Videt omnia. Meminit omnia. Iudicat omnia.
Adwersarz, który sądzi
Jedna pętla: polowanie w granicach prawa, domknięcie detekcji na SIEM-ie klienta, dowód zapieczętowany pod DORA. Dane i znaleziska zostają u Ciebie, rozumowanie idzie do LLM z maskowaniem adresów.
The adversary that judges
One loop: hunting within legal scope, detection closed on the client's SIEM, evidence sealed for DORA. Client data and findings stay with you; the reasoning goes to an LLM with address masking.
Wybierz ścieżkę czytaniaPick a reading path
Czym się różnimy
Narzędzia, które znasz, dają zwykle jedną warstwę: skaner zwraca listę podatności, platforma BAS odgrywa gotowy scenariusz, pentest kończy się raportem, a usługa red-team to wynajęta para rąk. CYRBER łączy sześć rzeczy w jedną rządzoną pętlę i to ich połączenie, a nie żadna z osobna, stanowi różnicę.
Rozumuje, zamiast odgrywać skrypt. MENS, agentowy narząd organizmu, prowadzi misję tak, że na każdej iteracji przechodzi OBSERVE, THINK, ACT, LEARN i sam wybiera następny ruch. Operator nie pisze playbooka pod konkretny cel, lecz obserwuje rozumowanie i pieczętuje wnioski. Skaner odpala stałą listę wtyczek, a platforma BAS odgrywa z góry ułożony scenariusz. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Celuje w realny dostęp, nie w listę CVE. Misja dąży do udowodnienia, że łańcuch da się przejść, a nie do wydrukowania rejestru podatności, przy czym domyślnie zatrzymuje się na udowodnionym dostępie, a ekstrakcję czy exfiltrację włączasz osobnym, bramkowanym trybem. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Domyka detekcję na SIEM-ie klienta. Wynik ataku trafia na SIEM klienta, obsługiwany konektorem (Wazuh i inne), więc atak i obrona uczą się na tym samym zdarzeniu, a luka w detekcji się zamyka. To purple, czyli red i blue w jednej pętli, a nie sam red team, który zostawia raport. Konektor SIEM i standing-purple MAMY, a gotowy stack Wazuh dla on-prem bez własnego SOC DOŁOŻYMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Zostawia dowód, nie obietnicę. Każde znalezisko jest zahashowane i zamknięte w drzewie Merkle, a korzeń drzewa każdej misji zobowiązujemy w kalendarzu OpenTimestamps (kotwica w Bitcoinie dochodzi po potwierdzeniu w bloku), więc werdykt sprawdzisz sam, bez dostępu do naszej bazy. Raport, któremu trzeba zaufać, zastępujemy dowodem, który przeliczysz. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Należy do klienta. Platforma stoi u klienta on-prem, dane oraz przebieg misji zostają na jego infrastrukturze, a my nie trzymamy żadnej kopii; do pełnego odcięcia od sieci brakuje jeszcze lokalnego modelu rozumowania. On-prem MAMY, pełny air-gap DOŁOŻYMY. Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Żyje, zamiast stać. Organizm sam leczy własny stan działania, uczy się z każdej zamkniętej misji i pilnuje, żeby jego własny opis pozostawał prawdziwy, więc nie jest statycznym narzędziem, lecz systemem, który nieustannie doprowadza się do porządku. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Żadna z tych sześciu rzeczy z osobna nie jest nowa. Nowa jest jedna rządzona pętla, która wiąże je razem: od polowania w granicach prawa, przez domknięcie detekcji, aż po dowód pod regulację, i to w całości pod kontrolą klienta.
CYRBER jest przy tym dokładnie tym, co dziś potrafimy uzasadnić kodem, ani mniej, ani więcej, i właśnie dlatego znaczniki DOŁOŻYMY zostawiamy widoczne, zamiast je chować. To jednak nie jest system zamrożony, ponieważ przez FORUM zgłaszasz własny postulat, brak albo potrzebę, a jeśli obroni się technicznie, biznesowo oraz logicznie, trafia do decyzji i go dokładamy. Lista DOŁOŻYMY nie jest więc naszą zamkniętą obietnicą, lecz kierunkiem, który współtworzysz. FORUM z panelem postulatów i decyzji MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
How we differ
The tools you know usually give one layer: a scanner returns a list of vulnerabilities, a BAS platform replays a canned scenario, a pentest ends in a report, and a red-team service is a pair of hired hands. CYRBER binds six things into one governed loop, and it is their combination, not any single one, that makes the difference.
It reasons instead of replaying a script. MENS, the agentic organ of the organism, runs a mission so that on every iteration it walks OBSERVE, THINK, ACT, LEARN and picks its own next move. The operator writes no per-target playbook and instead watches the reasoning and seals the conclusions. A scanner fires a fixed list of plugins; a BAS platform replays a scenario laid out in advance. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
It aims at real access, not a CVE list. A mission works to prove that the chain can be walked, not to print a register of vulnerabilities, and by default it stops at proven access; you turn extraction or exfiltration on through a separate, gated mode. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
It closes detection on the client's SIEM. The result of an attack lands on the client's SIEM via a connector (Wazuh and others), so attack and defense learn from the same event and the detection gap closes. This is purple: red and blue in one loop, not red alone leaving a report. The SIEM connector and standing-purple are SHIPPED, while a ready-made Wazuh stack for on-prem sites without their own SOC is PLANNED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
It leaves a proof, not a promise. Every finding is hashed, closed inside a Merkle tree whose root, for every mission, is committed to the OpenTimestamps calendar (the Bitcoin anchor follows once a block confirms it), so you check the verdict yourself, without access to our database. We replace a report you must trust with a proof you can recompute. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
It belongs to the client. The platform stands at the client's site on-prem, the data and the mission run stay on their infrastructure, and we keep no copy; a full cut-off from the network still needs the local reasoning model. On-prem is SHIPPED; a full air-gap is PLANNED. You can check this yourself in a demonstration, in the public verifier, or on the trust site.
It lives instead of sitting still. The organism repairs its own running state, learns from every mission that closes, and keeps its own account of itself true, so it is not a static tool but a system that keeps setting itself right. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
None of these six on its own is new. What is new is the one governed loop that binds them: from hunting within legal scope, through closing detection, to a proof fit for regulation, and all of it under the client's control.
CYRBER is exactly what we can justify in code today, no more and no less, which is why we leave the PLANNED markers visible instead of hiding them. Yet it is not a frozen system, because through FORUM you raise your own postulate, a gap or a need, and if it holds up technically, in business terms and in logic, it goes to a decision and we build it. The PLANNED list is therefore not a closed promise of ours but a direction you help shape. FORUM, with its postulate and decision panel, is SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Dlaczego organizm
Cerber strzeże granicy między światami i ma trzy głowy, żeby nie mieć martwego pola. Jedna pamięta każdego, kto już przekroczył próg, druga patrzy na tego, kto stoi u bramy teraz, trzecia wypatruje tego, kto dopiero nadchodzi. Nazwa CYRBER bierze się właśnie stąd, ponieważ to nie skaner odpalany na żądanie, lecz strażnik pilnujący trzech czasów naraz.
Motto Videt omnia. Meminit omnia. Iudicat omnia. rozkłada się dokładnie na te trzy czasy: MEMINIT trzyma przeszłość, VIDET teraźniejszość, IUDICAT przyszłość. To warstwa znaczenia, a nie etykiety podzespołów, ponieważ anatomicznie realizują ją trzy głowy rozumowania, czyli RATIO, ANIMUS i FATUM, wsparte pięcioma filarami opisanymi niżej.
Agent czeka na polecenie, wykonuje je i milknie, a kiedy skończy, zapomina. Organizm żyje dalej: nosi pamięć poprzednich starć w korpusie LIBER i w łańcuchu pieczęci, czuwa przez VIGIL, choć nikt mu nie kazał, i osądza przyszłość przez FATUM oraz ANNALES. Dlatego dokumentacja nie opisuje CYRBER jako agenta, bo agent to jeden narząd, a nie cały ustrój.
Precyzyjnie rzecz ujmując, agentem jest silnik rozumowania MENS, który prowadzi misję przez cykl OBSERVE, THINK, ACT, LEARN. Wokół niego stoją narzędzia rozpoznania i ataku, pamięć zapieczętowana kryptograficznie, pętla samosprawdzająca oraz ludzie, bez których żadne uderzenie nie ruszy, ponieważ to operator daje zgodę, a dyrektor bezpieczeństwa akceptuje działanie o realnym skutku. Sztuczna inteligencja jest tu jednym z narządów, nie całą istotą, i tak też ją opisujemy.
Why an organism
Cerberus guards the border between worlds and has three heads so that nothing escapes him. One remembers everyone who already crossed the threshold, the second watches whoever stands at the gate now, the third looks out for whoever is yet to come. The name CYRBER comes from exactly there, because this is no scanner fired on demand, but a guard watching three tenses at once.
The motto Videt omnia. Meminit omnia. Iudicat omnia. maps onto those three tenses precisely: MEMINIT holds the past, VIDET the present, IUDICAT the future. This is a layer of meaning rather than a set of component labels, because anatomically it is carried out by the three heads of reasoning, RATIO, ANIMUS and FATUM, supported by the five pillars described below.
An agent waits for an order, carries it out and falls silent, and once it is done, it forgets. An organism lives on: it carries the memory of earlier encounters in the LIBER corpus and in the chain of seals, it watches through VIGIL although nobody told it to, and it judges the future through FATUM and ANNALES. This is why these docs do not describe CYRBER as an agent, because an agent is one organ and not the whole body.
To be precise, the agent here is the MENS reasoning engine, which runs a mission through the OBSERVE, THINK, ACT, LEARN cycle. Around it stand recon and attack tooling, cryptographically sealed memory, a self-auditing loop, and people without whom no strike moves at all, because the operator grants consent and the security director signs off on anything with real impact. Artificial intelligence is one organ here, not the whole being, and that is how we describe it.
Filozofia
Łacina kompresuje pojęcie w jedno słowo i nie pozwala marketingowi go rozmyć. MENS to umysł, SPECULUM zwierciadło, TESTIMONIUM świadectwo, ANNALES kroniki, UMBRA cień. Trzymamy się tych nazw, a pierwsze użycie tłumaczy ich sens.
Pod tymi nazwami stoi pięć zasad, z których żadna nie jest metaforą doklejoną dla efektu, ponieważ każda pokrywa się z konkretnym miejscem w kodzie.
Rozumowanie biegnie na bieżąco. Silnik MENS, czyli agentowy narząd organizmu, prowadzi misję tak, że na każdej iteracji przechodzi cykl OBSERVE, THINK, ACT, LEARN i sam decyduje o następnym ruchu. Operator nie pisze playbooków pod cel; obserwuje rozumowanie i pieczętuje wnioski. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Organy mają puls, bo potrafią zasnąć. Niezmiennik I-9 jest jednoznaczny: każdy z … unikalnych komponentów, czyli dwunastu organów, pięciu filarów i dwóch głów, musi wysłać puls w ciągu doby, a kto milczy dłużej, ten liczy się już jako martwy. Puls jest przy tym mechanizmem utrzymania, ponieważ powierzchnia rośnie szybciej, niż jedna osoba zdoła ją dogonić, więc organizm sam melduje, co właśnie usnęło. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Filary żywią się nawzajem w łańcuchu. Kiedy misja MENS się domyka, rusza łańcuch hooków: SPECULUM liczy genom, TESTIMONIUM zakłada pieczęć, UMBRA odświeża blueprint środowiska, ANNALES stawia prognozę, CORTEX mierzy trafność, dalej FATUM, COMES, LIBER i ITERUM. Filary tworzą łańcuch pokarmowy: każdy zjada wynik poprzedniego, a po sukcesie bije własny puls. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Sygnał jednego organu uruchamia łuk odruchowy. Capability bus jest układem nerwowym: … zdolności w jednym rejestrze, a szyna organism_feedback przenosi zdarzenia między organami. Kaskady biegną wieloma hopami, ponieważ exploit_available budzi risk_spike, ten z kolei wywołuje drift_detected, a następnie dimension_stale, aż decide_and_act zamyka odruch, a autonomiczny krok pieczętuje liść w TESTIMONIUM, co w sumie daje do sześciu hopów od bodźca aż do dowodu. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Autonomia to pokrętło, nie przełącznik. Operator nie wybiera między trybem ręcznym a w pełni automatycznym, lecz kręci pokrętłem po macierzy klas ryzyka i ustawia, co system robi samodzielnie, co wymaga zgody, a co zostaje zablokowane, a jest to wola świadoma, sprawowana pod prawem LEX oraz pod polityką zapisaną osobno dla każdego celu. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Tych pięć zasad składa się w jedną tezę. Jedna rządzona pętla, od polowania po zapieczętowany werdykt: realna eksploatacja, zamknięcie luki w detekcji na własnym SIEM-ie klienta, kryptograficznie zapieczętowany dowód wspierający raportowanie testów odporności cyfrowej pod DORA, oraz ani jeden bajt nie opuszcza murów klienta. Część tej pętli już bije, część dokładamy DOŁOŻYMY; pełny obraz akt po akcie znajdziesz w rozdziale Rytuał misji. CYRBER każe weryfikować zamiast wierzyć na słowo, więc tę samą miarę stosujemy do dokumentacji: każda zasada wskazuje miejsce w kodzie, a znaczniki MAMY i DOŁOŻYMY oddzielają to, co już bije, od tego, co dopiero powstaje.
Philosophy
Latin compresses a concept into a single word and keeps marketing from watering it down. MENS is the mind, SPECULUM the mirror, TESTIMONIUM the witness, ANNALES the chronicles, UMBRA the shadow. The docs keep these names throughout, and every first use spells out what it means.
Five rules sit under those names, and none of them is a metaphor glued on for effect, because each maps to a specific place in the code.
Reasoning runs as it goes. The MENS engine, the agentic organ of the organism, runs a mission so that on every iteration it walks OBSERVE, THINK, ACT, LEARN and picks its own next move. The operator writes no per-target playbook, but instead watches the reasoning and seals the conclusions. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Organs carry a pulse because they can fall asleep. Invariant I-9 is unambiguous: each of the … unique components, twelve organs, five pillars and two heads, must emit a pulse within a day, and one that stays quiet longer counts as dead. The pulse is a maintenance mechanism: the attack surface grows faster than one person can chase it, so the organism reports on its own what went dark. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
The pillars feed on one another in a chain. When a MENS mission closes, a hook chain fires: SPECULUM scores the genome, TESTIMONIUM sets the seal, UMBRA refreshes the twin, ANNALES casts the forecast, CORTEX measures accuracy, then FATUM, COMES, LIBER and ITERUM. The pillars form a food chain: each consumes the previous result, and each beats its own pulse once it succeeds. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
One organ's signal fires a reflex arc. The capability bus is the nervous system: … capabilities in a single registry, with the organism_feedback bus carrying events between organs. Cascades run many hops deep: exploit_available wakes risk_spike, which trips drift_detected, then dimension_stale, until decide_and_act closes the loop and the autonomous step seals a leaf in TESTIMONIUM, which comes to as many as six hops from stimulus to proof. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Autonomy is a dial, not a switch. The operator does not pick between manual and fully automatic, but turns a dial across a matrix of risk classes, setting what the system does alone, what needs consent and what stays blocked, and that is deliberate will, exercised under the LEX policy engine and under a policy recorded per target. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
The five rules resolve into one thesis: a single governed loop, running from the hunt to a sealed verdict, with real exploitation, the detection gap closed on the client's own SIEM, a cryptographically sealed proof that supports digital-resilience test reporting under DORA, and not one byte leaving the client's walls. Part of that loop already beats; part of it we are still building PLANNED, and the full act-by-act picture waits in the Mission ritual chapter. CYRBER tells you to verify rather than take its word, so we hold these docs to the same standard: every rule points at a place in the code, and the SHIPPED and PLANNED markers separate what already runs from what is still being built.
Anatomia
Anatomy
Organizm ma anatomię, którą policzysz na żywo, ponieważ kafle wyżej biją własnym tętnem, obejmując moduły skanujące, zdolności na szynie oraz grupy zdolności, a te trzy rejestry składają się na całość. Pięć filarów niesie kręgosłup rozumowania, dwanaście organów utrzymuje i osądza, a trzy głowy dzielą atak po domenie, przy czym wszystko spina Capability Bus.
Pięć filarów
Filary tworzą kolumnę kręgową, z której każdy trzyma jeden wymiar misji i ma swoje miejsce w kodzie.
Silnik rozumowania. Prowadzi misję przez cykl OBSERVE, THINK, ACT, LEARN i sam wybiera następny ruch. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Security Genome. Składa profil obrony w pięciu wymiarach i rysuje radar, po jednym pomiarze na misję. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Compliance i dowód. Mapuje wynik na NIS2, DORA i GDPR i podpisuje tę pieczęć zgodności kluczem Ed25519, a każdy skan pieczętuje drzewem Merkle z kotwicą OpenTimestamps w łańcuchu Bitcoina. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Silnik prognozy. Liczy risk score i układa oś czasu na 30, 60 i 90 dni. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Migawka topologii i powierzchni ataku, nie cyfrowy bliźniak. Blueprint środowiska z migawkami ryzyka i sześciogodzinnym cooldownem; testy destrukcyjne biegną w bramkowanym trybie impact, nigdy po produkcji klienta. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Dwanaście organów
Organy utrzymują organizm i pilnują osądu, a każdy z nich robi jedną, ściśle wyznaczoną rzecz.
- VIGIL trzyma ciągły monitoring powierzchni.
- MEDICUS proponuje, weryfikuje i w razie potrzeby wycofuje naprawy, a przy okazji odzyskuje uszkodzone usługi.
- CORTEX rozpoznaje wzorce i uczy się z misji.
- AUDIT prowadzi kryptograficzny łańcuch audytu.
- FORUM prowadzi przepływ postulatów i decyzji.
- LEX egzekwuje zakres i politykę.
- AURUM śledzi koszt tokenów LLM i ekspozycję ryzyka biznesowego w euro.
- TESTIS zaświadcza i weryfikuje każdy krok, żeby dowód dało się sprawdzić także później.
- FATUM przewiduje, jak ryzyko rozłoży się w czasie i kiedy exploit stanie się dostępny.
- COMES towarzyszy misji i porządkuje kolejkę.
- LIBER pamięta jako korpus instytucjonalny.
- ITERUM odtwarza i wariantuje przebyte misje.
Cała dwunastka jest obecna i wpięta, trzymana pod naszym rygorem ALIVE. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Trzy głowy
Głowy dzielą atak według domen, przy czym one same jedynie planują, natomiast nad wykonaniem czuwa już MENS.
