CyberNeurix Intelligence Suite

Fragmented evidence,
one governed decision surface.

CNIS federates RixTrace, RixIntel, RixControl, RixLogix, RixNexis and RixOne over a single NEURIX kernel — every score traceable to the evidence, module, rule, version and timestamp that produced it. No black-box number. No naïve averaging.

Six specialist engines One shared kernel Evidence-traceable MAYA synthesis
6Specialist engines
13Design invariants
26Connector classes
1Shared kernel, carried byte-for-byte
Single canonical finding inventory

One finding object, followed all the way to an outcome

Findings are never flattened into one generic severity. Every object carries multiple authoritative dimensions, and you can traverse the whole chain without leaving CNIS.

Stage 01

Finding

Raw evidence lands as a typed object with its source, tier and timestamp attached.

Stage 02

Score

The owning engine produces its index — ERI, TRI, CRI or ORI — under the coverage gate.

Stage 03

Scenario

INFERA connects scores across modules into credible organizational scenarios.

Stage 04

Evidence

Every number stays walkable back to the rule, version and record that produced it.

Stage 05

Action

PRAXIS compares candidate interventions and packages the defensible one.

Stage 06

Outcome

What changed is measured back into the platform, closing the loop.

Six engines

Each answers one question properly, instead of all of them vaguely

Every product is a purpose-built engine with its own output index. The platform gains value as those outputs combine — not because any single module tries to become the whole stack.

ERI

RixTrace

SPECTRA
Exposure Risk Index

DNS, certificate transparency, internet exposure, vulnerability, credential and dark-web signal with active verification. The reference implementation — the kernel was validated here first.

External exposureOpen module →
TRI

RixIntel

SYNTRA
Threat Relevance Index

KEV, CTI feeds, ransomware and campaign intelligence matched to your technology and sector. A feed outage is treated as an evidence limitation — never as evidence of no threat.

Threat relevanceOpen module →
CRI

RixControl

NORMA
Compliance Risk Index

Policy, IAM, endpoint, cloud and attestation evidence mapped to obligations. The evidence tier sits next to the score, so a control never looks more verified than it actually is.

Control assuranceOpen module →
ORI

RixLogix

VERITA
Operational Reliability Index

SIEM exports, cloud audit logs, identity and endpoint telemetry, backup and recovery events. Computes in failure polarity internally and inverts exactly once, after the sufficiency gate.

Operational assuranceOpen module →
VERDICT

RixNexis

INFERA
Organizational Inference

Cross-module causal federation over typed engine outputs. Connects exposure, threat, control and operational findings into the relationships that actually matter to the organization.

Federation layerOpen module →
ACTION-ROI

RixOne

PRAXIS
Action-ROI / DecisionPackage

Counterfactual action packaging. The final engine in the series: it compares candidate interventions against the security context CNIS has already established, and says which one is worth doing first.

Decision layerOpen module →
The substrate

NEURIX — one kernel, module-agnostic by construction

Neural Engine for Unified Resilience and Integrated security eXchange. No product name appears anywhere in kernel code, which is why six different engines can share it without drifting apart.

  1. K1

    Propagate confidence, once

    Confidence moves through the graph a single time. Nothing gets to count its own certainty twice on the way to a score.

  2. K2

    Compose paths

    Noisy-OR within independence groups, disjunction across groups, and a logistic soft-gate — so correlated evidence doesn't masquerade as corroboration.

  3. K3

    Map to a band

    Monte-Carlo mapping onto a reported band, with γ as the only fitted constant in the entire kernel.

  4. K4

    Assemble under precondition

    Output is assembled only once the coverage precondition holds. Thin evidence produces an honest gap, not a flattering number.

Kernel status
Kernel versionv3.0-cal-1
Scoring blocks6
Blocks validated1 of 6
Design invariants13
Reference gateG7 · RixTrace frozen
Continuitybyte-for-byte since v3.1

The kernel is carried unchanged across revisions. When a module's score moves, it is because its evidence moved — not because the mathematics underneath it was quietly re-tuned.

Platform synthesis

MAYA — the four-letter executive epitome of CNIS

Multi-Axis Yield & Assurance. Not a replacement for ERI, TRI, CRI, ORI or VERDICT — a governed platform-level synthesis that sits above them and stays answerable to all six.

Illustrative six-axis vectorMAYA · 0–100
Exposure pressure · ERI78
Threat pressure · TRI61
Control assurance · CRI69
Operational reliability · ORI82
Scenario pressure · VERDICT
Action value · ACTION-ROI

Shape only — illustrative values, no live scoring, thresholds or calibration data shown. Pipeline currently runs at 0.9-shadow.

Six axes, bounded output, explicit sensitivity rules. MAYA summarizes exposure pressure, threat pressure, assurance, operational reliability, organizational scenario pressure and defensible action value into one governed figure a board can read.

What it is not is a six-number average. Coverage, freshness and uncertainty are inputs in their own right, and a thin axis drags the synthesis toward honesty rather than being quietly rounded away.

MAYA_input = {ERI, TRI, CRI, ORI, VERDICT, ACTION_ROI, coverage, freshness, uncertainty}
MAYA = clamp(platform_synthesis(MAYA_input, maya_version), 0, 100)
MAYA_output = {score, band, state, drivers, dependencies, maya_version}
// governed synthesis — never a naïve six-number average
Governance

Thirteen invariants the platform is not allowed to violate

The invariants are authoritative. They constrain what any engine may claim, and they are why a CNIS number can be defended in a room full of people who did not build it.

Never flatten

One finding keeps multiple authoritative dimensions. It is never collapsed into a single generic severity.

Never average naïvely

Composition follows the kernel's independence rules. Correlated evidence does not get to look like corroboration.

Never flatter thin evidence

Missing coverage is reported as missing coverage. Absence of signal is never rendered as a favourable result.

Never lose provenance

Every score walks back to the evidence, module, rule, version and timestamp that produced it.

evidencemoduleruleversiontimestampcoveragefreshnessuncertainty
Control plane

Twenty-six connector classes, one contract

Engines never speak to a source directly. Everything arrives through the connector control plane as a typed, tiered evidence object, which is what makes the kernel able to stay module-agnostic.

Surface

DNS, certificate transparency, internet exposure and active verification.

Threat

KEV, CTI and campaign feeds, exploitability and sector matching.

Assurance

GRC and policy systems, IAM, endpoint, cloud posture, VAPT, attestation.

Telemetry

SIEM export, cloud audit logs, identity logs, backup and recovery events.

How teams start

Begin with one engine. The platform compounds from there.

CNIS is deliberately not an all-or-nothing replacement for your security stack. Each engine is useful alone; the federation is what makes the second one worth more than the first.

One engine

Deploy a single module against a defined question and get a defensible index out of it.

Two engines

INFERA begins connecting outputs, and cross-module relationships become visible.

Four engines

The organizational scenario picture fills in across exposure, threat, control and operations.

Full suite

PRAXIS closes the loop — evidence becomes a governed decision, and MAYA reports the whole.

See a finding travel the whole chain

A live walkthrough follows one realistic finding from evidence through its engine score, into an organizational scenario, out to a governed action, and up into MAYA.