Above the tools you already own. Across six domains that have never resolved to one asset, and into the seams between them, where exposure accumulates and nothing you own is looking.
Producing a decision fast enough to matter, with an owner, a clock and an evidence chain attached.
Six domains resolved onto one asset. The space between your tools stops being nobody's job.
The clock runs to when a named person acts, not to when an alert fires.
Right asset, causes counted once, coverage disclosed, every signal still attached to its source.
One night at an installation. Every system does exactly what it was bought to do.
Counter-UAS console logs the track.
LoggedThe SOC opens a ticket.
Ticket openedAccess control flags it.
Morning reviewEach tool did its job. Three consoles, three teams, three queues. The pattern only exists across them, which is exactly where no one is looking.
Any one of these is available somewhere in the market. The combination is not, because the first makes the other two harder and the second and third are normally a tradeoff.
Between domains. Between organizations. Between authorities.
Every tool you own looks down a single column and reports faithfully on it. Nothing looks across. Exposure accumulates in the space between them. So does opportunity, which is why an adversary works a seam on purpose and an accident finds one by chance.
Seams have no owner, no budget line and no dashboard. That is the definition of a seam.
Measured to the decision, not to the alert.
The clock that matters starts when the signal exists and stops when a person with authority acts on it. Everything in between (assembly, translation, reconciliation, the meeting to agree whose problem it is) is the part nobody measures and the part that consumes the window.
Alerting got faster for twenty years. The decision did not.
The call reflects what is actually true.
The right asset, not a similar name in another system. Causes counted once, not the same storm entered twice under two labels. Coverage disclosed rather than implied. Confidence stated. Every contributing signal still attached to where it came from.
A confident wrong answer is worse than no answer in an environment like yours.
Speed and rigor only trade against each other when the case for a decision is assembled by hand, after the fact.
AETHOS builds the case as the situation develops: signals bound to assets as they arrive, provenance carried rather than flattened, the convergence set and its independence question posed before the object scores. So the call arrives inside the window with its defense already attached, instead of arriving fast and acquiring a defense later, or arriving defensible and late.
That is the whole design. Everything below is how it is done.
Every layer of your stack has an owner. The decision does not.
Detection has an owner. Monitoring has an owner. Response has an owner. The moment where all of it has to become one accountable call belongs to nobody, and no product in your stack was built for it. That layer is what AETHOS is.
Same inputs, same policy version, same output. The arithmetic is deterministic and reproducible. Provable on demand by your engineer, not ours.
It ranks by the priorities you ratified at onboarding. Disagreement with an output is a policy input, not an error, and changing it is a logged act with a name on it.
Every decision carries its evidence chain (its convergence set, its window, its named owner), traceable to source, time and originator.
No system can tell you which of six live situations matters most to your mission. Two good analysts will rank them differently, and both can be right. AETHOS does not pretend otherwise. It puts the whole picture, the owner and the clock in front of the person who has to decide.
Then it keeps score: every call, what happened next, and how often its confidence held up. Over time that record shows you, in your own data, how good your decisions are getting.
You have invested heavily in tools and in people. Leaders still operate from an incomplete picture, because the data was never built to resolve against a common asset, and the people reconciling it by hand are the bottleneck the architecture created.
Your most expensive people spend disproportionate time gathering context rather than applying judgment to it. Bandwidth consumed reconciling four systems is bandwidth not spent on the call those people are actually paid to make.
The path from a significant event to an executive decision runs through assembly by hand, across systems that share no schema, no asset name and no confidence convention. That path has a floor, and it is not set by how fast your people work.
Convergent exposure (where a cyber event, a physical incident and a geopolitical shift act on the same asset) is invisible to every single-domain system you own. It becomes visible in the after-action review, which is the one place it is worth nothing.
Seeing the intersection no single-domain tool can see, turning it into a decision with an owner and a clock, and leaving a record that survives the review.
Six domains arrive in different formats, on different time bases, under different naming and different confidence conventions. AETHOS resolves all of them against one shared asset model. Convergence is what happens next.
AETHOS does not automate the decision. It delivers complete, traceable context to the person holding the authority, fast enough that the decision still matters when it is made, and it records who that person was.
Anyone can show you a number going up. The harder thing, and the thing that decides whether an output is usable in your environment, is proving where the number came from, who is accountable for the policy behind it, and that neither one moved without a human saying so.
Every decision teaches AETHOS something about your estate and your people. What it learns makes the next call sharper. What it never does is quietly change the rules it is judged by. When the learning says a rule should move, it proposes the change and a named person signs it.
Where independence cannot be determined it is filed as undetermined, with a reason. A named human promotes it, and the assertion is logged.
Criticality is inherited from the authoritative source or marked not assessed. It is never inferred by the engine.
A candidate pattern can raise a site’s posture (attention), and that contribution is disclosed with its state. Posture says look here. Only a ratified finding says decide this.
At the threat boundary AETHOS is advisory: detect, track, identify, hand off. It is never the effector.
Sources are added as adapters against a common ingest harness rather than as bespoke integrations, which is what makes a partially instrumented estate the normal case.
Every signal is bound to the asset it touches, and the asset to its facility and installation. Convergence is defined on a shared asset. Without resolution there is nothing to converge on.