Wektor techniczny. Dysponuje ponad setką modułów skanujących i mapuje wynik na CWE oraz OWASP. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Wektor ofensywny. Realnie wpięty jest garak, fuzzer bezpieczeństwa modeli LLM, którego dispatch woła trzema ścieżkami, wsparty nocnym baseline. Wpięte są też narzędzia Sliver C2 (deploy_beacon oraz harvest), dispatchowalne wyłącznie pod bramą trybu impact. evilginx2 i pineapple to wrappery odczytu z zewnętrznie postawionej infrastruktury, nie autonomiczne narzędzia. Nad całością stoi niezmiennik requires_consent=True, więc nic nie ruszy bez zadeklarowanej zgody. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Ten sam moduł co organ FATUM, druga perspektywa. Organ przewiduje punktowo, głowa patrzy na czas jako aspekt rozumowania. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Szyna zdolności
Bus jest fundamentem, a nie kolejnym organem ani filarem, ponieważ stanowi jeden płaski rejestr zdolności, po którym rozmawiają ze sobą filary, organy i głowy. Każda zdolność niesie scope (owner, admin, operator, client), wpis w audit logu, opcjonalną zgodę przez HMAC lub bramkę MFA i udokumentowany pendant defensywny, czyli odpowiednik mówiący, jak SPECULUM albo UMBRA to samo wykrywa lub odzwierciedla. Liczbę zdolności, modułów i grup zobaczysz w kaflach wyżej, liczone na żywo. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Kiedy komponent jest żywy
Nasz rygor ALIVE stawia trzy warunki naraz, a samo istnienie pliku nie liczy się do niczego. Po pierwsze producent wywołań w produkcji: realny dispatch albo hook woła kod, a nie tylko import. Po drugie test e2e, który ćwiczy prawdziwą ścieżkę i świeci na zielono w suite. Po trzecie udokumentowany pendant defensywny. Gdy zabraknie choćby jednego, piszemy stan wprost: wired-untested, dormant, unwired, skeleton. To właśnie ten rygor utrzymuje organizm w uczciwości, ponieważ żywotność liczy się co dobę, a milczenie dłuższe niż jedna doba znaczy śmierć. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
The organism has an anatomy you can count live, because the tiles above beat with their own pulse across scan modules, capabilities on the bus and capability groups, and those three registers make up the whole. Five pillars carry the spine of reasoning, twelve organs keep it running and judging, and three heads split the attack by domain, with the Capability Bus wiring them together.
Five pillars
The pillars are the backbone. Each holds one dimension of a mission and has its own place in the code.
The reasoning engine. It runs a mission through OBSERVE, THINK, ACT, LEARN and picks its own next move. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
The Security Genome. It builds a defense profile across five dimensions and draws a radar, one reading per mission. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Compliance and proof. It maps findings onto NIS2, DORA and GDPR and signs that compliance seal with an Ed25519 key, while it seals every scan with a Merkle tree and an OpenTimestamps anchor on the Bitcoin chain. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
The forecast engine. It scores risk and lays out a timeline over 30, 60 and 90 days. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
A snapshot of topology and attack surface, not a digital twin. A blueprint of the environment with risk snapshots and a six-hour cooldown; destructive tests run in a gated impact mode, never against the client's production. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Twelve organs
The organs keep the body running and guard its judgment, and each of them does one strictly assigned thing.
- VIGIL watches the surface without pause.
- MEDICUS proposes, verifies and, when needed, rolls back fixes, and recovers broken services along the way.
- CORTEX recognizes patterns and learns from missions.
- AUDIT keeps the cryptographic audit chain.
- FORUM runs the postulate and decision flow.
- LEX enforces scope and policy.
- AURUM tracks LLM token cost and business-risk exposure in EUR.
- TESTIS witnesses and verifies each step, so the proof can be checked later too.
- FATUM predicts how risk unfolds over time and when an exploit becomes available.
- COMES rides with the mission and orders its queue.
- LIBER remembers as an institutional corpus.
- ITERUM replays and varies past missions.
All twelve are present and wired, held to our ALIVE bar. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Three heads
The heads split the attack by domain. They plan; MENS owns the execution.
The technical vector. It dispatches over a hundred scan modules and maps findings onto CWE and OWASP. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
The offensive vector. The wired tool is garak, an LLM security fuzzer whose dispatch fires through three paths, backed by a nightly baseline. The Sliver C2 tools (deploy_beacon and harvest) are also wired, dispatchable only behind the impact-mode gate. evilginx2 and pineapple are read wrappers over externally stood-up infrastructure, not autonomous tools. The requires_consent=True invariant governs all of it, so nothing fires without declared consent. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
The same module as the FATUM organ, seen from a second angle. The organ predicts point by point; the head treats time as an aspect of reasoning. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
The Capability Bus
The bus is the foundation, not another organ or pillar. It is a single flat registry of capabilities that pillars, organs and heads all speak through. Every capability carries a scope (owner, admin, operator, client), an audit-log entry, optional consent via HMAC or an MFA gate, and a documented defensive pendant, the counterpart that says how SPECULUM or UMBRA detects or reflects the same thing. The count of capabilities, modules and groups sits in the tiles above, computed live. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
When a component is alive
Our ALIVE bar sets three conditions at once, and a file simply existing counts for nothing. First, a caller in production: a real dispatch or hook invokes the code, not just an import. Second, an e2e test that exercises the real path and stays green in the suite. Third, a documented defensive pendant. Miss any one and we name the state plainly: wired-untested, dormant, unwired, skeleton. This rigor keeps the organism honest. Liveness is counted every day, and silence longer than a day reads as death. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Rytuał misji
Cała praca organizmu układa się w jeden rytuał pięciu aktów. To rdzeń całego CYRBER: jedna rządzona pętla od polowania po zapieczętowany werdykt. Część aktów już bije pełnym tętnem, część dopiero dokładamy, co oznaczamy wprost, akt po akcie.
1 · Puls
Akt czuwania. VIGIL trzyma baseline powierzchni, niezmiennik I-9 liczy żywotność … komponentów, a standing-scan regimen wybija stały rytm. Zanim zacznie się polowanie, organizm już wie, co ma pod ręką i co usnęło. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
2 · Polowanie
Akt rozumowania. MENS iteruje pętlę i dysponuje modułami skanującymi głowy RATIO pod prawem LEX, celując w realny dostęp, nie w samą listę podatności. Flotą celów rządzi pokrętło autonomii, a każdy cel niesie własny postulat zakresu. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Na ekranie Playbooks (/playbooks) leżą gotowe łańcuchy ataku, między innymi Active Directory, aplikacja webowa, chmura i ransomware. Operator uruchamia taki scenariusz, gdy droga jest już ustalona, a swobodne rozumowanie misji zostaje przy MENS. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
3 · Pojedynek
Akt konfrontacji. CYRBER uruchamia realną eksploatację modułami ofensywnymi (loot z głowy RATIO oraz Sliver z głowy ANIMUS), a wynik trafia na własny SIEM klienta, obsługiwany konektorem (Wazuh i inne), z opcjonalnym stackiem Wazuh dla on-prem bez SOC, żeby domknąć luki detekcji. To purple w czystej postaci: atak i obrona uczą się na tym samym zdarzeniu. Domyślnie dowodzimy dostępu, nie skutku, ponieważ sama eksploatacja pokazuje, że łańcuch da się przejść, a ekstrakcję danych włącza dopiero osobny tryb impact, który przechodzi przez pięć bramek naraz, od licencji i polityki LEX po autoryzację klienta oraz zgodę na każdy krok. Konektor SIEM (Wazuh i inne), metryka standing-purple z siedmiu dni oraz domyślny dowód dostępu z bramkowanym trybem impact MAMY. Gotowy stack Wazuh dla on-prem bez SOC oraz dwupanelowy widok purple spięty w jeden rytuał DOŁOŻYMY. Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
4 · Werdykt
Akt świadectwa. TESTIMONIUM pieczętuje dowód drzewem Merkle oraz kotwicą OpenTimestamps w łańcuchu Bitcoina, a werdykt zmapowany na zgodność, podpisany kluczem Ed25519, ląduje w zapieczętowanym PDF. Paczka dowodowa układa pieczęcie i dowód dostępu jako materiał na zamknięcie testów odporności wymaganych przez DORA. Test prowadzi uprawniony niezależny zespół, a my dostarczamy dowód, który sprawdzisz offline. Ponowny test po poprawce, który sam zamyka zgłoszenie, jest w planie. Łańcuch pieczęci i PDF zgodności MAMY. Paczka dowodowa z publicznym weryfikatorem w pliku ZIP MAMY, a zamknięcie zgłoszenia po ponownym teście to DOŁOŻYMY. Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
5 · Pamięć
Akt uczenia. Po misji łańcuch hooków karmi organizm: LIBER indeksuje do korpusu instytucjonalnego, CORTEX mierzy trafność, ANNALES odświeża prognozę, ITERUM przygotowuje replay. Organizm pamięta misję i wraca do niej mądrzejszy. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Tych pięć aktów tworzy jedną pętlę, którą sterujesz pokrętłem, którą udowodnisz regulatorowi i która w całości należy do klienta. Suwerenność, czyli on-prem i lokalny model LLM, czyni ją niekopiowalną: nikt z zewnątrz nie odtworzy ani danych, ani przebiegu. Jak działa dowód dla sceptyka, opisuje rozdział Glass House; skąd bierze się nienaruszalność, rozdział Suwerenność. Aspiracje z aktów Pojedynek i Werdykt oznaczamy DOŁOŻYMY, żeby było jasne, co należy do planu, a co już bije.
Mission ritual
Everything the organism does resolves into one ritual of five acts. This is the core of CYRBER: a single governed loop from the hunt to a sealed verdict. Some acts already beat at full pulse; some we are still building, and we say which is which, act by act.
1 · Pulse
The act of watching. VIGIL holds a baseline of the surface, invariant I-9 counts the liveness of … components, and the standing-scan regimen keeps a steady beat. Before the hunt begins, the organism already knows what it has to hand and what has gone quiet. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
2 · Hunt
The act of reasoning. MENS iterates its loop and dispatches the RATIO head's scan modules under the LEX policy engine, aiming at real access rather than a bare list of vulnerabilities. The autonomy dial governs the fleet of targets, and each target carries its own scope postulate. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
The Playbooks screen (/playbooks) holds ready attack chains, including Active Directory, a web application, cloud and ransomware. The operator launches that scenario when the path is already known, and free mission reasoning stays with MENS. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
3 · Duel
The act of confrontation. CYRBER runs real exploitation through its offensive modules (loot from the RATIO head and Sliver from the ANIMUS head), and the result lands on the client's own SIEM via a connector (Wazuh and others), with an optional Wazuh stack for on-prem without a SOC, to close the detection gap. This is purple in its pure form: attack and defense learn from the same event. By default we prove access, not impact, because the exploitation itself shows the chain can be walked, while data extraction turns on only through a separate impact mode that passes five gates at once, from the license and the LEX policy to the client's authorisation and consent on every step. The SIEM connector (Wazuh and others), the seven-day standing-purple metric and the default proof-of-access with a gated impact mode are SHIPPED. A ready-made Wazuh stack for on-prem without a SOC and a two-panel purple view fused into one ritual are PLANNED. You can check this yourself in a demonstration, in the public verifier, or on the trust site.
4 · Verdict
The act of witness. TESTIMONIUM seals the proof with a Merkle tree and an OpenTimestamps anchor on the Bitcoin chain, and the compliance-mapped verdict, signed with an Ed25519 key, lands in a sealed PDF. An evidence pack lays out the seals and the proof of access as material for the close of the resilience tests DORA requires. An authorised independent team runs the test and we supply the proof, which you can check offline. A retest after the fix, which closes the ticket on its own, is planned. The seal chain and compliance PDF are SHIPPED. An evidence pack with the public verifier inside the ZIP export is SHIPPED, while closing the ticket after a retest is PLANNED. You can check this yourself in a demonstration, in the public verifier, or on the trust site.
5 · Memory
The act of learning. Once a mission closes, the hook chain feeds the organism: LIBER indexes into the institutional corpus, CORTEX measures accuracy, ANNALES refreshes the forecast, ITERUM prepares a replay. The organism remembers the mission and comes back to it wiser. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
These five acts are one loop. You steer it with a dial, you can prove it to a regulator, and it belongs to the client in full. Sovereignty, meaning on-prem plus a local LLM, makes it uncopyable: no outsider can reconstruct the data or the run. The Glass House chapter shows how the proof works for a skeptic, and the Sovereignty chapter shows where the tamper-resistance comes from. We mark the aspirations in the Duel and Verdict acts as PLANNED, so it stays clear which parts belong to the plan and which already run.
Samoleczenie
Samodoskonalenie w CYRBER dzieje się na trzech poziomach naraz: organizm naprawia własny stan działania, wyciąga wnioski z każdej zamkniętej misji oraz pilnuje, żeby jego własny opis samego siebie pozostawał prawdziwy. Nie kończy więc pracy na samym wykryciu usterki, lecz zauważa ją, naprawia, zapamiętuje płynący z niej wniosek, a tę samą pętlę domyka na dokumentacji, którą właśnie czytasz.
Jak się naprawia
Sam proponuje naprawę na znalezisko i klasyfikuje ją: gotowa receptura, poprawka kodu albo plan czekający na zgodę. Wykonanie przechodzi przez politykę LEX oraz klucz z sejfu, a po udanej komendzie MEDICUS zleca retest i nie ponawia spalonej receptury. Osobno pilnuje pulsu usług i prowadzi recovery, gdy komponent pada, zanim ktokolwiek zdąży złożyć zgłoszenie. Propozycję, klasyfikację, bramkowane wykonanie, zlecony retest oraz recovery usług MAMY. Retest, który dowodzi, że dziura naprawdę zniknęła, i domknięcie tej pętli bez ręki człowieka DOŁOŻYMY. Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Pod spodem bije odruch. Sygnały organizmu są drenowane co sześćdziesiąt sekund, a handlery reagują same: wygaszają pewność, kasują nieaktualny baseline, wołają decide_and_act. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Kiedy moduł wraca do zdrowia, self-test sam zamyka powiązane z nim zgłoszenie GH. Naprawa i jej ślad domykają się bez ręki człowieka. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Jak się uczy
Rozpoznaje wzorce w tym, co organizm już widział, i mierzy trafność własnych prognoz. Każda pomyłka wraca do niego jako korekta. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Zbiera wnioski z zamkniętych misji i domyka pętlę uczenia, żeby następny przebieg startował mądrzejszy. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Jak leczy się ta dokumentacja
Ta strona podlega tej samej zasadzie. Liczby i statusy, które tu widzisz, nie są przepisane ręcznie, lecz renderują się z żywego API organizmu, dzięki czemu nie zestarzeją się po cichu. Nad samą prozą czuwa strażnik dryfu, ponieważ każde twierdzenie, oznaczone jako MAMY albo DOŁOŻYMY, trzyma kotwicę w konkretnym miejscu kodu, którą sprawdzasz przyciskiem „udowodnij”, a nocny przebieg weryfikuje, czy kod wciąż to twierdzenie potwierdza, i robi to na trzech warstwach: czy pliki, symbole oraz endpointy z kotwicy nadal istnieją, czy liczby zgadzają się z API, a wreszcie czy sam sens twierdzenia trzyma się kodu. Gdy organizm wyprzedzi opis, strażnik sam zakłada zgłoszenie GH z konkretem, tym samym trybem, którym self-test już dziś zamyka zgłoszenia po naprawie, i sam je domyka, gdy proza wróci do prawdy. To Glass House przyłożony do dokumentu: nie każemy Ci wierzyć, że opis pozostaje aktualny, lecz utrzymujemy mechanizm, który tę aktualność wymusza. Żywe fakty z API oraz strażnika dryfu prozy MAMY. Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Te trzy poziomy, naprawa stanu, nauka z misji oraz uczciwość własnego opisu, składają się na jedną ideę: system, który nie tylko działa, lecz sam doprowadza się do porządku, a każdy taki krok zostawia ślad, który możesz sprawdzić.
Self-healing
Self-improvement in CYRBER runs on three levels at once: the organism repairs its own running state, draws lessons from every mission that closes, and keeps its own account of itself true. It therefore does not stop at spotting a fault, but notices it, repairs it and keeps the lesson, and then the same loop closes on the documentation you are reading now.
How it repairs itself
Proposes a fix for a finding and classifies it: a ready recipe, a code patch, or a plan awaiting consent. Execution passes the LEX policy and a key from the vault, and once a command succeeds MEDICUS orders a retest and never reruns a burned recipe. Separately it watches the pulse of the services and drives recovery when a component falls over, before anyone files a ticket. The proposal, the classification, the gated execution, the ordered retest and the service recovery are SHIPPED. A retest that proves the hole actually cleared, and closing that loop with no human hand, are PLANNED. You can check this yourself in a demonstration, in the public verifier, or on the trust site.
A reflex beats underneath. Organism signals drain every sixty seconds, and the handlers react on their own: they decay confidence, wipe a stale baseline, call decide_and_act. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
When a module returns to health, the self-test closes the GH issue tied to it. The repair and its trace both close with no human hand. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
How it learns
Recognises patterns in what the organism has already seen and measures the accuracy of its own forecasts. Every miss comes back to it as a correction. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Gathers the lessons from closed missions and closes the learning loop, so the next run starts wiser. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
How this documentation heals
This page lives by the same rule. The numbers and statuses you see here are not typed in by hand. They render from the organism's live API, so they cannot age in silence. A drift guard watches the prose itself, because every claim, marked SHIPPED or PLANNED, holds an anchor at a specific place in the code that you check with the "prove it" button, and a nightly run verifies that the code still bears the claim out, across three layers: whether the files, symbols and endpoints from the anchor still exist, whether the numbers match the API, and finally whether the meaning of the claim still holds against the code. When the organism runs ahead of the description, the guard opens a GH issue with the specifics, by the same route the self-test already uses to close issues after a repair, and closes it again once the prose returns to the truth. This is the Glass House turned on a document: we do not ask you to trust that the description is current; we run a mechanism that forces it to be. Live facts from the API and the prose drift guard are SHIPPED. You can check this yourself in a demonstration, in the public verifier, or on the trust site.
These three levels, repairing the state, learning from missions and keeping its own account honest, make one idea: a system that does not merely run but keeps setting itself right, and every such step leaves a trace you can check.
Glass House
Każdy dostawca prosi o zaufanie, natomiast CYRBER kładzie na stół dowód, który sprawdzisz samodzielnie, bez najmniejszego wglądu w jego bazę.
