacker intent, malicious intent, causal attribution, future attack, future breach, control effectiveness beyond observed Evidence, business impact, legal liability, regulatory compliance, the optimal remediation decision, the optimal defensive action or autonomous security authority.

11

DAILY DETERMINISTIC INTELLIGENCE

Search, compare, reconstruct and trace technical security state without requiring AI.

SOURCE AUTHORITY

Security systems remain authoritative.

Asset systems, IAM, EDR, vulnerability scanners, SIEM, cloud platforms and configuration sources retain authority over their records.

TRACE EXPOSURE

Follow technical state to Evidence.

Navigate from an exposure or finding through assets, identities, controls, observations and source records.

AI OPTIONAL IN DAILY USE

CUSTOMER-CONTROLLED COMPUTE

Deterministic Cybersecurity Intelligence can operate over customer-controlled security Ground without requiring a generative model or mandatory radius19-hosted SaaS runtime.

PRODUCT BOUNDARY

Observation is not autonomous security action.

The product does not establish automatic source-data correctness, automatic risk correctness, guaranteed vulnerability exploitability, proof of compromise from exposure alone, autonomous remediation, offensive exploitation, access-control authority or operational writeback. It is not a generative copilot for ordinary daily use.

12

SOFTWARE LICENSE

Deploy Cybersecurity Intelligence in customer-controlled infrastructure.

Cybersecurity Intelligence is offered as software under a direct licensing and delivery relationship. Security Ground, source systems, reconstruction rules, access boundaries and deployment context determine the bounded product configuration.

Discuss Cybersecurity Intelligence with radius19 ← Back to Products