Fragmented evidence,
one governed decision surface.
CNIS federates RixTrace, RixIntel, RixControl, RixLogix, RixNexis and RixOne over a single NEURIX kernel — every score traceable to the evidence, module, rule, version and timestamp that produced it. No black-box number. No naïve averaging.
The broad exposure evidence producer, and the reference implementation — the kernel is validated here first.
One finding object, followed all the way to an outcome
Findings are never flattened into one generic severity. Every object carries multiple authoritative dimensions, and you can traverse the whole chain without leaving CNIS.
Finding
Raw evidence lands as a typed object with its source, tier and timestamp attached.
Score
The owning engine produces its index — ERI, TRI, CRI or ORI — under the coverage gate.
Scenario
INFERA connects scores across modules into credible organizational scenarios.
Evidence
Every number stays walkable back to the rule, version and record that produced it.
Action
PRAXIS compares candidate interventions and packages the defensible one.
Outcome
What changed is measured back into the platform, closing the loop.
Each answers one question properly, instead of all of them vaguely
Every product is a purpose-built engine with its own output index. The platform gains value as those outputs combine — not because any single module tries to become the whole stack.
RixTrace
SPECTRADNS, certificate transparency, internet exposure, vulnerability, credential and dark-web signal with active verification. The reference implementation — the kernel was validated here first.
RixIntel
SYNTRAKEV, CTI feeds, ransomware and campaign intelligence matched to your technology and sector. A feed outage is treated as an evidence limitation — never as evidence of no threat.
RixControl
NORMAPolicy, IAM, endpoint, cloud and attestation evidence mapped to obligations. The evidence tier sits next to the score, so a control never looks more verified than it actually is.
RixLogix
VERITASIEM exports, cloud audit logs, identity and endpoint telemetry, backup and recovery events. Computes in failure polarity internally and inverts exactly once, after the sufficiency gate.
RixNexis
INFERACross-module causal federation over typed engine outputs. Connects exposure, threat, control and operational findings into the relationships that actually matter to the organization.
RixOne
PRAXISCounterfactual action packaging. The final engine in the series: it compares candidate interventions against the security context CNIS has already established, and says which one is worth doing first.
NEURIX — one kernel, module-agnostic by construction
Neural Engine for Unified Resilience and Integrated security eXchange. No product name appears anywhere in kernel code, which is why six different engines can share it without drifting apart.
- K1
Propagate confidence, once
Confidence moves through the graph a single time. Nothing gets to count its own certainty twice on the way to a score.
- K2
Compose paths
Noisy-OR within independence groups, disjunction across groups, and a logistic soft-gate — so correlated evidence doesn't masquerade as corroboration.
- K3
Map to a band
Monte-Carlo mapping onto a reported band, with γ as the only fitted constant in the entire kernel.
- K4
Assemble under precondition
Output is assembled only once the coverage precondition holds. Thin evidence produces an honest gap, not a flattering number.
The kernel is carried unchanged across revisions. When a module's score moves, it is because its evidence moved — not because the mathematics underneath it was quietly re-tuned.
MAYA — the four-letter executive epitome of CNIS
Multi-Axis Yield & Assurance. Not a replacement for ERI, TRI, CRI, ORI or VERDICT — a governed platform-level synthesis that sits above them and stays answerable to all six.
Shape only — illustrative values, no live scoring, thresholds or calibration data shown. Pipeline currently runs at 0.9-shadow.
Six axes, bounded output, explicit sensitivity rules. MAYA summarizes exposure pressure, threat pressure, assurance, operational reliability, organizational scenario pressure and defensible action value into one governed figure a board can read.
What it is not is a six-number average. Coverage, freshness and uncertainty are inputs in their own right, and a thin axis drags the synthesis toward honesty rather than being quietly rounded away.
MAYA = clamp(platform_synthesis(MAYA_input, maya_version), 0, 100)
MAYA_output = {score, band, state, drivers, dependencies, maya_version}
// governed synthesis — never a naïve six-number average
Thirteen invariants the platform is not allowed to violate
The invariants are authoritative. They constrain what any engine may claim, and they are why a CNIS number can be defended in a room full of people who did not build it.
One finding keeps multiple authoritative dimensions. It is never collapsed into a single generic severity.
Composition follows the kernel's independence rules. Correlated evidence does not get to look like corroboration.
Missing coverage is reported as missing coverage. Absence of signal is never rendered as a favourable result.
Every score walks back to the evidence, module, rule, version and timestamp that produced it.
Twenty-six connector classes, one contract
Engines never speak to a source directly. Everything arrives through the connector control plane as a typed, tiered evidence object, which is what makes the kernel able to stay module-agnostic.
DNS, certificate transparency, internet exposure and active verification.
KEV, CTI and campaign feeds, exploitability and sector matching.
GRC and policy systems, IAM, endpoint, cloud posture, VAPT, attestation.
SIEM export, cloud audit logs, identity logs, backup and recovery events.
Begin with one engine. The platform compounds from there.
CNIS is deliberately not an all-or-nothing replacement for your security stack. Each engine is useful alone; the federation is what makes the second one worth more than the first.
Deploy a single module against a defined question and get a defensible index out of it.
INFERA begins connecting outputs, and cross-module relationships become visible.
The organizational scenario picture fills in across exposure, threat, control and operations.
PRAXIS closes the loop — evidence becomes a governed decision, and MAYA reports the whole.
See a finding travel the whole chain
A live walkthrough follows one realistic finding from evidence through its engine score, into an organizational scenario, out to a governed action, and up into MAYA.