Pieczęć
Każde znalezisko trafia pod hash SHA-256, po czym hashe łączą się parami w drzewo Merkle, a ponieważ zmiana choćby jednego znaku w jednym znalezisku rozsypuje root tego drzewa, każda podmiana zostaje natychmiast widoczna. Każdy liść nosi przy tym podpis HMAC naszego serwera, a wiarygodność samego roota bierze się z kotwicy opisanej niżej, nie z naszego słowa. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Kotwica
Korzeń drzewa znalezisk każdej misji oraz hash dziennego snapshotu kotwiczymy w bloku łańcucha Bitcoina przez OpenTimestamps. Żeby przepisać historię, trzeba by przepisać bloki, a tego nikt nie zrobi po cichu. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Weryfikacja bez zaufania
Audytor bierze znalezisko, przelicza jego hash i przechodzi ścieżkę Merkle aż do roota, co kosztuje go O(log N) kroków, a nie kopię całej bazy, natomiast klucz weryfikujący dostaje offline w nagłówku X-Proof-Key, dzięki czemu dowód broni się nawet wtedy, gdy nasz serwer pozostaje niedostępny. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Łańcuch pieczęci
Łańcuch pieczęci trzyma pieczęcie kolejnych misji, jedna za drugą. Liczba pieczęci rośnie z każdą zamkniętą misją: …. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Paczka dowodowa
Paczka dowodowa składa w jeden plik pieczęcie, zamknięte reguły wykrywania i dowód dostępu. Służy jako materiał na zamknięcie testów odporności wymaganych przez DORA. Test prowadzi uprawniony zespół, a my dostarczamy dowód. Publiczny weryfikator jedzie w pliku ZIP i sprawdza dowód offline, bez naszej bazy. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Stąd bierze się zasada, którą trzymamy tu i w produkcie: masz sprawdzić werdykt, a nie zawierzyć mu. To decyzja architektoniczna, która przesądziła, jak wygląda każda pieczęć. Skąd bierze się nienaruszalność u klienta, mówi rozdział Suwerenność.
Glass House
Every vendor asks for trust. CYRBER puts a proof on the table that you can check without looking into its database.
The seal
Every finding goes under a SHA-256 hash. The hashes join in pairs into a Merkle tree. Change one character in one finding and the tree's root falls apart, so tampering stays visible. Each leaf carries an HMAC signature from our server, and the root's credibility comes from the anchor described below, not from our word. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
The anchor
We anchor each mission's Merkle root and the hash of the daily snapshot into a Bitcoin block through OpenTimestamps. To rewrite history, you would have to rewrite the blocks, and nobody does that quietly. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Verification without trust
An auditor takes a finding, recomputes its hash and walks the Merkle path to the root. It costs them O(log N) steps, not a copy of the database. The verifying key arrives offline in the X-Proof-Key header, so the proof holds even when our server is unreachable. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
The seal chain
The seal chain holds the seals of successive missions, one after another. The count grows with every mission that closes: …. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
The evidence pack
The evidence pack puts the seals, the closed detection rules and the proof of access into one file. It is material for the close of the resilience tests DORA requires. An authorised team runs the test and we supply the proof. The public verifier travels in the ZIP file and checks the proof offline, without our database. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
This is where the rule we keep here and in the product comes from: verify the verdict, do not trust it. It is an architectural decision that shaped every seal, not a marketing line. Where the tamper-resistance comes from at the client's site is the Sovereignty chapter.
Ludzie
Napastnik rzadko zaczyna od portu, częściej od wiadomości, więc zespół jest powierzchnią ataku dokładnie tak samo jak serwer, tyle że nikt go nie skanuje nmapem. CYRBER traktuje ten obszar jedną pętlą: mierzy odsłonięcie konkretnych odbiorców, kieruje szkolenie najpierw do najbardziej narażonych, a wynik zamyka rekordem zgodności, który da się przedłożyć audytorowi.
Kampanie i phishing
Silnik kampanii planuje działanie w czasie, prowadzi je etapami i sam przechodzi do kolejnej fazy, gdy warunek zostanie spełniony, dzięki czemu ćwiczenie rozkłada się na tygodnie, a nie na jeden pamiętny poniedziałek. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Wiadomość powstaje pod konkretną rolę i kontekst odbiorcy, a wysyłka idzie przez GoPhish, więc widzisz nie tylko, kto kliknął, lecz jak daleko doszedł, od otwarcia po podanie danych. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
SUASOR, czyli miara odsłonięcia
SUASOR zamienia przebieg kampanii w liczbę na osobę. Punktacja odsłonięcia bierze najdalszy osiągnięty etap, impulsywność kliknięcia oraz bierną obecność w otwartych źródłach, a wynik rośnie wraz z narażeniem, więc czyta się go tak samo jak poziom ryzyka. Sam mechanizm jest deterministyczny i pozbawiony wejścia z sieci, dzięki czemu ten sam materiał zawsze daje ten sam wynik, co ma znaczenie, gdy rozmawiasz o ludziach, a nie o hostach. Każde działanie wobec pracownika wymaga zgody organizacji, a propozycje czekają na zatwierdzenie, zanim cokolwiek wyjdzie na zewnątrz. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
LUDUS, czyli szkolenie zakończone dowodem
Pracownik dostaje link, który działa bez logowania i bez zakładania konta, ponieważ próg wejścia decyduje o tym, czy ćwiczenie w ogóle się odbędzie. Po drugiej stronie czeka krótki dryl osadzony w realiach jego roli, a nie kurs ogólny dla wszystkich. Wynik liczy się deterministycznie, więc ocena nie zależy od humoru modelu językowego, a na końcu powstaje imienny certyfikat z identyfikatorem, który każdy może sprawdzić bez dostępu do danych osobowych. Ty dostajesz rekord zgodności gotowy do przedłożenia, ponieważ obowiązek szkolenia z NIS2 oraz z rozporządzenia DORA spełnia się dowodem, a nie deklaracją. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Te cztery elementy nie są osobnymi narzędziami, lecz jedną pętlą: kampania wskazuje osoby najbardziej odsłonięte, szkolenie trafia najpierw do nich, kolejny pomiar pokazuje, czy coś się zmieniło, a całość zostawia ślad, który obroni się przed audytorem.
People
An attacker rarely starts at a port and usually starts at a message, so your team is an attack surface exactly as a server is, except nobody scans it with nmap. CYRBER treats this ground as one loop: it measures the exposure of specific recipients, sends training to the most exposed first, and closes the result with a compliance record you can put in front of an auditor.
Campaigns and phishing
The campaign engine plans the work over time, runs it in stages and advances to the next phase on its own once a condition is met, so an exercise spreads across weeks rather than one memorable Monday. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
The message is written for a specific role and context, and delivery goes through GoPhish, so you see not only who clicked but how far they went, from opening the mail to handing over credentials. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
SUASOR, the measure of exposure
SUASOR turns a campaign run into a number per person. The footprint score takes the furthest stage reached, the impulsivity of the click and passive presence in open sources, and it rises with exposure, so it reads the same way a risk level does. The mechanism itself is deterministic and performs no network I/O, so the same material always yields the same score, which matters when the subject is a person rather than a host. Every action aimed at an employee needs the organisation's consent, and proposals wait for approval before anything leaves the building. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
LUDUS, training that ends in proof
The employee gets a link that works without a login and without creating an account, because the entry barrier decides whether the exercise happens at all. On the other side waits a short drill set in the reality of their role, not a general course for everyone. Scoring is deterministic, so the mark does not depend on a language model's mood, and at the end there is a named certificate with an identifier anyone can check without access to personal data. You get a compliance record ready to submit, because the training duty under NIS2 and under the DORA regulation is met with proof rather than a declaration. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
These four parts are not separate tools but one loop: the campaign points at the most exposed people, training reaches them first, the next measurement shows whether anything changed, and the whole thing leaves a trace that holds up in front of an auditor.
Sondy brzegowe
Część sieci nie jest widoczna z miejsca, w którym stoi platforma, ponieważ siedzi za NAT, w odległym oddziale albo w segmencie odciętym od reszty świata celowo. Sonda rozwiązuje to bez otwierania dziury w zaporze: mały appliance w kontenerze albo na komputerze jednopłytkowym sam melduje się do platformy, pobiera zadanie, wykonuje je lokalnie i odsyła wynik.
Platforma prowadzi rejestr sond, wydaje im zadania i pokazuje historię każdego zlecenia wraz z podsumowaniem, dzięki czemu operator widzi, co sonda robiła i kiedy ostatnio dała znak życia. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Sonda nie jest obejściem polityki. Zadanie przechodzi tę samą bramę zakresu co misja prowadzona z centrali, więc cel spoza zakresu zostaje odrzucony niezależnie od tego, kto go zlecił i skąd. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Sondy zmieniają zasięg, nie zasady. Wynik z odległego oddziału wchodzi do tego samego łańcucha dowodowego co skan wykonany lokalnie, a Ty nie musisz w zamian wystawiać żadnego portu na świat.
Edge probes
Part of a network is invisible from wherever the platform stands, because it sits behind NAT, in a distant branch, or in a segment deliberately cut off from the rest of the world. A probe solves that without opening a hole in the firewall: a small appliance in a container or on a single-board computer checks in to the platform on its own, pulls a job, runs it locally and sends the result back.
The platform keeps a registry of probes, hands them jobs and shows the history of every assignment together with a summary, so the operator can see what a probe did and when it last showed a sign of life. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
A probe is not a way around policy. Its job passes the same scope gate as a mission run from headquarters, so a target outside scope is refused no matter who ordered it or from where. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Probes change the reach, not the rules. A result from a distant branch enters the same evidence chain as a scan run locally, and you do not have to expose a single port to the world in return.
Obowiązki regulacyjne
Regulacje nie pytają, czy używasz dobrego narzędzia, lecz czy potrafisz pokazać, co i kiedy zrobiłeś. Poniższe powierzchnie istnieją właśnie po to, aby odpowiedź na takie pytanie dało się wydrukować, zamiast opowiadać ją na spotkaniu.
Zbiera wymagania rozporządzenia, ocenia stan wobec nich i wystawia dokument, który idzie do organu albo do klienta. Dzięki temu przygotowanie do rozmowy nadzorczej przestaje być projektem na kwartał. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Modele językowe weszły w procesy szybciej niż procedury ich kontroli, więc CYRBER bada je własnym zestawem testów i wiąże wynik z artykułami aktu, z punktami NIST AI RMF oraz z pozycjami OWASP dla modeli językowych. Dostawca modelu ma swoje obowiązki, Ty jako wdrażający masz osobne i to właśnie one są tu przedmiotem dowodu. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Rejestr czynności przetwarzania prowadzi się i tak, więc lepiej, żeby powstawał obok dowodów technicznych niż w osobnym arkuszu, o którym wszyscy zapominają między audytami. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Zgody nie są formalnością dopinaną po fakcie, lecz warunkiem, bez którego część działań w ogóle nie ruszy, a ich rejestr eksportujesz razem z resztą dowodów. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Walidacja u siebie
Osobną sprawą jest pytanie, czy Twoje własne systemy bezpieczeństwa w ogóle zobaczyły to, co robiliśmy. Integracja z Energy Logserver pozwala sprawdzić, czy zdarzenie wygenerowane przez misję dotarło do Twojego magazynu logów, ponieważ test detekcji ma sens tylko wtedy, gdy potwierdzisz go po swojej stronie, a nie po naszej. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Regulatory duties
Regulations do not ask whether you use a good tool; they ask whether you can show what you did and when. The surfaces below exist so that the answer to such a question can be printed rather than told at a meeting.
Gathers the regulation's requirements, assesses your state against them and issues a document that goes to the authority or to a client. Preparing for a supervisory conversation stops being a quarter-long project. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Language models entered business processes faster than the procedures to control them, so CYRBER tests them with its own battery and ties each result to articles of the act, to NIST AI RMF points and to OWASP entries for language models. The model provider carries its own duties; as the deployer you carry separate ones, and those are what this evidence is about. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
You keep a record of processing activities anyway, so it is better built next to the technical evidence than in a separate spreadsheet everyone forgets between audits. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Consents are not a formality bolted on afterwards but a condition without which some actions will not start at all, and their register exports alongside the rest of the evidence. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Validation on your side
A separate question is whether your own security systems saw any of what we did. The Energy Logserver integration lets you check that an event generated by a mission reached your log store, because a detection test only means something once you confirm it on your side rather than on ours. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Rozpoznanie
Zanim napastnik wybierze narzędzie, zbiera wiedzę, a robi to wyłącznie ze źródeł, do których nie musi się włamywać. CYRBER przechodzi tę samą drogę, żeby pokazać Ci własną organizację oczami kogoś z zewnątrz, wraz z tym, co z tej wiedzy wynika.
Domeny, subdomeny, usługi wystawione przypadkiem, adresy pocztowe krążące po sieci. Obraz powstaje ze źródeł otwartych i pokazuje punkt startowy przeciwnika, a nie stan wymarzony z dokumentacji sieci. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Układa zebrane ślady w portret konkretnej organizacji, ponieważ luźna lista faktów nie mówi jeszcze nic, dopóki nie widać, które z nich prowadzą do siebie nawzajem. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Co tydzień sprawdza w Have I Been Pwned, czy konta z domeny organizacji pojawiły się w wyciekach, zostawia historię wyników i otwiera znalezisko przy nowym wycieku. Wymaga klucza HIBP, domeny zweryfikowanej na koncie tego klucza oraz włączenia monitoringu dla organizacji. Hasło pracownika krążące po sieci jest gotowym wejściem, więc lepiej dowiedzieć się o nim przed incydentem. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania. Ekran Dark Web (/darkweb) sprawdza na żądanie, czy w Have I Been Pwned jest wyciek samego serwisu o tej domenie; to także wymaga klucza HIBP. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania. Sprawdzenie kont pracowników na żądanie i kolejne źródła wycieków, poza Have I Been Pwned. DOŁOŻYMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Od wiedzy do drogi ataku
Rozpoznanie samo w sobie jest tylko materiałem. Wartość pojawia się, gdy z pojedynczych ustaleń złoży się przejście: otwarta usługa prowadzi do konta, konto do uprawnienia, uprawnienie do danych. Widok ścieżki ataku pokazuje to przejście jako łańcuch, a topologia rysuje sieć tak, jak widzi ją silnik misji, dzięki czemu rozmowa przestaje dotyczyć listy podatności, a zaczyna dotyczyć drogi, którą ktoś realnie przejdzie. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Reconnaissance
Before an attacker picks a tool they gather knowledge, and they do it purely from sources they never have to break into. CYRBER walks the same road to show you your own organisation through an outsider's eyes, along with what follows from that knowledge.
Domains, subdomains, services exposed by accident, mail addresses drifting around the net. The picture comes from open sources and shows an adversary's starting point rather than the ideal state in your network documentation. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Arranges the collected traces into a portrait of one organisation, because a loose list of facts says nothing until you can see which of them lead to one another. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Each week it checks Have I Been Pwned for accounts from the organisation's domain that appear in breaches, keeps a history of results and opens a finding when a new leak shows up. It requires an HIBP key, a domain verified on that key's account, and monitoring enabled for the organisation. An employee's password circulating online is a ready-made way in, so it is better to learn about it before an incident. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site. The Dark Web screen (/darkweb) checks on demand whether Have I Been Pwned lists a breach of the service at that domain itself; this also requires an HIBP key. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site. An on-demand check of employee accounts and further leak sources beyond Have I Been Pwned. PLANNED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
From knowledge to a path of attack
Reconnaissance on its own is only material. The value appears when single findings compose into a passage: an exposed service leads to an account, the account to a privilege, the privilege to data. The attack path view shows that passage as a chain, and the topology draws the network as the mission engine sees it, so the conversation stops being about a list of vulnerabilities and starts being about the road someone would actually walk. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Widoki i stan
Te same ustalenia wyglądają inaczej z fotela operatora, inaczej z fotela zarządu, a jeszcze inaczej z perspektywy kogoś, kto pyta o zdrowie samej platformy. Zamiast zmuszać wszystkich do jednego ekranu, CYRBER podaje ten sam materiał w kilku ujęciach.
Bieżący obraz pracy: co się dzieje, co czeka na decyzję, co wymaga ręki człowieka. Widok dla kogoś, kto prowadzi dzień. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Ujęcie dla zarządu, gdzie liczy się kierunek i ryzyko, a nie identyfikator znaleziska. Prognoza i stan zgodności zamiast surowego zrzutu z narzędzia. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Zwięzła karta podmiotu: profil, wymiary bezpieczeństwa, historia. Dobra na wejście w rozmowę z kimś, kto widzi Twoją organizację pierwszy raz. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Podgląd przebiegu misji krok po kroku, przydatny wtedy, gdy chcesz zobaczyć rozumowanie, a nie tylko wynik. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Zdrowie platformy i jej łańcucha dostaw
Osobno stoi pytanie o kondycję samego narzędzia, bo system, który bada bezpieczeństwo, sam bywa celem. Widok zdrowia zbiera podatności zależności, ważność certyfikatów, spójność łańcucha audytowego, stan kopii zapasowych i wynik samoskanowania, natomiast rejestr składników oprogramowania (SBOM w formacie CycloneDX, ekran /sbom dla administratora) mówi, z czego platforma jest zbudowana, i daje się pobrać jako plik dla Twojego zespołu bezpieczeństwa. Nexus dokłada obraz węzłów i strumień zdarzeń, przydatny przy większych wdrożeniach. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Ćwiczenia przeciwstawne
Do tego dochodzą ujęcia ofensywne, po które sięga się świadomie i pod nadzorem: symulacja przeciwnika obejmująca scenariusz ransomware, starcie modelu z modelem oraz atak przez łańcuch dostaw, a obok osobny warsztat czerwonego zespołu wymierzony w modele językowe, czyli ai-redteam, gdzie model dostaje serię prób obejścia zabezpieczeń i widać, które z nich przechodzą. To narzędzia dla kogoś, kto chce sprawdzić reakcję, a nie tylko listę. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Views and state
The same findings look one way from an operator's chair, another from the board's, and different again to someone asking about the health of the platform itself. Rather than forcing everyone onto one screen, CYRBER serves the same material in several framings.
The running picture: what is happening, what waits for a decision, what needs a human hand. A view for whoever runs the day. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
A framing for the board, where direction and risk matter rather than a finding identifier. Forecast and compliance state instead of a raw tool dump. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
A compact card for the entity: profile, security dimensions, history. Good for opening a conversation with someone seeing your organisation for the first time. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
A step-by-step view of a mission as it runs, useful when you want to see the reasoning rather than only the result. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Health of the platform and its supply chain
The condition of the tool itself stands apart, because a system that examines security is a target too. The health view gathers dependency vulnerabilities, certificate expiry, audit chain integrity, backup state and self-scan results, while the software bill of materials (an SBOM in CycloneDX format, the /sbom screen for administrators) shows what the platform is built from and downloads as a file for your security team. Nexus adds a picture of nodes and a stream of events, useful in larger deployments. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Adversarial exercises
There are also offensive framings, reached for deliberately and under supervision: an adversary simulation covering a ransomware scenario, model against model, and a supply chain attack, plus a separate red team workbench aimed at language models, the ai-redteam surface, where a model is put through a run of jailbreak attempts and you see which ones get through. These are for someone who wants to test the reaction, not only the list. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Quick start
Od loginu aż po zapieczętowany raport, bez żadnych rytuałów pośrednich, prowadzą Cię poniższe kroki, które przechodzą przez jedną pełną misję od początku do końca.
1. Zaloguj się
Wejdź na app.cyrber.com jako OPERATOR lub ADMIN. Sesja to ciasteczko HTTP-only, ważne cztery godziny; po wygaśnięciu logujesz się ponownie, token nie leży w localStorage.
2. Dodaj zasięg
Na stronie /lex ustaw politykę LEX dla celu: zakres CIDR, tryb autonomii (poziom LIBER pozwala systemowi działać samodzielnie w tej klasie ryzyka) i flagę requires_consent dla wyższych tierów, gdzie krok wymaga Twojego podpisu przed wykonaniem. Samo pokrętło autonomii, ile wolności ma organizm, kręcisz na stronie /organism.
3. Odpal misję
W MISJE wybierz Start, podaj politykę i cel. Jeśli krok w planie wymaga wyższego tieru, podpisujesz zgodę (consent signing), zanim MENS ruszy. Po starcie MENS buduje graf ataku i dysponuje modułami skanującymi przez kolejki Celery (kolejka scanning).
4. Oglądaj na żywo
W KOKPICIE, w trybie Battle Mode, widzisz aktywną iterację: który moduł pracuje, na jakim celu, licznik znalezisk i EKG, które pulsuje kolorem zależnym od stanu misji.
5. Odbierz raport i pieczęć
Po zamknięciu misji TESTIMONIUM pieczętuje wynik: drzewo Merkle oraz podpis, a stąd eksportujesz raport misji do PDF w języku polskim lub angielskim. Taki sam raport, z nazwą organizacji, genomem i pieczęcią werdyktu zgodności, pobierzesz też dla pojedynczego skanu, na przykład OpenVAS. Raport składa się w tle: pierwszy trwa od kilkunastu sekund, a przycisk pokazuje, ile już czekasz; kolejne pobrania tego samego raportu przychodzą od razu. Zgodność pobierasz osobno, jako JSON dla NIS2, DORA i GDPR albo jako PDF dla samego NIS2. Pieczęć zweryfikujesz publicznie, bez naszej bazy, na trust.cyrber.com; krok po kroku pokazuje rozdział Public verify.
Ten sam zapieczętowany dowód nie musi czekać, aż ktoś go ręcznie pobierze, ponieważ wypychasz go wprost do Twojego systemu GRC, tam gdzie audytor już pracuje: assessment-results w standardzie OSCAL, plan działań naprawczych i PDF zgodności lądują jako załączniki przy kontroli, a komentarz notuje root drzewa Merkle, który audytor przelicza samodzielnie i porównuje z pieczęcią. Dowód opuszcza pieczęć tylko do systemu, który należy do Ciebie, a sam wypływ bramkujemy krokiem MFA. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Quick start
From login to a sealed report, no detours in between. The steps below walk one mission from start to finish.
1. Log in
Go to app.cyrber.com as OPERATOR or ADMIN. The session runs on an HTTP-only cookie, good for four hours; once it expires, you log in again, and the token never touches localStorage.
2. Set the scope
On /lex, write a LEX policy for the target: a CIDR range, an autonomy tier (LIBER lets the system act on its own within that risk class), and a requires_consent flag for the higher tiers, where a step waits for your signature before it fires. The autonomy dial itself, how much latitude the organism gets, lives on /organism.
3. Launch the mission
Under MISSIONS, pick Start, then the policy and the target. If a planned step needs a higher tier, you sign consent before MENS moves. Once launched, MENS builds an attack graph and dispatches scan modules through the Celery queues (the scanning queue).
4. Watch it live
In KOKPIT, Battle Mode shows the running iteration: which module is active, against which target, a running finding count, and a heartbeat trace that shifts color with the mission's state.
5. Collect the report and the seal
Once the mission closes, TESTIMONIUM seals the result with a Merkle tree and a signature, and from there you export the mission report to PDF in Polish or English. You get the same report, with the organisation name, the genome and the seal over the compliance verdict, for a single scan too, an OpenVAS one for instance. The report is built in the background: the first one takes from a dozen or so seconds and the button shows how long you have been waiting; later downloads of the same report arrive at once. Compliance is a separate export, as JSON for NIS2, DORA and GDPR or as PDF for NIS2 alone. You can check the seal yourself, no access to our database needed, at trust.cyrber.com; the Public verify chapter walks through it step by step.
That same sealed proof does not have to wait for someone to download it by hand, because you push it straight into your own GRC, where the auditor already works: the OSCAL assessment-results, the plan of action and milestones, and the compliance PDF land as attachments on the control, and a comment records the Merkle tree root that the auditor recomputes independently and checks against the seal. The proof leaves the seal only for a system that belongs to you, and the egress itself is gated by an MFA step. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Wdrożenie
CYRBER stawiasz na dwa sposoby i jest to świadomy wybór architektury, a nie przypadek, ponieważ model managed prowadzimy my na własnych serwerach, podczas gdy on-prem stoi w całości u klienta, na jego infrastrukturze i pod jego kontrolą. Ten rozdział mówi wprost, czym oba modele się różnią, co jest gotowe już dziś, a co dokładamy, zanim domkniemy pełny air-gap.
Dwa modele
Managed. Instancję prowadzimy my na infrastrukturze CYRBER, dzięki czemu dostajesz gotowe konto i zaczynasz pracę w kilka minut, bez stawiania własnego serwera, a wiele organizacji dzieli tę samą instancję z twardą izolacją per-org na poziomie bazy danych, tak że dane jednego klienta nigdy nie widzą danych drugiego, i właśnie w tym modelu działa dziś app.cyrber.com. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
On-prem. Cały stos stoi wtedy u klienta, na jego metalu i pod jego licencją, przez co przebieg misji oraz wszystkie dane zostają na jego infrastrukturze, a my nie trzymamy żadnej kopii; jest to model dla tych, którzy potrzebują pełnej suwerenności, i choć rozumowanie zamknięte w murach klienta domykamy dopiero modelem lokalnym, sama zasada pozostaje jednoznaczna. On-prem MAMY, a rozumowanie bez wyjścia na zewnątrz DOŁOŻYMY. Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Wybór modelu nie zmienia samego produktu, lecz jedynie to, gdzie on stoi i kto trzyma nad nim kontrolę, dlatego reszta rozdziału opisuje już wyłącznie stos, jednakowy w obu wariantach.
Edycje
Produkt jest jeden, a edycje różnią się przede wszystkim tym, jak długo trzymamy dane. Cztery pakiety układają się w drabinę: SPECULATOR trzyma misje przez trzydzieści dni, EXCUBITOR przez dziewięćdziesiąt, HARUSPEX przez rok, a PRAEFECTUS nie kasuje niczego i utrzymuje pełną historię bez końca, przy czym raporty przechowujemy odpowiednio dłużej, kolejno przez dziewięćdziesiąt dni, rok, trzy lata oraz również bez limitu, a wyższą edycję rozpoznasz też po tym, że dopiero na jej szczycie otwiera się tryb impact z ekstrakcją danych za pięcioma bramkami. Świadomie pokazujemy tu jedynie to, co edycja egzekwuje w kodzie, natomiast pełny zakres handlowy każdej z nich ustalasz z nami przy wdrożeniu, ponieważ nie chcemy wpisywać do dokumentacji obietnic, których kod nie potwierdza. Okna retencji per edycja oraz mapowanie licencji na pakiet MAMY. Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Egzekwowanie licencji
Edycja nie jest pustą etykietą, ponieważ jej wygaśnięcie egzekwuje sam system, i to stopniowo, a nie jednym zatrzaśnięciem drzwi. Dopóki licencja jest ważna, pracujesz bez ograniczeń, natomiast po jej wygaśnięciu wchodzisz najpierw w okres karencji, w którym blokujemy jedynie zakładanie nowych misji, podczas gdy cała reszta pracy toczy się dalej, a gdy i ten okres minie, platforma przechodzi w tryb tylko do odczytu, w którym żaden zapis już nie przejdzie, aż wreszcie w tryb zamrożenia danych. Kluczowe jest jednak to, co w tym ostatnim trybie zostaje otwarte, ponieważ nawet przy w pełni zamrożonym zapisie eksport dowodów, czyli raport PDF, wykonawczy i techniczny, działa nadal, tak że nie trzymamy Twoich dowodów jako zakładnika rozliczenia, a każdą z tych blokad system komunikuje operatorowi uczciwym kodem 402 wraz z nazwą trybu, nie cichym błędem. Stopniową degradację po wygaśnięciu wraz z zawsze otwartym eksportem MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Architektura
Rdzeń stanowią FastAPI oraz Celery, osadzone nad PostgreSQL 16 i Redis, a całość ukryta jest za nginx, podczas gdy zadania w tle chodzą czterema izolowanymi kolejkami, z których scanning obsługuje moduły MENS, reporting generuje PDF, intel zasila się ze źródeł KEV, ATT&CK i EPSS, a maintenance pilnuje arsenału, licencji i sprzątania. Ponieważ wszystko składa jeden plik Compose z profilami, ciężkie narzędzia, takie jak Kali, przeglądarka czy garak włączasz jednym profilem, a nie ręcznie. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Wymagania i tryby
Na start wystarcza pojedynczy węzeł on-prem, na którym stoi Docker, znajduje się dysk na dane i raporty oraz otwarty port dla nginx, a trybem domyślnym jest instalacja u klienta, przy której przebieg misji i dane zostają na jego infrastrukturze. Całość podnosi jeden instalator uruchamiany pojedynczym poleceniem, natomiast obraz przygotowany pod prywatny rejestr, skracający postawienie środowiska całkowicie odciętego do kilku minut, dokładamy osobno. Stos Compose oraz instalator jednego polecenia MAMY, a obraz pod prywatny rejestr DOŁOŻYMY. Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Wymagania sprzętowe
Wymagań sprzętowych nie zgadujemy, ponieważ rdzeń stacku deklaruje w Compose twarde limity zasobów, więc wyprowadzamy je wprost z tego, ile realnie biorą kontenery, a baza, Redis, API, worker Celery, beat oraz most Matrix sumują się w szczycie do około ośmiu gigabajtów pamięci i siedmiu rdzeni, natomiast każdy cięższy profil narzędziowy, taki jak ZAP czy Kali, dokłada do tego kolejne dwa gigabajty i dwa rdzenie. Poniżej opisujemy trzy poziomy, prowadzące od progu, na którym system w ogóle ruszy, aż po konfigurację, na której chodzi idealnie, przy czym pod samym poziomem minimalnym leży jeszcze niższy próg absolutny rzędu sześćdziesięciu gigabajtów dysku, którego instalator pilnuje i poniżej którego odmawia startu, lecz trzymamy go wyłącznie na ewaluację, a nie na realną pracę. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Jest to próg, na którym system startuje z zapasem nad limitami kontenerów, ponieważ zakłada rozumowanie w chmurze bez GPU, skany prowadzone sekwencyjnie oraz niewielki zespół operatorów, lecz nie zostawia jeszcze pola na wiele misji naraz ani na pełny arsenał narzędzi.
To poziom, na którym stawiamy większość instalacji on-prem, ponieważ udźwignie kilka misji prowadzonych równolegle oraz włączone profile narzędzi, takie jak ZAP, Kali i przeglądarka, zapewniając operatorowi komfortową, płynną pracę.
Jest to konfiguracja, na której system chodzi idealnie, ponieważ udźwignie pełny arsenał, dużą flotę celów oraz lokalny model rozumowania w trybie air-gap uruchomiony na tej właśnie karcie, dzięki czemu ani jeden token nie wychodzi na zewnątrz, przy czym sam lokalny model na GPU dopiero DOŁOŻYMY. Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Do zasobów obliczeniowych dochodzą zasoby dyskowe, ponieważ organizm z czasem rośnie i uczy się na własnej historii, a na dysku odkładają się dane PostgreSQL, wygenerowane raporty PDF, artefakty skanów, łańcuch pieczęci oraz korpus instytucjonalny z osadzeniami, z których CORTEX i LIBER czerpią przy kolejnych misjach, dlatego dysk traktuj jako zasób rosnący, a nie stały, i przewiduj zapas ponad wartości podane w powyższych poziomach. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Zupełnie osobną możliwością systemu jest UMBRA. Dziś to precyzyjny blueprint środowiska klienta: migawka topologii i powierzchni ataku wraz z migawkami ryzyka oraz sześciogodzinnym cooldownem. Na dysku waży tyle, ile metadane, rzędy megabajtów na organizację, i nie rezerwuje pod siebie osobnych maszyn. Celem, do którego zmierzamy, jest pełny cyfrowy bliźniak: postawiona z tego blueprintu, działająca replika środowiska wraz z Active Directory i siecią, na której puszczasz testy destrukcyjne najgorszego scenariusza, nie narażając ani jednego żywego systemu. Taki bliźniak potrzebuje własnej puli rdzeni, pamięci i dysku, skalowanej wprost z liczbą odwzorowanych hostów i dobranej do skali celu oraz budżetu klienta. Blueprint z cooldownem MAMY. Automatyczne stawianie pełnej, działającej umbry pod skalę całego środowiska DOŁOŻYMY. Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Jeśli nie chcesz stawiać sprzętu samodzielnie, przygotowujemy gotowy appliance CYRBER, czyli maszynę z zainstalowanym i zestrojonym systemem, którą wystarczy wpiąć w sieć, aby ruszyć bez własnej roboty infrastrukturalnej. DOŁOŻYMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Retencja i dane do uczenia
Wzrost dysku nie jest nieokreślony, ponieważ część danych porządkuje w tle retencja: telemetria pulsu znika po sześćdziesięciu dniach, misje wędrują do archiwum po oknie właściwym dla pakietu, wynoszącym trzydzieści dni w SPECULATOR, dziewięćdziesiąt w EXCUBITOR oraz trzysta sześćdziesiąt pięć w HARUSPEX, a raporty trzymamy odpowiednio dłużej, przy czym pakiet PRAEFECTUS nie kasuje niczego i zachowuje pełną historię bez końca. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Retencja świadomie omija jedno, mianowicie substrat, na którym organizm się uczy, ponieważ genom bezpieczeństwa wraz z migawkami i trendem, osadzenia znalezisk oraz korpus instytucjonalny LIBER razem ze wzorcami CORTEX nie podlegają żadnemu czyszczeniu, tak że nawet kiedy usuwamy surowe misje, pamięć wyprowadzona z ich przebiegu zostaje, a to właśnie ona sprawia, że system z każdym miesiącem sądzi trafniej. Ma to jednak swoją konsekwencję dla dysku, gdyż ta warstwa rośnie bez górnej granicy i to ją, a nie chwilowe artefakty skanów, trzeba planować na lata, dlatego przy instalacji na dłuższą metę dokładaj zapas dysku ponad wartości z poziomów sprzętowych. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Instalacja krok po kroku
Najkrótsza droga to jedno polecenie, ponieważ instalator sprawdza wymagania systemu, w razie potrzeby dokłada Dockera, generuje wszystkie sekrety oraz plik .env, wystawia certyfikat TLS, zakłada rolę bazy pod izolację RLS, podnosi stos, migruje schemat Alembikiem do wersji head, czeka na zdrowe API, a na końcu wypisuje adres panelu wraz z odciskiem maszyny do aktywacji licencji. Ścieżkę ręczną, czyli klon repozytorium, wypełnienie .env (baza, Redis, sekret JWT o długości co najmniej trzydziestu dwóch znaków oraz klucz szyfrujący kolumny), postawienie stosu i migracje, zostawiamy dla tych, którzy wolą prowadzić każdy krok samodzielnie, przy czym po jednej i drugiej drodze zakładasz konto administratora, włączasz MFA i od tego momentu logujesz się już wyłącznie ciasteczkiem HTTP-only. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Kreator pierwszego uruchomienia
Po postawieniu stosu nie zostajesz przed pustym panelem, ponieważ pierwsze logowanie prowadzi kreator wdrożenia, który w pięciu krokach doprowadza Cię od świeżej instalacji do pierwszej misji. Zaczynasz od profilu sektora, gdzie wybór instytucji, na przykład samorząd, finanse, przemysł albo zdrowie, ustawia rozsądne wartości domyślne pakietu, polityki oraz macierzy autonomii, następnie zakładasz organizację wraz z jej trybem połączenia, podłączonym, planowym albo całkowicie odciętym, po czym podajesz zakres celu jako adresy CIDR oraz domeny, na tej podstawie kreator zapisuje politykę LEX z oknami czasowymi i progami zgody, a na końcu odpala pierwszą misję MENS i przenosi Cię prosto na jej podgląd. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Model rozumowania
Domyślnie rozumowanie kierujemy do chmury łańcuchem zapasowym, w którym Mistral pełni rolę głównego dostawcy, a za nim ustawiają się kolejno Claude, OpenAI oraz DeepSeek, a w pętli rozumowania MENS, zanim prompt trafi do chmurowego modelu, maskujemy publiczne adresy IP oraz nazwy hostów deterministycznym hashem liczonym osobno dla każdej misji, więc model rozumuje nad strukturą, nie widząc realnych adresów, a prywatne zakresy testowe zostawiamy nietknięte. Router robi to samo maskowanie przed każdym wywołaniem modelu, także przy narracji po misji, więc adres celu nie wychodzi z platformy. Taki układ działa już dziś, podczas gdy lokalny model zamknięty w murach klienta, czyli Ollama na serwerze GPU, jest wprawdzie przygotowany w kodzie, lecz prąd jeszcze przez niego nie płynie, dlatego przełączenie na tryb lokalny domykamy, zanim uruchomisz CYRBER produkcyjnie u siebie. Chmurę z maskowaniem adresów przed wysyłką MAMY, a model lokalny w trybie air-gap DOŁOŻYMY. Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Stąd bierze się też wymóg karty o co najmniej dwudziestu czterech gigabajtach pamięci, ponieważ model, który zamykamy w murach klienta, należy do klasy od kilku do kilkunastu miliardów parametrów, czyli qwen3 klasy trzydziestu miliardów (MoE, około trzech miliardów aktywnych) do rozumowania oraz Qwen czternastu miliardów do zadań badawczych, a w wersji skwantyzowanej jeden taki model wraz z kontekstem mieści się właśnie w dwudziestu czterech gigabajtach, natomiast gdy chcesz trzymać oba załadowane równolegle, wygodną pracę daje dopiero około czterdziestu ośmiu gigabajtów, czyli para kart klasy RTX 6000 Ada. DOŁOŻYMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Sieć i egress
Od strony sieci obraz jest przejrzysty, ponieważ do środka prowadzi jedynie nginx, przez który wchodzi ruch HTTPS operatorów, i żaden inny port nie musi być wystawiony na świat, natomiast na zewnątrz domyślna konfiguracja sięga dokładnie do czterech miejsc, które nazywamy wprost, bo to od nich zależy cała rozmowa o air-gapie: rozumowanie kierujemy do chmurowego dostawcy LLM, Intel Sync pobiera kanały zagrożeń z CISA KEV, MITRE ATT&CK, FIRST EPSS oraz NVD, most Matrix wysyła alerty na serwer domowy, a pieczęć TESTIMONIUM wysyła sam root_hash do publicznych serwerów kalendarza OpenTimestamps po kotwicę czasową w łańcuchu Bitcoin. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Każde z tych czterech wyjść daje się domknąć, a suwerenność polega właśnie na ich świadomym odcięciu, ponieważ rozumowanie zamykasz w murach klienta lokalnym modelem na GPU, i to jedyny element, który do pełnego air-gapu jeszcze dokładamy, podczas gdy Intel Sync zastępujesz pakietem wywiadu offline, eksportowanym z instancji podłączonej i wgrywanym do odciętej, most Matrix albo wyłączasz jednym przełącznikiem, albo kierujesz na własny serwer domowy klienta, a kotwicę OpenTimestamps zdejmujesz jednym przełącznikiem, po którym pieczęć wciąż domyka się drzewem Merkle oraz podpisem HMAC na każdym liściu, tracąc jedynie publiczne zakotwiczenie w łańcuchu Bitcoina, przy czym wszystkie te trzy odcięcia działają już dziś. Odcięcie wywiadu, mostu oraz kotwicy OpenTimestamps MAMY, a odcięcie rozumowania lokalnym modelem DOŁOŻYMY. Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Kopia i odtwarzanie
Kopia zapasowa to zrzut PostgreSQL szyfrowany GPG, zamknięty w trybie fail-close, w którym pozbawiony klucza skrypt produkcyjny raczej przerwie pracę, niż zapisze jawny plik na dysku, a do tego dochodzi retencja domyślnie trzydziestodniowa oraz odcisk migracji, który przy odtwarzaniu pilnuje parytetu wersji, więc kiedy wepniesz całość zwykłym cronem, możesz spać spokojnie. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Sam pakiet to jednak więcej niż baza, ponieważ obok zrzutu PostgreSQL zamykamy w nim także wygenerowane raporty oraz odcisk wersji migracji, a na życzenie również plik konfiguracyjny z kluczem szyfrującym kolumny, bez którego odtworzenie bazy nie miałoby sensu, i tak złożony pakiet domyślnie ląduje na dysku węzła, natomiast gdy wskażesz zdalny magazyn, kopiuje się dodatkowo poza serwer, przy czym w modelu on-prem to miejsce pozostaje w pełni pod kontrolą klienta. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Rytm kopii ustawiasz własnym cronem, a my zalecamy przebieg nocny, przez co punkt odtworzenia, czyli ile danych najwyżej stracisz przy awarii, równa się odstępowi między kopiami i w wariancie dobowym wynosi co najwyżej jeden dzień, natomiast świeżości ostatniej kopii pilnuje osobny sprawdzian zdrowia, a jej odtwarzalność potwierdza skrypt testu odtworzenia, tak że kopia nie jest kwestią wiary, lecz czymś realnie sprawdzonym. Kopię, monitoring jej świeżości oraz test odtworzenia MAMY, a ciągłą archiwizację skracającą punkt odtworzenia poniżej doby DOŁOŻYMY. Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Wysoka dostępność
O odporności mówimy wprost, ponieważ dziś stawiamy CYRBER na pojedynczym węźle, a to, co chroni go w codziennej pracy, działa wewnątrz tego węzła, gdyż kontenery pod nadzorem wstają po zawieszeniu, osobne zadania w tle wykrywają i podnoszą utknięte misje oraz cofają nieudane naprawy, tak że pojedyncza usługa, która się potknie, wraca do formy bez udziału operatora. Samoleczenie w obrębie węzła MAMY. Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Nie udajemy natomiast prawdziwej wysokiej dostępności, ponieważ utrata całego węzła nie przełącza dziś ruchu na zapasowy samoczynnie, lecz sprowadza się do odtworzenia z kopii na nowym sprzęcie, którego czas zależy od rozmiaru bazy, dlatego gorący standby bazy, automatyczny failover oraz układ pozbawiony pojedynczego punktu awarii traktujemy jako osobny, świadomie nazwany etap. Odtworzenie po utracie węzła MAMY, a gorący standby z automatycznym przełączeniem DOŁOŻYMY. Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Izolacja i hardening
Wiele organizacji utrzymywanych na jednej instancji rozdziela izolacja per-org na poziomie bazy danych, wejście chroni ciasteczko HTTP-only wsparte MFA/TOTP oraz SSO/OIDC, a każde wywołanie zdolności ląduje w łańcuchu audytu, natomiast formalny przewodnik hardeningu, spięty w jeden dokument, dopiero dokładamy. Izolację i audyt MAMY, a spójny przewodnik hardeningu DOŁOŻYMY. Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Postawienie maszyny to dopiero połowa drogi, ponieważ codzienna praca rządzi się własnymi prawami, a to, jak prowadzić misje, czytać werdykt i eksportować dowód, opisuje rozdział Obsługa.
Deployment
You stand CYRBER up in two ways, and it is a deliberate choice, not an accident. We run the managed model on our own servers, while on-prem stands entirely at the client. This chapter says plainly how they differ, what is ready today and what we will add before a full air-gap.
Two models
Managed. We run the instance on CYRBER infrastructure; you get an account and start in a few minutes, with no server of your own. Many organizations share one instance with hard per-org isolation at the database level, so one client's data never sees another's. This is how app.cyrber.com runs today. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
On-prem. The whole stack stands at the client, on their metal, under their license. The mission run and the data stay on their infrastructure, we keep no copy. This is the model for full sovereignty; we close the reasoning inside the client's walls only once a local model lands. On-prem is SHIPPED, reasoning with no path outside is PLANNED. You can check this yourself in a demonstration, in the public verifier, or on the trust site.
The choice does not change the product; it changes where it stands and who holds it. The rest of this chapter describes the stack itself, identical in both models.
Editions
The product is one; the editions differ mainly in how long we keep the data. Four packages form a ladder: SPECULATOR holds missions for thirty days, EXCUBITOR for ninety, HARUSPEX for a year, and PRAEFECTUS deletes nothing and keeps the full history without end, with reports kept correspondingly longer, ninety days, a year, three years and again without limit, and you also recognize a higher edition by the fact that only at its top does the impact mode open, with data extraction behind five gates. We deliberately show here only what an edition enforces in the code, while you agree the full commercial scope of each with us at deployment, because we do not want to write promises into the documentation that the code does not bear out. The retention windows per edition and the license-to-package mapping are SHIPPED. You can check this yourself in a demonstration, in the public verifier, or on the trust site.
License enforcement
An edition is not an empty label, because the system enforces its expiry itself, and it does so gradually rather than by slamming one door. While the license is valid you work without limits, whereas once it expires you enter a grace period first, in which we block only the starting of new missions while the rest of the work carries on, and when that period too runs out the platform moves into a read-only mode where no write goes through any longer, and finally into a data-frozen mode. What matters is what stays open in that last mode, because even with writes fully frozen the evidence export, the PDF, executive and technical reports, still runs, so we do not hold your evidence hostage to a bill, and the system answers each of these blocks to the operator with an honest 402 and the mode's name rather than a silent error. The gradual degradation on expiry together with an always-open export is SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Architecture
The core is FastAPI and Celery over PostgreSQL 16 and Redis, behind nginx. Background work runs on four isolated queues: scanning for the MENS modules, reporting for PDFs, intel for the KEV, ATT&CK and EPSS feeds, and maintenance for the arsenal, licensing and cleanup. One Compose file with profiles assembles the whole thing, so heavy tools like Kali, the browser or garak come up by profile, not by hand. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Requirements and modes
One on-prem node is enough to start: Docker, disk for data and reports, a port for nginx. The default mode is an install at the client, the mission run and the data stay on their infrastructure. A single installer brings the whole thing up with one command, while an image built for a private registry, which cuts standing up a fully severed environment down to minutes, we add separately. The Compose stack and the one-command installer are SHIPPED, the private-registry image is PLANNED. You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Hardware requirements
We do not guess the hardware, because the core stack declares hard resource limits in Compose, so we derive the sizing straight from what the containers actually take, and the database, Redis, the API, the Celery worker, beat and the Matrix bridge add up at peak to roughly eight gigabytes of memory and seven cores, while each heavier tool profile, such as ZAP or Kali, adds another two gigabytes and two cores. Below we describe three levels, leading from the threshold where the system runs at all to the configuration where it runs ideally, and below the minimum level itself sits an even lower absolute floor, around sixty gigabytes of disk, which the installer enforces and below which it refuses to start, though we keep it for evaluation only, not for real work. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
This is the threshold where the system starts with headroom over the container limits, because it assumes cloud reasoning with no GPU, scans run sequentially and a small operator team, yet it leaves no room for many missions at once or the full tool arsenal.
This is the level on which we stand most on-prem installs, because it carries several missions in parallel and the tool profiles turned on, such as ZAP, Kali and the browser, giving the operator comfortable, smooth work.
This is the configuration where the system runs ideally, because it carries the full arsenal, a large fleet of targets and a local reasoning model in air-gap mode running on that very card, so not one token leaves, though the local model on the GPU itself is still PLANNED. You can check this yourself in a demonstration, in the public verifier, or on the trust site.
On top of the compute come the disk resources, because the organism grows over time and learns from its own history, and the disk accumulates PostgreSQL data, generated PDF reports, scan artifacts, the seal chain and the institutional corpus with embeddings that CORTEX and LIBER draw on across later missions, so treat the disk as a growing resource rather than a fixed one and plan headroom above the figures in the levels above. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
A wholly separate capability of the system is UMBRA. Today it is a precise blueprint of the client's environment: a snapshot of topology and attack surface with risk snapshots and a six-hour cooldown. On disk it weighs what metadata weighs, on the order of megabytes per organization, and it reserves no machines of its own. What we are building towards is a full digital twin: a running replica stood up from that blueprint, Active Directory and network included, where you run worst-case destructive tests without exposing a single live system. Such a twin needs its own pool of cores, memory and disk, scaling directly with the number of mirrored hosts and matched to the target and the client's budget. The blueprint with its cooldown is SHIPPED. Standing up a full, running umbra automatically at the scale of a whole environment is PLANNED. You can check this yourself in a demonstration, in the public verifier, or on the trust site.
If you would rather not stand up the hardware yourself, we are preparing a ready-made CYRBER appliance, a machine with the system installed and tuned, which you only plug into the network to start, with no infrastructure work of your own. PLANNED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Retention and the learning data
Disk growth is not open-ended, because retention orders part of the data in the background: pulse telemetry is gone after sixty days, missions move to the archive after the window that fits the package, thirty days on SPECULATOR, ninety on EXCUBITOR and three hundred and sixty-five on HARUSPEX, and reports are kept correspondingly longer, while the PRAEFECTUS package deletes nothing and keeps the full history without end. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Retention deliberately spares one thing, the substrate the organism learns on, because the security genome with its snapshots and trend, the finding embeddings and the LIBER institutional corpus together with the CORTEX patterns are subject to no cleanup, so even when we delete the raw missions, the memory drawn from their run stays, and it is that memory which makes the system judge more accurately each month. This does carry a consequence for disk, since this layer grows with no upper bound, and it is this layer, not the transient scan artifacts, that you plan for over the years, so for a long-lived install add disk headroom above the figures in the hardware levels. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Install, step by step
The shortest path is one command, because the installer checks the system requirements, adds Docker if it is missing, generates every secret and the .env file, issues a TLS certificate, sets up the database role for RLS isolation, brings the stack up, migrates the schema with Alembic to head, waits for a healthy API, and finally prints the panel address together with the machine fingerprint for license activation. The manual path, cloning the repo, filling in .env (database, Redis, a JWT secret of at least thirty-two characters, the column encryption key), bringing the stack up and running migrations, we leave for those who prefer to drive every step themselves, and down either path you create an admin account, turn on MFA and from there log in with an HTTP-only cookie and nothing else. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
First-run wizard
Once the stack is up you are not left staring at an empty panel, because the first login runs a deployment wizard that walks you in five steps from a fresh install to the first mission. You start with the sector profile, where the choice of institution, local government, finance, industry or health for instance, sets sensible defaults for the package, the policy and the autonomy matrix, then you create the organization together with its connection mode, connected, scheduled or fully severed, after which you give the target scope as CIDR addresses and domains, on that basis the wizard writes a LEX policy with time windows and consent thresholds, and finally it launches the first MENS mission and takes you straight to its view. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
The reasoning model
By default the reasoning goes to the cloud with a fallback chain: Mistral as primary, then Claude, OpenAI and DeepSeek. In the MENS reasoning loop, before a prompt reaches the cloud model, we mask the public IP addresses and hostnames inside it with a deterministic hash computed per mission, so the model reasons over the structure without seeing the real addresses, while private test ranges are left untouched. The router applies the same masking before every model call, including the narrative written after a mission ends, so the target address does not leave the platform. That works today. A local model inside the client's walls, Ollama on a GPU server, is prepared in the code, but the current is not flowing yet; the cutover to local lands before you run CYRBER in production on your own site. The cloud with address masking before send is SHIPPED, the local air-gap model is PLANNED. You can check this yourself in a demonstration, in the public verifier, or on the trust site.
This is also where the requirement of a card with at least twenty-four gigabytes of memory comes from, because the model we shut inside the client's walls sits in the class of a few to a few tens of billions of parameters, meaning a qwen3 in the thirty-billion class (MoE, roughly three billion active) for reasoning and a Qwen of fourteen billion for research tasks, and when quantized, one such model together with its context fits exactly in twenty-four gigabytes, while if you want to keep both loaded in parallel, comfortable work starts only around forty-eight gigabytes, that is, a pair of RTX 6000 Ada-class cards. PLANNED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Network and egress
On the network side the picture is clean, because the only way in is nginx, through which the operators' HTTPS traffic enters, and no other port has to face the world, while outbound the default configuration reaches exactly four places, which we name plainly, because the whole air-gap conversation turns on them: the reasoning goes to a cloud LLM provider, Intel Sync pulls threat feeds from CISA KEV, MITRE ATT&CK, FIRST EPSS and NVD, the Matrix bridge sends alerts to a home server, and the TESTIMONIUM seal sends the bare root_hash to the public OpenTimestamps calendar servers for a timestamp anchor on the Bitcoin chain. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Each of these four exits can be closed, and sovereignty is exactly this deliberate severing, because you shut the reasoning inside the client's walls with a local model on the GPU, and that is the only element still outstanding for a full air-gap, while you replace Intel Sync with an offline intelligence package exported from a connected instance and imported into the severed one, you either turn the Matrix bridge off with a single switch or point it at the client's own home server, and you drop the OpenTimestamps anchor the same way, after which the seal still closes over its Merkle tree and the per-leaf HMAC signature, losing only the public Bitcoin anchoring, all three of which work today. Severing the intelligence, the bridge and the OpenTimestamps anchor is SHIPPED, severing the reasoning with a local model is PLANNED. You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Backup and restore
The backup is a PostgreSQL dump encrypted with GPG and fail-close (with no key in production the script refuses to write a plaintext file), and it comes with a default thirty-day retention and a migration fingerprint for restore parity. You wire it to cron and sleep soundly. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
The bundle is more than the database, because alongside the PostgreSQL dump we seal in the generated reports and the migration-version fingerprint, and on request the configuration file with the column encryption key, without which restoring the database would be pointless, and the bundle so assembled lands by default on the node's disk, while if you name a remote store it is additionally copied off the server, and in the on-prem model that location stays entirely under the client's control. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
You set the backup rhythm with your own cron, and we recommend a nightly run, so the recovery point, meaning how much data you lose at most in a failure, equals the interval between backups and in the daily variant is at most one day, while the freshness of the latest backup is watched by a separate health check and its restorability is proven by a restore-test script, so the backup is not a matter of faith but something actually verified. The backup, the freshness monitoring and the restore test are SHIPPED, continuous archiving that shortens the recovery point below a day is PLANNED. You can check this yourself in a demonstration, in the public verifier, or on the trust site.
High availability
We talk about resilience plainly, because today we stand CYRBER on a single node, and what protects it in daily work runs inside that node, since supervised containers come back up after a stall, separate background tasks detect and revive stuck missions and roll back failed remediations, so a single service that trips returns to form with no hand from an operator. Self-healing within the node is SHIPPED. You can check this yourself in a demonstration, in the public verifier, or on the trust site.
What we do not pretend, on the other hand, is true high availability, because the loss of a whole node does not switch traffic to a spare on its own today, but comes down to restoring from backup on new hardware, whose time depends on the database size, so we treat a hot standby of the database, automatic failover and a layout with no single point of failure as a separate, deliberately named stage. Recovery after a node loss is SHIPPED, a hot standby with automatic failover is PLANNED. You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Isolation and hardening
Many organizations on one instance are kept apart by per-org isolation at the database level. The entrance is guarded by an HTTP-only cookie, MFA/TOTP and SSO/OIDC, and every capability call lands in the audit chain. A formal hardening guide, gathered into one document, is still to come. Isolation and audit are SHIPPED, the hardening guide is PLANNED. You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Standing the machine up is one thing; the daily work is another. The Operating chapter covers how to run missions, read the verdict and export the proof.
Obsługa
Quick start przeprowadza jedną misję od loginu aż po pieczęć, natomiast ten rozdział zbiera całą obsługę codzienną, na którą składają się role i dostęp, cykl misji, pokrętło autonomii, naprawa oraz eksport dowodu.
Role i dostęp
Role nadajesz w Administracji, przy dodawaniu użytkownika, i każda widzi tyle, ile powinna. ADMIN zarządza swoją organizacją: użytkownikami, kluczami API, SSO i dziennikiem audytu, i widzi wszystkie ekrany. OPERATOR prowadzi misje, znaleziska, operacje, naprawy, raporty i zgodność. AUDITOR ma wgląd tylko do odczytu w zgodność, weryfikację i podsumowanie dla zarządu, bez misji i operacji. CEO widzi podsumowanie dla zarządu, ryzyko i genom organizacji, przegląd znalezisk oraz stan zgodności. VIEWER ogląda znaleziska, zgodność i stan organizmu wyłącznie do odczytu. Ponad rolami stoi superadministrator, który prowadzi wszystkie organizacje, a konto demonstracyjne dostaje taki podgląd jak VIEWER. MAMY Sprawdzisz to sam w kodzie: backend/roles.py, static/nav.js
Cykl misji
Misja zaczyna się od polityki LEX, która wyznacza zasięg oraz klasę ryzyka, po czym MENS iteruje pętlą OBSERVE, THINK, ACT, LEARN i samodzielnie dobiera następny ruch, a gdy tylko się domknie, uruchamia się łańcuch hooków, na który składają się profil SPECULUM, pieczęć TESTIMONIUM, migawka UMBRA, prognoza ANNALES, kolejka naprawy oraz pamięć LIBER. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Pokrętło autonomii
To, ile wolności otrzymuje organizm, ustawiasz na stronie /organism, gdzie dla niższej klasy ryzyka system działa samodzielnie, natomiast dla wyższej każdy krok czeka na Twój podpis, czyli na consent, a opcjonalnie na bramę MFA, zanim w ogóle się wykona, i właśnie dlatego jest to pokrętło z klasami ryzyka, a nie przełącznik zero-jeden. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Werdykt i naprawa
Znaleziska lądują na Zagrożeniach opatrzone poziomem severity oraz ryzykiem biznesowym, a samą naprawę prowadzi MEDICUS, który proponuje konkretny krok, którego wykonanie zbroisz podpisem TOTP na miejscu, bez opuszczania ekranu. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Zgodność i eksport
Wynik mapuje się na NIS2, DORA oraz GDPR, a sam raport misji, w języku polskim lub angielskim i opatrzony brandingiem klienta, eksportujesz do PDF jednym kliknięciem, natomiast eksport zgodności pobierasz osobno: dla całej trójki wychodzi jako JSON, a do PDF renderuje się dziś wyłącznie NIS2, ponieważ wariantu dla DORA i GDPR jeszcze nie dołożyliśmy. Każdy skan pieczętuje przy tym TESTIMONIUM drzewem Merkle oraz podpisem, dzięki czemu samą pieczęć sprawdzisz publicznie, bez dostępu do naszej bazy. Raport misji w PDF, eksport zgodności w JSON dla całej trójki oraz PDF dla NIS2 MAMY, a PDF dla DORA i GDPR DOŁOŻYMY (szczegóły w rozdziale Compliance). Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Podgląd na żywo
KOKPIT w trybie Battle pokazuje aktywną iterację wraz z EKG misji, natomiast żywotność organizmu, w którym każdy z … komponentów pozostaje pod rygorem niezmiennika I-9, obserwujesz na stronach Organizm oraz Status. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Najczęstsze pytania
Jak uruchomić pierwszą misję? Misję MENS zlecasz w oknie rozmowy z CYRBER, podając cel, na przykład adres serwera. CYRBER pokazuje cel i tryb, a misja rusza dopiero po Twoim TAK. Cel musi mieścić się w zakresie ustalonym w polityce LEX Twojej organizacji, inaczej LEX go odrzuci. Zlecić misję może operator albo administrator. Przycisk na stronie Misje uruchamia osobno skan OpenVAS. MAMY Sprawdzisz to sam w kodzie: modules/capabilities/missions.py
Co się dzieje po zakończeniu misji? Gdy misja się kończy, CYRBER sam uruchamia łańcuch kroków. Pieczętuje znaleziska w TESTIMONIUM, liczy genom SPECULUM, zapisuje migawkę UMBRA, pisze opis przebiegu misji, przelicza ocenę ryzyka, odświeża prognozę ANNALES i proponuje naprawy. Wynik zobaczysz na stronie misji (Misje, potem wybrana misja), a raport PDF pobierzesz w Raportach. MAMY Sprawdzisz to sam w kodzie: modules/mind_agent.py
Po co jest rejestr zgód? Rejestr zgód (strona Zgody, /consents) zbiera każdą zgodę na misję, która jej wymaga: na jaki cel, w jakim trybie i kto zdecydował. Zgoda ma jednorazowy token ważny 24 godziny. Z rejestru zatwierdzisz albo cofniesz zgodę, przedłużysz ją o dobę, wyślesz ponownie prośbę, zobaczysz jej historię i wyeksportujesz listę do CSV. Administrator widzi zgody swojej organizacji. MAMY Sprawdzisz to sam w kodzie: backend/routers/consent.py
Jak działa ANNALES? ANNALES pamięta historię ryzyka organizacji i przewiduje, jak się zmieni. Prognozę odświeża codziennie o 4:45 UTC, a po każdej misji oznacza ją jako nieaktualną, żeby następna uwzględniła nowe znaleziska. Każda prognoza dostaje później wynik celności, porównany z tym, co faktycznie się stało. Wykres i prognozy są na stronie ANNALES (/annales). MAMY Sprawdzisz to sam w kodzie: modules/annales.py
Czym jest SPECULUM i co pokazuje genom bezpieczeństwa? SPECULUM składa wynik misji w genom bezpieczeństwa organizacji: siedem wymiarów na jednym radarze. Są to ekspozycja sieci, aktualizacje i łatki, uwierzytelnianie i dostęp, bezpieczeństwo aplikacji, ochrona danych, czynnik ludzki oraz łańcuch dostaw. Kolejne misje dokładają znaleziska do genomu, zamiast go nadpisywać. Radar zobaczysz na stronie SPECULUM (/speculum). MAMY Sprawdzisz to sam w kodzie: modules/speculum.py
Jak pobrać raport PDF z misji? Raporty są na stronie Raporty (/reports). Wybierasz zakończoną misję i język raportu (polski albo angielski), generujesz raport, a gotowy plik pobierasz przyciskiem POBIERZ PDF. Raport niesie branding Twojej organizacji. MAMY Sprawdzisz to sam w kodzie: backend/routers/reports.py
Jak dodać użytkownika? Użytkowników dodaje administrator organizacji w Administracji (/admin), na zakładce Użytkownicy, przyciskiem + DODAJ UŻYTKOWNIKA. Podajesz dane konta i wybierasz rolę, która określa, co ta osoba zobaczy i co może zrobić. MAMY Sprawdzisz to sam w kodzie: static/admin.html
Czym różni się operator od klienta i od innych ról? Operator pracuje: zleca misje, prowadzi naprawy, wystawia raporty i obsługuje zgody. Klient tylko ogląda. Dawną rolę klienta nadajesz dziś jako VIEWER (znaleziska i zgodność do odczytu), CEO (podsumowanie dla zarządu, ryzyko i genom) albo AUDITOR (zgodność i weryfikacja do odczytu). Żadna z tych trzech ról nie uruchamia misji ani napraw. MAMY Sprawdzisz to sam w kodzie: backend/roles.py
Dlaczego misja jest wstrzymana i czeka na zgodę? W trybie ze zgodą operatora misja zatrzymuje się przed krokiem, który wymaga Twojej decyzji. Zatwierdzasz go albo odrzucasz w oknie rozmowy z CYRBER albo w komunikatorze. Po 20 minutach bez decyzji przychodzi ostrzeżenie, a potem przypomnienia co dwie godziny. Misja czeka na Ciebie i sama nie przechodzi dalej. Krok najwyższego poziomu bez decyzji przez 24 godziny przerywa misję. MAMY Sprawdzisz to sam w kodzie: modules/tasks.py
Co sprawdza strona Weryfikacja? Weryfikacja (/verify) sprawdza, czy adres e-mail, strona internetowa albo firma (także po numerze NIP) nie jest oszustwem. Wpisujesz zapytanie, CYRBER sam rozpoznaje jego rodzaj i zwraca ocenę z uzasadnieniem. Historia wcześniejszych sprawdzeń zostaje na tej samej stronie. Pieczęć misji sprawdzasz osobno, w rozdziale Weryfikacja publiczna. MAMY Sprawdzisz to sam w kodzie: modules/verify.py
Jak podłączyć Matrix i rozmawiać z CYRBER w komunikatorze? Gdy administrator doda Cię jako użytkownika, a instalacja ma włączone automatyczne konta, CYRBER sam zakłada Ci konto w komunikatorze Matrix pod tym samym loginem i wiąże je z kontem w aplikacji. W Elemencie albo innym kliencie Matrix wybierasz serwer swojej instalacji i logujesz się przyciskiem Zaloguj przez CYRBER. W komunikatorze masz te same uprawnienia co w aplikacji. Pokoje organizacji (Alerty, Zgody, Briefing) zakłada administrator w Ustawieniach, w sekcji Matrix, przyciskiem WŁĄCZ KANAŁY. W pokoju Zgody odpowiadasz TAK albo NIE na prośby o zgodę. MAMY Sprawdzisz to sam w kodzie: modules/matrix_account_provision.py, modules/matrix_provision.py
Gdzie konkretnie werdykt zapada w rytuale, opisuje akt Werdykt w rozdziale Rytuał, natomiast to, jak sprawdzić pieczęć bez naszej bazy, pokazuje rozdział Public verify.
Operating
Quick start walks one mission from login to seal. This is the full operation: roles, the mission cycle, the autonomy dial, remediation and the evidence export.
Roles and access
You assign roles under Administration when you add a user, and each role sees what it should. ADMIN runs their own organization: users, API keys, SSO and the audit log, and sees every screen. OPERATOR runs missions, findings, operations, remediation, reports and compliance. AUDITOR has read-only access to compliance, verification and the executive summary, without missions or operations. CEO sees the executive summary, the organization's risk and genome, a findings overview and the compliance status. VIEWER sees findings, compliance and the organism state, read-only. Above the roles stands the superadmin, who runs every organization, and a demo account gets the same view as VIEWER. SHIPPED You can check it in the code: backend/roles.py, static/nav.js
The mission cycle
A mission starts from a LEX policy that sets the scope and the risk class. Then MENS iterates the OBSERVE, THINK, ACT, LEARN loop and picks its own next move. On close a hook chain fires: the SPECULUM profile, the TESTIMONIUM seal, the UMBRA snapshot, the ANNALES forecast, the remediation queue and the LIBER memory. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
The autonomy dial
You set how much latitude the organism gets on /organism. For a lower risk class the system acts on its own, for a higher one a step waits for your signature (consent, optionally an MFA gate) before it fires. It is a dial with risk classes, not a zero-one switch. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Verdict and remediation
Findings land under Threats with a severity level and a business risk. Remediation runs through MEDICUS: it proposes a step, and you arm its execution with an inline TOTP signature, without leaving the screen. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Compliance and export
The result maps to NIS2, DORA and GDPR, and the mission report itself, in Polish or English and with the client's branding, exports to PDF in one click, while the compliance export is separate: it comes out as JSON for all three, and only NIS2 renders to PDF today, since we have not yet added that variant for DORA and GDPR. Every scan is sealed by TESTIMONIUM with a Merkle tree and a signature, so you can check the seal publicly, without our database. The mission report PDF, the JSON compliance export for all three and the NIS2 PDF are SHIPPED, a PDF for DORA and GDPR is PLANNED (details in the Compliance chapter). You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Live view
KOKPIT in Battle Mode shows the running iteration and the mission heartbeat, and the organism's liveness, where each of the … components sits under the I-9 invariant, is what you see on Organism and Status. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Frequent questions
How do I start my first mission? You ask for a MENS mission in the CYRBER chat window and give the target, for example a server address. CYRBER shows the target and the mode, and the mission starts only after your YES. The target must fall inside the scope set in your organization's LEX policy, otherwise LEX refuses it. An operator or an administrator may order a mission. The button on the Missions page starts an OpenVAS scan separately. MAMY You can check it in the code: modules/capabilities/missions.py
What happens after a mission ends? When a mission ends, CYRBER runs a chain of steps by itself. It seals the findings in TESTIMONIUM, computes the SPECULUM genome, records an UMBRA snapshot, writes a narrative of the mission, recalculates the risk score, refreshes the ANNALES forecast and proposes fixes. You see the result on the mission page (Missions, then the mission), and you download the PDF report under Reports. MAMY You can check it in the code: modules/mind_agent.py
What is the consent register for? The consent register (Consents page, /consents) lists every consent a mission needed: for which target, in which mode and who decided. A consent carries a one-time token valid for 24 hours. From the register you approve or revoke a consent, extend it by a day, resend the request, see its history and export the list to CSV. An administrator sees the consents of their own organization. MAMY You can check it in the code: backend/routers/consent.py
How does ANNALES work? ANNALES keeps the organization's risk history and forecasts how it will change. It refreshes the forecast every day at 04:45 UTC and marks it stale after each mission, so the next one takes the new findings into account. Every forecast later gets an accuracy score against what actually happened. The chart and the forecasts are on the ANNALES page (/annales). MAMY You can check it in the code: modules/annales.py
What is SPECULUM and what does the security genome show? SPECULUM turns mission results into the organization's security genome: seven dimensions on one radar. They are network exposure, patch management, authentication and access, application security, data protection, the human factor and the supply chain. Each mission adds its findings to the genome instead of overwriting it. You see the radar on the SPECULUM page (/speculum). MAMY You can check it in the code: modules/speculum.py
How do I download a mission PDF report? Reports live on the Reports page (/reports). You pick a finished mission and the report language (Polish or English), generate the report and download the file with the DOWNLOAD PDF button. The report carries your organization's branding. MAMY You can check it in the code: backend/routers/reports.py
How do I add a user? An organization administrator adds users under Administration (/admin), on the Users tab, with the + ADD USER button. You enter the account details and choose a role, which decides what the person sees and what they may do. MAMY You can check it in the code: static/admin.html
How does an operator differ from a client and the other roles? An operator does the work: orders missions, runs remediation, issues reports and handles consents. A client only looks. You assign the former client role today as VIEWER (findings and compliance, read-only), CEO (executive summary, risk and genome) or AUDITOR (compliance and verification, read-only). None of these three roles starts a mission or a fix. MAMY You can check it in the code: backend/roles.py
Why is a mission paused and waiting for approval? In operator-approval mode a mission stops before a step that needs your decision. You approve or reject it in the CYRBER chat window or in the messenger. After 20 minutes without a decision a warning arrives, then reminders every two hours. The mission waits for you and does not move on by itself. A top-level step left without a decision for 24 hours ends the mission. MAMY You can check it in the code: modules/tasks.py
What does the Verify page check? Verify (/verify) checks whether an e-mail address, a website or a company (also by its Polish tax ID, NIP) is a fraud. You enter the query, CYRBER recognizes its type and returns an assessment with its reasons. Earlier checks stay in the history on the same page. A mission seal is checked separately, in the Public verification chapter. MAMY You can check it in the code: modules/verify.py
How do I connect Matrix and talk to CYRBER in the messenger? When an administrator adds you as a user and the installation has automatic accounts turned on, CYRBER creates your Matrix account under the same login and binds it to your app account. In Element or another Matrix client you pick your installation's server and sign in with the Sign in with CYRBER button. In the messenger you have the same permissions as in the app. The organization rooms (Alerts, Consents, Briefing) are created by an administrator in Settings, in the Matrix section, with the ENABLE CHANNELS button. In the Consents room you answer YES or NO to consent requests. MAMY You can check it in the code: modules/matrix_account_provision.py, modules/matrix_provision.py
The Verdict act of the Ritual chapter shows where the verdict is reached, and the Public verify chapter shows how to check the seal without our database.
API
Powierzchnię API dzielą trzy warstwy dostępu, z których każda ma inny próg zaufania i inne wymagania wobec tego, kto do niej puka.
Publiczne
/api/public/* nie wymaga uwierzytelnienia i ma otwarty CORS. Tu żyją status komponentów oraz dane, które CYRBER pokazuje na zewnątrz bez logowania. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
X-Proof-Key
/api/proof/verify/* i /api/proof/feed wymagają nagłówka X-Proof-Key, klucza wydawanego audytorom kanałem offline, a jest to ścieżka dla kogoś, kto ma sprawdzić dowód, a nie zarządzać kontem, przy czym pełny jej opis znajdziesz w rozdziale Public verify. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Bearer i cookie
Reszta API stoi za sesją operatora: ciasteczko HTTP-only jako pierwszy wybór, nagłówek Bearer jako zapasowy oraz klucz API (X-API-Key) dla integracji maszyna-maszyna. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Status publiczny
GET /api/public/status zwraca migawkę zdrowia ośmiu komponentów, złożoną w jeden wynik po najgorszym przypadku, i trzyma ją w cache 30 sekund, żeby nie dobijać się do bazy przy każdym odpytaniu. Ten sam status napędza status.cyrber.com. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
curl https://api.cyrber.com/api/public/status
Przykładowa odpowiedź. Przy schedulerze latency_ms to takt jego pętli bicia, nie czas odpowiedzi widziany przez użytkownika, więc wyższa wartość jest tu normalna.
{
"generated_at": "2026-07-18T09:12:00Z",
"overall": "operational",
"components": [
{"name": "api", "status": "operational"},
{"name": "database", "status": "operational", "latency_ms": 4.2},
{"name": "redis", "status": "operational", "latency_ms": 1.1},
{"name": "scheduler", "status": "operational", "latency_ms": 812.5},
{"name": "llm-router", "status": "operational"},
{"name": "glass-house-verify", "status": "operational"},
{"name": "matrix-bridge", "status": "operational"},
{"name": "jitsi", "status": "operational", "latency_ms": 210.4}
],
"incidents": [],
"maintenance": []
}
Reference
Interaktywny Swagger oraz surowy openapi.json pod generatory kodu klienta budują się z tras FastAPI, natomiast w trybie produkcyjnym wyłączamy je z rozmysłu, żeby nie wystawiać powierzchni na zewnątrz, dlatego publiczny api.cyrber.com/docs odpowiada dziś 404. Klient on-prem włącza je u siebie jedną zmienną środowiskową (CYRBER_ENV na wartość inną niż production), po czym /docs, /redoc i /openapi.json stają się dostępne w jego instancji. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
API
Three access tiers, each with its own trust threshold and its own demands on whoever knocks.
Public
/api/public/* needs no authentication and runs open CORS. Component status and anything CYRBER shows to the outside world without a login live here. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
X-Proof-Key
/api/proof/verify/* and /api/proof/feed require an X-Proof-Key header, a key handed to auditors through an offline channel. This tier is for someone checking a proof, not managing an account. Full detail sits in the Public verify chapter. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Bearer and cookie
Everything else runs behind an operator session: an HTTP-only cookie first, a Bearer header as fallback, and an API key (X-API-Key) for machine-to-machine integrations. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Public status
GET /api/public/status returns a health snapshot of eight components, rolled up to a single worst-case reading, and caches it for 30 seconds so a poll does not hit the database every time. The same status feeds status.cyrber.com. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
curl https://api.cyrber.com/api/public/status
Example response. For the scheduler, latency_ms is its beat-loop tick, not a user-facing response time, so a higher value there is normal.
{
"generated_at": "2026-07-18T09:12:00Z",
"overall": "operational",
"components": [
{"name": "api", "status": "operational"},
{"name": "database", "status": "operational", "latency_ms": 4.2},
{"name": "redis", "status": "operational", "latency_ms": 1.1},
{"name": "scheduler", "status": "operational", "latency_ms": 812.5},
{"name": "llm-router", "status": "operational"},
{"name": "glass-house-verify", "status": "operational"},
{"name": "matrix-bridge", "status": "operational"},
{"name": "jitsi", "status": "operational", "latency_ms": 210.4}
],
"incidents": [],
"maintenance": []
}
Reference
The interactive Swagger and a raw openapi.json for client codegen are built from the FastAPI routes, yet in production we disable them on purpose, to keep that surface off the public edge, which is why api.cyrber.com/docs answers 404 today. An on-prem customer turns them on with a single environment variable (CYRBER_ENV set to anything other than production), after which /docs, /redoc and /openapi.json become available in their own instance. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Public verify
Każde znalezisko jest hashowane, podpisane HMAC i zamknięte w drzewie Merkle na poziomie skanu. Root drzewa plus ścieżka Merkle wystarczą, żeby dowolna strona potwierdziła istnienie znaleziska w momencie skanu, bez wglądu w naszą bazę. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
1. Zdobądź klucz
Poproś o X-Proof-Key kanałem offline, nie mailem ani przez UI. To jeden współdzielony klucz, ten sam dla każdego audytora, nie osobne wydanie per audyt, i po dostarczeniu nie zależy od dostępności naszego serwera. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
2. Zbierz identyfikatory
Z raportu wypisz scan_id i finding_id znaleziska, które sprawdzasz.
3. Zapytaj i przelicz
curl -H "X-Proof-Key: $PROOF_KEY" \
https://api.cyrber.com/api/proof/verify/{scan_id}/{finding_id}
{
"valid": true,
"root_hash": "3f2b7a9e1c4d8f60b52e77a1d9c3f048e91a",
"finding_hash": "9c7d5e1a0b3f6428d715c9a02b8e4f01",
"verified_at": "2026-07-18T10:03:11Z"
}
Pole valid to wynik przeliczenia ścieżki Merkle po stronie serwera, nie gołosłowne twierdzenie: porównaj root_hash z rootem opublikowanym dla tego skanu na trust.cyrber.com i finding_hash z hashem znaleziska we własnym raporcie. Sama ścieżka Merkle użyta do przeliczenia nie wraca w tej odpowiedzi; kto ma dostęp operatorski do platformy, znajdzie ją przy znalezisku pod GET /api/proof/trees/{scan_id} (pole merkle_path w każdym liściu). MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Public verify
Every finding is hashed, HMAC-signed and closed inside a Merkle tree at scan level. The tree's root plus a Merkle path are enough for any party to confirm a finding existed at scan time, with no view into our database. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
1. Get a key
Ask for an X-Proof-Key through an offline channel, never email or the UI. It is one shared key, the same for every auditor, not issued fresh per audit, and once delivered it does not depend on our server being reachable. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
2. Collect the identifiers
From the report, pull scan_id and finding_id for the finding you are checking.
3. Query and recompute
curl -H "X-Proof-Key: $PROOF_KEY" \
https://api.cyrber.com/api/proof/verify/{scan_id}/{finding_id}
{
"valid": true,
"root_hash": "3f2b7a9e1c4d8f60b52e77a1d9c3f048e91a",
"finding_hash": "9c7d5e1a0b3f6428d715c9a02b8e4f01",
"verified_at": "2026-07-18T10:03:11Z"
}
The valid field is the result of the server walking the Merkle path, not an unsupported claim: check root_hash against the root published for that scan at trust.cyrber.com, and finding_hash against the finding's hash in your own report. The Merkle path used for that walk does not come back in this response; anyone with operator access to the platform finds it per finding at GET /api/proof/trees/{scan_id} (the merkle_path field on each leaf). SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Integracje
Po zamknięciu misji łańcuch hooków rozsyła znaleziska na zewnątrz, a konfiguracja tego rozsyłu żyje w panelu admin → Integrations, osobno dla każdej organizacji.
Kanały wychodzące
Matrix (czat w czasie rzeczywistym), webhook (POST JSON pod dowolny endpoint, w tym Slack, Teams czy Discord, z opcjonalnym podpisem HMAC), Jira (automatyczne zgłoszenie na znalezisko), GitLab (issue tracker), Wazuh (korelacja SIEM), Splunk (push HEC), QRadar (cele i CVE do reference setu, korelacja SOC), Energy SOAR (alerty do containmentu), MS Teams (powiadomienia), MISP i TheHive (threat intel, IOC), ELS (zewnętrzny strumień logów, syslog CEF oraz Elasticsearch). To dwanaście kanałów, którymi platforma wypycha znaleziska na zewnątrz. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Jeśli nie masz SIEM-a, CYRBER działa bez niego, a znaleziska dostajesz w raportach i kanałach wymienionych wyżej. Drogę od ataku do jego wykrycia w jednym zdarzeniu pokazujemy na demo Wazuha, a wdrożenie Wazuha u Ciebie jest osobną usługą, poza licencją.
Matrix
Pokoje tworzą jeden zestaw wspólny dla całej platformy, skonfigurowany zmiennymi środowiskowymi (Alerts, Admin, System, Incidents, Postulatum), przy czym nie zakładamy osobnego kompletu ani per organizacja, ani per poziom severity. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Jira i GitLab
Do trackera trafiają dziś wyłącznie znaleziska o severity CRITICAL oraz HIGH, ponieważ ten próg jest zaszyty w łańcuchu hooków po misji, a severity mapuje się na priorytet Jira wprost, gdzie dla CRITICAL zakładamy ticket o priorytecie Highest, a dla HIGH o priorytecie High. GitLab dostaje issue tą samą ścieżką, natomiast MEDIUM, LOW oraz INFO nie trafiają do trackera wcale. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Próg konfigurowalny osobno dla każdej organizacji, a więc wybór, od którego poziomu severity zakładamy ticket, DOŁOŻYMY. Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Integracje wejściowe
Rozsył znaleziska biegnie na zewnątrz, natomiast platforma przyjmuje też połączenia z drugiej strony, a każde z nich ma w panelu admina osobną zakładkę, niezależną od kanałów. Tożsamość wpinasz przez SSO/OIDC, gdzie logowanie prowadzi zewnętrzny dostawca, taki jak Okta, Microsoft Entra ID albo Google, a przepływ domyka standardowy OpenID Connect z weryfikacją podpisu tokena. Wywiad zasila Intel Sync, który zaciąga kanały zagrożeń z CISA KEV, NVD, FIRST EPSS oraz MITRE ATT&CK, a w trybie odciętym zastępujesz go pakietem wywiadu offline. Podatności celu dociągasz z Tenable.io, skąd platforma pobiera znane CVE hosta i wpuszcza je do rozumowania MENS na etapie OBSERVE, wzbogacając ocenę, zanim ruszą moduły skanujące. Dostęp maszyna do maszyny otwierasz kluczem API w nagłówku X-API-Key, obwarowanym zakresami uprawnień, przy czym tą samą bramą stoi serwer MCP, przez który zewnętrzny agent sięga po narzędzia platformy. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Silniki skanujące
Obok modułów, którymi MENS dysponuje w trakcie misji, CYRBER prowadzi też zewnętrzny silnik skanowania podatności Greenbone, znany szerzej jako OpenVAS, wpięty protokołem GMP do osobnego serwera skanera, a nie do jednego z kontenerów platformy. Reżim dzienny sam odpala głęboki skan każdego hosta, który mieści się w zakresie polityki LEX, raz na noc, nawet jeśli ten sam host ma w zakresie kilka organizacji; każda z nich dostaje własny wynik z tego jednego przebiegu. Skaner nie rusza sieci laboratorium platformy. Pełny skan hosta trwa zwykle kilka godzin, a ostatnie procenty postępu stoją długo, bo skaner domyka wtedy wolne testy; kokpit pokazuje taki skan w stopce jako skan w tle, z czasem trwania. Osobny cykl dociąga wynik, a raport ma dla niego własną sekcję i wlicza znaleziska do poziomu ryzyka na okładce. Gdy skaner nie dotrze do hosta, wynik brzmi „nie oceniono”, a nie „zero znalezisk”, więc cisza nie udaje czystego systemu. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Konfiguracja
Każdy kanał włączasz zmienną środowiskową albo wpisem na poziomie organizacji, który ląduje w bazie i wczytuje się dopiero w chwili rozsyłu, dzięki czemu pojedynczej integracji nie musisz przypłacać restartem całej platformy. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Integrations
Once a mission closes, the hook chain fans findings out to your stack. Configuration lives under admin → Integrations, per organization.
Outbound channels
Matrix (real-time chat), webhook (POST JSON to any endpoint, Slack, Teams or Discord included, with an optional HMAC signature), Jira (an issue per finding, automatic), GitLab (issue tracker), Wazuh (SIEM correlation), Splunk (HEC push), QRadar (targets and CVEs into a reference set, SOC correlation), Energy SOAR (containment alerts), MS Teams (notifications), MISP and TheHive (threat intel, IOCs), ELS (external log stream, syslog CEF and Elasticsearch). This is a set of twelve channels through which the platform pushes findings out. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
If you have no SIEM, CYRBER runs without one and findings reach you through the reports and the channels listed above. We show the path from an attack to its detection in a single event on our Wazuh demo, and deploying Wazuh on your side is a separate service, outside the licence.
Matrix
One room set, shared across the whole platform and configured through environment variables (Alerts, Admin, System, Incidents, Postulatum), not a separate set per organization or per severity level. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Jira and GitLab
Only CRITICAL and HIGH findings reach the tracker today, because that threshold is baked into the post-mission hook chain, and severity maps straight onto a Jira priority, where CRITICAL opens a Highest-priority ticket and HIGH a High one. GitLab gets an issue down the same path, while MEDIUM, LOW and INFO never reach the tracker at all. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Making the threshold configurable per organization, so you pick the severity level at which a ticket opens, is PLANNED. You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Inbound integrations
The finding fan-out runs outward, yet the platform also takes connections from the other side, and each of them has its own tab in the admin panel, separate from the channels. Identity plugs in through SSO/OIDC, where an external provider such as Okta, Microsoft Entra ID or Google drives the login and standard OpenID Connect closes the flow with token-signature verification. Intelligence is fed by Intel Sync, which pulls threat feeds from CISA KEV, NVD, FIRST EPSS and MITRE ATT&CK, and in the severed mode you replace it with an offline intelligence bundle. Target vulnerabilities come in from Tenable.io, from which the platform pulls the host’s known CVEs and feeds them into MENS reasoning at the OBSERVE stage, enriching the assessment before the scanning modules run. Machine-to-machine access opens with an API key in the X-API-Key header, fenced by permission scopes, and the same gate carries the MCP server, through which an external agent reaches the platform's tools. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Scanning engines
Beyond the modules MENS dispatches during a mission, CYRBER also drives an external Greenbone vulnerability scanner, known more widely as OpenVAS, wired over the GMP protocol to a separate scanner server rather than to one of the platform's own containers. A daily regimen launches a deep scan of every host that falls inside a LEX policy's scope, once a night, even when several organisations have the same host in scope; each of them gets its own result from that single run. The scanner leaves the platform's lab network alone. A full host scan usually takes a few hours, and the last few percent of progress stand still for a long time because the scanner is finishing its slow tests; the cockpit shows such a scan in its footer as a background scan, with its running time. A separate cycle pulls the result, and the report gives it a section of its own and counts its findings into the risk level on the cover. When the scanner cannot reach the host, the result reads "not assessed" rather than "zero findings", so silence does not pass for a clean system. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Configuration
Each channel turns on through an environment variable or an organization-level entry that lands in the database and loads only at dispatch time, so a single integration never costs you a full platform restart. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Compliance
TESTIMONIUM mapuje znaleziska na kontrole regulacyjne: coverage per wymóg, poziom ryzyka tam, gdzie kontrola nie jest spełniona, i luka do zamknięcia w naprawie. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Frameworki
NIS2 (art. 21 ust. 2), DORA (ryzyko ICT oraz rekordy autoryzacji TLPT), GDPR/RODO (środki techniczne i podsumowanie ochrony danych), ISO/IEC 27001:2022. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Eksport per misja
Endpoint zwraca wszystkie trzy frameworki naraz, nie jeden wybrany filtrem ?framework=: nie ma takiego parametru, ponieważ oceniamy misję jednym zapytaniem pod NIS2, DORA i GDPR równolegle. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
GET /api/proof/mission/4821/compliance
Przykładowa odpowiedź. Nazwa organizacji i wartości pokrycia są ilustracyjne, nie są benchmarkiem produktu ani realnym wynikiem klienta.
{
"organization": "Acme Sp. z o.o.",
"mission_id": 4821,
"overall_status": "PARTIALLY_COMPLIANT",
"frameworks": {
"NIS2": {
"overall_status": "PARTIALLY_COMPLIANT",
"risk_level": "MEDIUM",
"coverage_percentage": 62,
"requirements": {
"21_2_b": {
"name": "Obsługa incydentów",
"article": "Art. 21(2)(b)",
"status": "COVERED_WITH_FINDINGS",
"covering_modules": ["nuclei", "mens_loop"],
"high_critical_findings": 1
},
"21_2_e": {
"name": "Testowanie planów odzyskiwania",
"article": "Art. 21(2)(e)",
"status": "NOT_TESTED",
"covering_modules": [],
"high_critical_findings": 0
}
},
"summary": {"total_requirements": 9, "covered": 5, "covered_with_findings": 2, "not_tested": 4}
},
"DORA": {"overall_status": "PARTIALLY_COMPLIANT", "coverage_percentage": 55},
"GDPR": {"overall_status": "COMPLIANT", "coverage_percentage": 84}
},
"coverage_summary": {"NIS2": 62, "DORA": 55, "GDPR": 84}
}
Eksport per organizacja
/api/proof/export/{nis2|dora|gdpr}/{org_id} zwraca zagregowany JSON po wszystkich misjach organizacji dla każdego z trzech frameworków, natomiast wariant PDF renderuje WeasyPrint na razie tylko dla NIS2 (/api/proof/export/nis2/{org_id}/pdf), podczas gdy DORA i GDPR zostają przy JSON. Eksport JSON całej trójki oraz PDF dla NIS2 MAMY, a PDF dla DORA i GDPR DOŁOŻYMY. Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Eksport w otwartym standardzie OSCAL
CYRBER eksportuje dowód badania w otwartym standardzie NIST OSCAL 1.1.2, w dwóch modelach, przy czym pierwszy z nich, assessment-results, niesie wyniki badania, w którym każda obserwacja daje się zweryfikować względem korzenia Merkle danej misji, a drugi, plan-of-action-and-milestones, zbiera otwarte zadania naprawcze. Ponieważ dokument przechodzi walidację oficjalnym narzędziem oscal-cli instytutu NIST, nabywca wczytuje go wprost do własnego systemu GRC, nie pisząc ani nie utrzymując własnego tłumacza formatu, i właśnie dlatego oparcie się o standard branżowy jest dla odbiorcy wygodniejsze niż kolejny format zamknięty w jednym produkcie. Eksport OSCAL, zarówno dla pojedynczej misji (/api/proof/mission/{id}/oscal/assessment-results oraz /api/proof/mission/{id}/oscal/poam), jak i zbiorczo dla całej organizacji (parametr ?format=oscal na trasach eksportu), MAMY. Natywny push tego dokumentu do ServiceNow IRM (Table API i Attachment API, ten sam rekord przy ponownym wysłaniu) MAMY. Natywne REST API Eramba Enterprise DOŁOŻYMY. Poszczególne ustalenia wiążą się z konkretnymi artykułami regulacji przez mapowanie modułu skanującego, który je wykrył, na wymaganie NIS2, DORA lub RODO, dzięki czemu przeważająca część dowodu wskazuje wprost artykuł, którego dotyczy, natomiast jeżeli ustalenie pochodzi z modułu spoza mapy, trafia do dokumentu jako niezmapowane, co jest w jego treści widoczne wprost i świadomie nie jest maskowane, ponieważ dokument dowodowy nie może twierdzić więcej, niż zostało zbadane. Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Prawo, dane i samodoskonalenie
CYRBER ocenia odporność ludzi na socjotechnikę na podstawie zachowania w kontrolowanej kampanii, a nie cech osobistych. Ocena jest deterministyczna i liczona z tego samego materiału, bez zewnętrznego wejścia. Każde działanie wobec pracownika wymaga zgody organizacji i zatwierdzenia przed wysyłką, wynik służy doborowi szkolenia, nie decyzjom kadrowym, i nie jest podstawą zautomatyzowanej decyzji w rozumieniu art. 22 RODO. Administratorem danych pracowników pozostaje organizacja klienta.
Publiczny, zakotwiczony dowód to jednokierunkowy skrót kryptograficzny (korzeń Merkle, podpis Ed25519, kotwica OpenTimestamps), a nie treść ustaleń. Surowe ustalenia, które mogą zawierać dane osobowe, pozostają w bazie organizacji i podlegają usunięciu. Zakotwiczony skrót nie ujawnia treści i nie da się go odwrócić, więc realizacja prawa do usunięcia nie narusza łańcucha dowodowego.
Pętla samodoskonalenia proponuje zmiany, nie wprowadza ich sama. Wnioski trafiają do kolejki decyzyjnej FORUM i czekają na rozstrzygnięcie. System nie zmienia własnego kodu, promptów ani reguł bez tego kroku.
Licencja i dostęp do kodu: Business Source License 1.1, źródło dostępne do wglądu.
Compliance
TESTIMONIUM maps findings onto regulatory controls: coverage per requirement, a risk level wherever a control is not met, and a gap to close through remediation. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Frameworks
NIS2 (Art. 21(2)), DORA (ICT risk plus TLPT authorization records), GDPR (technical measures and a data protection summary), ISO/IEC 27001:2022. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Per-mission export
The endpoint returns all three frameworks at once, not one picked through a ?framework= filter: there is no such parameter, one call assesses the mission under NIS2, DORA and GDPR in parallel. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
GET /api/proof/mission/4821/compliance
Example response. The organisation name and coverage figures are illustrative, not a product benchmark or a real customer result.
{
"organization": "Acme Sp. z o.o.",
"mission_id": 4821,
"overall_status": "PARTIALLY_COMPLIANT",
"frameworks": {
"NIS2": {
"overall_status": "PARTIALLY_COMPLIANT",
"risk_level": "MEDIUM",
"coverage_percentage": 62,
"requirements": {
"21_2_b": {
"name": "Incident handling",
"article": "Art. 21(2)(b)",
"status": "COVERED_WITH_FINDINGS",
"covering_modules": ["nuclei", "mens_loop"],
"high_critical_findings": 1
},
"21_2_e": {
"name": "Recovery plan testing",
"article": "Art. 21(2)(e)",
"status": "NOT_TESTED",
"covering_modules": [],
"high_critical_findings": 0
}
},
"summary": {"total_requirements": 9, "covered": 5, "covered_with_findings": 2, "not_tested": 4}
},
"DORA": {"overall_status": "PARTIALLY_COMPLIANT", "coverage_percentage": 55},
"GDPR": {"overall_status": "COMPLIANT", "coverage_percentage": 84}
},
"coverage_summary": {"NIS2": 62, "DORA": 55, "GDPR": 84}
}
Per-org export
/api/proof/export/{nis2|dora|gdpr}/{org_id} returns aggregated JSON across every mission the organization ran, for each of the three frameworks, while the PDF variant renders through WeasyPrint for NIS2 alone for now (/api/proof/export/nis2/{org_id}/pdf), whereas DORA and GDPR stay JSON. The JSON export of all three and the NIS2 PDF are SHIPPED, a PDF for DORA and GDPR is PLANNED. You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Export in the open OSCAL standard
CYRBER exports its assessment evidence in the open NIST OSCAL 1.1.2 standard across two models, where the first one, assessment-results, carries the findings of the assessment in which every observation can be verified against the mission Merkle root, and the second one, plan-of-action-and-milestones, gathers the open remediation tasks. Because the document passes validation with the official NIST oscal-cli tool, a buyer loads it straight into their own GRC system without writing or maintaining a bespoke format translator, and that is precisely why relying on an industry standard is more convenient for the recipient than yet another format locked inside a single product. OSCAL export, both for a single mission (/api/proof/mission/{id}/oscal/assessment-results and /api/proof/mission/{id}/oscal/poam) and aggregated for the whole organization (the ?format=oscal parameter on the export routes), is SHIPPED. Native push of that document into ServiceNow IRM (Table API and Attachment API, the same record on a repeat send) is SHIPPED. A native Eramba Enterprise REST API is PLANNED. Individual findings tie to concrete regulatory articles through a mapping of the scanning module that surfaced them onto a NIS2, DORA or GDPR requirement, so the majority of the evidence points straight at the article it concerns, whereas a finding coming from a module outside the map enters the document as unmapped, which is shown plainly in its contents and is deliberately not masked, because an evidence document must never claim more than what was actually examined. You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Law, data and self-improvement
CYRBER assesses people's resilience to social engineering from behaviour in a controlled campaign, not from personal traits. The scoring is deterministic and computed from the same material, with no external input. Every action toward an employee requires the organisation's consent and approval before it is sent, the result guides training rather than HR decisions, and it is not a basis for an automated decision within the meaning of Article 22 GDPR. The controller of employee data remains the client organisation.
The public, anchored proof is a one-way cryptographic digest (a Merkle root, an Ed25519 signature, an OpenTimestamps anchor), not the content of the findings. Raw findings, which may contain personal data, stay in the organisation's database and can be erased. The anchored digest reveals nothing and cannot be reversed, so honouring the right to erasure does not break the evidence chain.
The self-improvement loop proposes changes, it does not apply them on its own. Proposals land in the FORUM decision queue and wait for a ruling. The system does not change its own code, prompts or rules without that step.
Licence and access to the code: Business Source License 1.1, source available for inspection.
Incident response
Przy znalezisku o poziomie CRITICAL lub HIGH system wysyła zdarzenie do zewnętrznego SIEM-a automatycznie, przez webhook, bez czekania na operatora. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Payload
{
"source": "CYRBER",
"event_type": "finding_detected",
"title": "Finding Detected",
"color": "#ff4444",
"timestamp": "2026-07-18T10:15:00Z",
"payload": {
"severity": "CRITICAL",
"target": "10.0.0.5",
"finding": "SQL Injection",
"cve_id": "CVE-2024-1234",
"organization_id": 1,
"mission_id": "m-4821",
"message": "Parametr id podatny na wstrzyknięcie SQL"
}
}
Podpis
Każde zdarzenie niesie nagłówek X-CYRBER-Signature, HMAC-SHA256 nad surowym ciałem payloadu, liczony współdzielonym sekretem ustalonym z góry przy konfiguracji webhooka. SOC weryfikuje go offline: liczy ten sam HMAC-SHA256 nad otrzymanym ciałem tym samym sekretem i porównuje wynik z nagłówkiem, bez odpytywania naszego API. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Korelacja i air-gap
Operator SOC koreluje event z własnym logiem po polach payloadu, przede wszystkim po mission_id oraz target, a sam podpis HMAC sprawdza offline współdzielonym sekretem, bez żadnego wywołania do CYRBER. Pełny dowód Merkle danego znaleziska weryfikuje osobno, ścieżką z rozdziału Public verify, czyli przeliczeniem hasha i drogi Merkle pod kluczem X-Proof-Key, również bez kontaktu z naszym API, więc cały krok domyka się bez dostępu do sieci. Weryfikację podpisu oraz dowód Merkle offline MAMY, a wzbogacenie samego eventu o gotowy verify_url i merkle_root, żeby SOC nie sięgał po nie osobno, DOŁOŻYMY. Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Incident response
A CRITICAL or HIGH finding sends an event to the external SIEM on its own, over a webhook, with no operator needed to trigger it. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Payload
{
"source": "CYRBER",
"event_type": "finding_detected",
"title": "Finding Detected",
"color": "#ff4444",
"timestamp": "2026-07-18T10:15:00Z",
"payload": {
"severity": "CRITICAL",
"target": "10.0.0.5",
"finding": "SQL Injection",
"cve_id": "CVE-2024-1234",
"organization_id": 1,
"mission_id": "m-4821",
"message": "id parameter vulnerable to SQL injection"
}
}
Signature
Every event carries an X-CYRBER-Signature header, an HMAC-SHA256 over the raw payload body, computed with a shared secret agreed when the webhook was configured. The SOC verifies it offline, computing the same HMAC-SHA256 over the received body with that same secret and compare it against the header, no call back to our API required. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Correlation and air-gap
The SOC operator correlates the event against their own log by the payload fields, chiefly mission_id and target, and checks the HMAC signature offline with the shared secret, with no call to CYRBER at all. They verify the full Merkle proof of a finding separately, by the path in the Public verify chapter, recomputing the hash and the Merkle walk under an X-Proof-Key, again with no contact with our API, so the whole step closes off the network. Verifying the signature and the offline Merkle proof are SHIPPED, while enriching the event itself with a ready verify_url and merkle_root, so the SOC need not fetch them separately, is PLANNED. You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Suwerenność
Suwerenność w CYRBER znaczy, że platforma, dane oraz dowód zostają po Twojej stronie, a nie po naszej. Dostajesz maszynę dowodową, której nikt z zewnątrz nie odtworzy bez jednoczesnego złożenia silnika eksploatacji, zamknięcia detekcji na własnym SIEM-ie oraz zbudowania łańcucha dowodowego uszytego pod Twoją regulację. To rozdział, w którym jesteśmy najbardziej szczerzy w całym dokumencie, bo część tej obietnicy jest już faktem, a część dopiero planem.
On-prem
Platforma stoi u klienta, a dane i przebieg misji zostają na jego infrastrukturze, my zaś nie trzymamy żadnej kopii, ponieważ deployment on-prem działa już dziś. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Komunikacja i wideo bez trzeciej strony
Suwerenność nie kończy się na danych, bo dotyczy również tego, jak się komunikujesz. Szyfrowany serwer Matrix, czyli Synapse z klientem Element, oraz wideorozmowa przez Jitsi stoją jako osobne stosy obok rdzenia CYRBER, na tym samym metalu, dokładnie tak, jak chodzą dziś w naszej własnej produkcji pod adresami meet.cyrber.com i matrix.cyrber.com. Rozmowa audio i wideo prowadzona wprost w pokoju Matrix idzie przez własny serwer mediów, szyfrowana end-to-end, więc poza mury nie wychodzi ani treść wiadomości, ani głos.
Te dwie drogi dzieli warunek tożsamości i stąd bierze się podział ról. Jitsi obsługuje każdego, kto dostanie link, bez konta i bez rejestracji, więc prowadzisz na nim demo albo umówione spotkanie z kimś z zewnątrz. Rozmowa w Matriksie wymaga konta na Twoim serwerze, dlatego odwiedzający stronę może napisać, ale nie zadzwoni, za to ludzie pracujący już w danym pokoju rozmawiają tam, gdzie leży historia sprawy. Alert z platformy trafia na Twój serwer Matrix, a media płyną przez Twoją maszynę, więc nawet warstwa łączności zostaje bez pośrednika i bez cudzej chmury. Są to stosy towarzyszące rdzeniowi, a nie część instalatora jednego polecenia, i tak je opisujemy, żeby nie obiecać wygody, której jeszcze nie ma. Samodzielny serwer Matrix, rozmowy audio i wideo w jego pokojach oraz wideo Jitsi MAMY, a ich złożenie w jeden instalator DOŁOŻYMY. Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Lokalny model
Chcemy, żeby całe rozumowanie zostawało w murach klienta, i choć routing air-gap oraz lokalna Ollama są już przygotowane w kodzie, domyślnym trybem pozostaje dziś chmura, a GPU chodzi jako osobny overlay (compose gpu-nvidia/gpu-amd), przy czym produkcja to dziś CPU-VPS bez VRAM, więc instalacja istnieje, lecz prąd jeszcze przez nią nie płynie. Dopóki tak pozostaje, nie napiszemy, że rozumowanie nie wychodzi na zewnątrz, a przełączenie na model lokalny domykamy, zanim uruchomisz CYRBER produkcyjnie u siebie. DOŁOŻYMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Klucze u klienta
Klucz podpisujący pieczęcie jest dziś jeden na instancję, po stronie serwera. Żeby klient sam trzymał swój klucz i sam decydował o podpisie, dokładamy BYOK. DOŁOŻYMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Air-gap uczciwie
Teza „nic nie wychodzi” pęka w chwili, w której GUI pobiera cokolwiek z zewnętrznego CDN. Ta dokumentacja trzyma u siebie zasadę zero-CDN: żadnych fontów z sieci, żadnych bibliotek z zewnątrz, wszystko podane z serwera. Dla tej strony air-gap jest już faktem, natomiast dla całego produktu pozostaje warunkiem, który dopinamy powierzchnia po powierzchni. Z czterech wyjść danych opisanych w sekcji Sieć i egress wywiad, most alertów oraz kotwicę OpenTimestamps odcinasz już dziś, więc do pełnego air-gapu brakuje przede wszystkim lokalnego modelu rozumowania. Zero CDN na tej stronie MAMY. Air-gap całego produktu DOŁOŻYMY. Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Suwerenność jest właściwością, którą sprawdzisz sam. Dopóki rozumowanie idzie do chmury, nie napiszemy, że nic nie wychodzi, i właśnie dlatego przełączenie na model lokalny domykamy, zanim uruchomisz CYRBER produkcyjnie u siebie. Jak ten sam werdykt zweryfikujesz bez naszej bazy, pokazuje Glass House, a gdzie werdykt zapada w rytuale, opisuje akt Werdykt w rozdziale Rytuał.
Sovereignty
Sovereignty in CYRBER means the platform, the data and the proof stay on your side, not ours. You get a proof machine no outsider can reconstruct without building the exploitation engine, the detection close on the SIEM and the evidence chain all at once, tailored to your regulation. This is the chapter where we are most honest in the whole document, because part of that promise is already a fact and part is still a plan.
On-prem
The platform stands at the client's site. The data and the mission run stay on their infrastructure, and we keep no copy. On-prem deployment works today. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Comms and video with no third party
Sovereignty does not stop at the data, because it also covers how you communicate. An encrypted Matrix server, Synapse with the Element client, and video calls over Jitsi run as separate stacks beside the CYRBER core, on the same metal, exactly as they run in our own production today at meet.cyrber.com and matrix.cyrber.com. A call placed inside a Matrix room goes through your own media server, end-to-end encrypted, so neither the message nor the voice leaves your walls.
What separates the two routes is the question of identity, and that is where the division of labour comes from. Jitsi serves anyone who receives a link, with no account and no registration, which makes it the route for a demo or a booked call with an outsider. A call in Matrix requires an account on your server, so a visitor to your site can write but cannot ring, while the people already working in a room talk where the history of the case lives. An alert from the platform reaches your Matrix server, and the media flows through your machine, so even the connectivity layer stays free of intermediaries and outside clouds. These are companion stacks, not part of the one-command installer, and we describe them that way so as not to promise a convenience that is not there yet. A self-hosted Matrix server, audio and video calls inside its rooms and Jitsi video are SHIPPED, folding them into a single installer is PLANNED. You can check this yourself in a demonstration, in the public verifier, or on the trust site.
The local model
We want all of the reasoning to stay inside the client's walls. The air-gap routing and a local Ollama are prepared in the code, but the default mode today is the cloud, and the GPU runs as a separate overlay (gpu-nvidia/gpu-amd) while production is a CPU-VPS without VRAM. The wiring is in; the current is not flowing yet. As long as that holds, we will not write that the reasoning stays inside those walls. The cutover to a local model lands before you run CYRBER in production on your own site. PLANNED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Keys at the client
The key that signs the seals is, for now, one per instance, on the server side. For the client to hold their own key and own the signature, we add BYOK. PLANNED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Air-gap, honestly
The claim that nothing leaves breaks the moment the GUI pulls anything from an external CDN. This documentation keeps a zero-CDN rule of its own: no fonts from the network, no libraries from outside, everything served from the server. For this page, the air-gap is a fact. For the whole product it is a condition we are closing surface by surface. Of the four data exits described in the Network and egress section, you already sever the intelligence feed, the alert bridge and the OpenTimestamps anchor today, so what a full air-gap mainly still needs is the local reasoning model. Zero CDN on this page is SHIPPED. A whole-product air-gap is PLANNED. You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Sovereignty is not a slogan but a property you can check yourself. As long as the reasoning goes to the cloud we will not write that nothing leaves, which is why the cutover to a local model lands before you run CYRBER in production on your own site. The Glass House chapter shows how you check the same verdict without our database, and the Verdict act of the Ritual chapter shows where the verdict is reached.
Zaufanie i bezpieczeństwo
Nie musisz nam wierzyć na słowo, ponieważ każdą gwarancję poniżej pokazujemy tam, gdzie mieszka w kodzie, a tam, gdzie coś jest jeszcze przed nami, mówimy to wprost znacznikiem DOŁOŻYMY, zamiast to chować. Kliknij „udowodnij” przy dowolnym znaczniku MAMY, żeby zobaczyć ścieżkę, którą sam zweryfikujesz.
Sondy brzegowe uwierzytelniają się podpisem, nie zaufaniem. Sonda łączy się podpisem HMAC na osobnym sekrecie, ze znacznikiem czasu i porównaniem stałoczasowym, a sonda związana z własnym kluczem odrzuca zejście na współdzielony sekret, więc skradziony sekret nie podszyje się pod cudzą sondę. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Klucz nie zaleje wrażliwych tras. Trasy wrażliwe, jak zlecanie działań ofensywnych czy pobieranie raportów, mają limit tempa liczony per adres, więc skradziony klucz nie zamieni się tam w zalew żądań, a globalny limit domyślny obowiązuje na każdym wejściu API. Limit na trasach wrażliwych MAMY, globalny limit domyślny MAMY. Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Jedna organizacja nie sięgnie danych drugiej. Baza odmawia dostępu domyślnie i przepuszcza wyłącznie wiersze pasujące do organizacji z kontekstu, a wyjątek jest wpięty jedynie w sygnał przeduruchomieniowy zadania, więc izolacja trzyma nawet przy błędzie w warstwie wyżej. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Nic destrukcyjnego bez człowieka w pętli. Narzędzia ofensywne wymagają jawnej zgody, polityka LEX pilnuje zakresu, moratorium wygasza nadmiar postulatów, a krok o realnym skutku czeka na zatwierdzenie po stronie klienta, więc autonomia kończy się tam, gdzie zaczyna się decyzja o szkodzie. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Zostawiamy dowód, nie obietnicę. Każde znalezisko jest zahashowane, zamknięte w drzewie Merkle i zakotwiczone przez OpenTimestamps, przy czym kalendarz łączy tysiące hashy w jedną transakcję, więc koszt pojedynczego dowodu jest bliski zeru, na łańcuch trafia sam hash bez powiązania z organizacją, a dowód wstępny masz od ręki i domykasz go później. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Klucz podpisu nigdy nie leży w kodzie. Klucz Ed25519 jest wymagany ze zmiennej środowiskowej w produkcji i platforma odmawia startu bez niego, a osobne przechowanie w module sprzętowym oraz rotację klucza dokładamy. Klucz poza kodem MAMY, moduł sprzętowy i rotacja DOŁOŻYMY. Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Twoje dane wychodzą, kiedy chcesz. Dane mają politykę retencji i cykliczne czyszczenie, swoje znaleziska wyeksportujesz do CSV oraz JSON, a ślad audytu do CSV, więc zakończenie umowy nie zostawia niczego w zawieszeniu. MAMY Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Widać kto i co uruchomił. Każde wywołanie zdolności oraz zdarzenie uwierzytelnienia ląduje w audycie, a łańcuch audytu jest kryptograficzny, więc przebieg jest odtwarzalny; formalny dokument governance dostępu do produkcji dokładamy. Ślad audytu MAMY, dokument governance DOŁOŻYMY. Sprawdzisz to sam: w demonstracji, w publicznym weryfikatorze albo na stronie zaufania.
Trust & Security
You do not have to take our word, because every guarantee below is shown where it lives in the code, and wherever something is still ahead of us we say so plainly with a PLANNED badge rather than hide it. Click ‘prove it’ on any SHIPPED badge to see the path you verify yourself.
Edge probes authenticate with a signature, not with trust. A probe connects with an HMAC signature over a dedicated secret, with a timestamp and a constant-time comparison, and a key-bound probe refuses to fall back to the shared secret, so a stolen secret cannot impersonate another probe. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
A key cannot flood the sensitive routes. Sensitive routes, such as dispatching offensive actions or downloading reports, are rate limited per address, so a stolen key does not turn into a flood there, and a global default limit applies on every API entry. Rate limit on sensitive routes SHIPPED, global default limit SHIPPED. You can check this yourself in a demonstration, in the public verifier, or on the trust site.
One organization cannot reach another's data. The database denies access by default and passes only rows matching the organization from context, and the bypass is wired solely into a task's prerun signal, so isolation holds even on a bug in the layer above. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Nothing destructive without a human in the loop. Offensive tools require explicit consent, LEX policy holds the scope, a moratorium damps a surplus of proposals, and a step with real impact waits for client-side approval, so autonomy ends where the decision to cause harm begins. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
We leave proof, not a promise. Every finding is hashed, sealed in a Merkle tree and anchored through OpenTimestamps, and the calendar folds thousands of hashes into a single transaction, so the cost of one proof is near zero, only the hash reaches the chain with no link to the organization, and you hold a pending proof at once and upgrade it later. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
The signing key never lives in code. The Ed25519 key is required from an environment variable in production and the platform refuses to start without it, and separate storage in a hardware module plus key rotation is what we add next. Key out of code SHIPPED, hardware module and rotation PLANNED. You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Your data leaves when you want. Data has a retention policy and periodic cleanup, you export your findings to CSV and JSON and your audit trail to CSV, so ending the contract leaves nothing in limbo. SHIPPED You can check this yourself in a demonstration, in the public verifier, or on the trust site.
You see who ran what. Every capability call and authentication event lands in the audit, and the audit chain is cryptographic, so the run is replayable; a formal production-access governance document is what we add next. Audit trail SHIPPED, governance document PLANNED. You can check this yourself in a demonstration, in the public verifier, or on the trust site.
Release notes
Pełna, bieżąca historia zmian żyje na cyrber.com/zmiany. Ta sekcja odsyła tam celowo: release notes trzymamy poza tym dokumentem, żeby proza tutaj nie starzała się przy każdym wydaniu.
Release notes
The full, current change history lives at cyrber.com/zmiany. This section points there on purpose: we keep release notes outside this document so the prose here does not go stale with every release.