Two or more independent causes on the same asset inside the same window are credited. Where independence is undetermined, the object does not score until a human says so.
The output is a decision object, not a view: ranked options, a named owner, a decision clock and the evidence chain behind it. It is committed, worked and resolved inside the record.
Every surface in AETHOS is either an input to a decision object or an action out of one. Nothing exists merely to be looked at.
The score ranks. The auditable decision is the product. Which is why provenance here is not metadata: a number that cannot answer where did you get that, when, and from whom has defended nothing.
Break any link and the chain does not degrade. It inverts. A confident wrong answer is worse than no answer in an environment like yours. So the score is a function of what is actually connected, and it says so on its face.
Every system in this market has a reason to count generously. More contributing causes, a bigger number, more urgency in the room. Here is what that costs you.
Two signals land on the same facility inside the same window. A storm front is degrading the power feed. A fuel delivery is stuck behind a closed corridor. The obvious move is to count both and let convergence carry the score up.
AETHOS does not count both until someone establishes that the two causes are independent. If that same front closed the corridor, that is one weather event counted twice, and the score collapses the first time anyone pulls on it.
So the question is answered before the object scores. That is a human call, made by a named person and recorded with the decision. When the answer is common cause, the credited set shrinks and the number comes down.
Same origin is not the same as common cause. Three thin signals around one site (unrest on the adjacent corridor, surveillance at the gate, interference on the approach routes) may share an actor without sharing a cause. Collapse those and the picture goes blind at exactly the moment a coordinated pattern is running.
What is hard to copy is not the arithmetic. It is the discipline about what is allowed to enter it, and the record proving a person made that call. Try it →
Blank slate is the assumption: any number of facilities, each with different characteristics and different feeds. Heterogeneous coverage is the normal case, not the exception.
Garrison to forward edge, CONUS and OCONUS, including fixed diplomatic posts, where physical, cyber, airspace and host-nation risk act on the same perimeter.
Where supply chain, OT security and geopolitical exposure converge on assets that cannot be taken offline to be protected.
Perimeter, power, cooling and cyber are one exposure surface, and the estate is measured in megawatts rather than buildings.
The most time-compressed decision environment there is, where airspace, physical security and crowd state have to read as one picture or not at all.
Operations across continents, where OT security, supplier status and geopolitical exposure land on the same production line.
Multi-agency, multi-jurisdiction and continuous, with airspace and landside security answering to different authorities.
Where a cyber event, a utility failure and a physical incident all resolve to patient safety on the same floor.
Systemically important, persistently targeted, and operating under the heaviest regulatory scrutiny of any sector.
An open community and a complex threat environment: protecting an institution without closing the openness that defines it.
Fragmented agencies, shared infrastructure, and no single authority holding the whole picture.
AETHOS consumes the systems you already own as feeds. It does not replace them and it does not ask them to change. Sources are added as adapters against a common harness rather than as bespoke integrations.
The scoring backbone. Deterministic, versioned, reproducible and disclosed: the score states the coverage it was computed on rather than implying a complete estate.
Binds every signal to the asset it touches, and the asset to its facility and installation. Convergence is defined here or it is not defined at all.
Normalizes structured and unstructured reporting into one threat picture, carrying each item's source, time and originator forward rather than flattening them away.
Built for bidirectional exchange with the surfaces already in use (TAK Server, ATAK and WinTAK among them): the fused picture out to the field, field reporting back into the record.
One harness, many adapters. A new source is a configuration exercise against a common contract rather than a bespoke integration project, which is what lets a partially instrumented estate onboard at all.
Decision objects delivered at the altitude of the authority that has to act, and committed, worked and resolved without waiting for a briefer to assemble it.
Connector families, by domain. Named as classes rather than products, because the harness is the claim. The connector set is built in customer sequence, against whatever you already run.
Assessment of threat landscape, decision path and operational readiness, with facilitated tabletop exercises that expose where a decision currently fails to get made.
Environment assessment, asset model build, feed integration, policy ratification and operational acceptance: onboarding an estate from empty, not configuring a fixture.
Continuous threat picture maintenance, recurring intelligence products, on-demand analysis and surge capacity against a defined estate.
Operator and analyst certification, tabletop facilitation, wargaming support and train-the-trainer programs built around the decision record.
Program management, integration engineering, compliance documentation and custom development for government and enterprise deployments.
What we publish, so your team can check it before you sign anything.
The scoring formula is published. Same inputs, same policy version, same output. Reproducible by your engineer, not ours.
A written statement of what we claim, what we do not, and the one claim that is not testable.
What is allowed to count as a converging cause, and why a human has to say so before it does.
What the machine never does, including deciding, acting, or changing its own rules.
Not a product demonstration. A working session on where a decision currently fails to get made in your environment, who owns it when it does, and what the record looks like afterward. Tailored, and conducted under NDA.
Sixty minutes for senior leadership. Threat landscape, organizational exposure, and the AETHOS claim stack applied to your environment, including what we do not claim.
For CTO, CISO and senior technical staff. Ingest harness against your existing stack, asset model, evidence chain, deployment and accreditation path. Bring your skeptic.
A representative convergence case worked end to end (resolution, independence call, decision object, record) in an environment that resembles yours.
All discussions under NDA. We will tell you in the first meeting which parts of the platform are built, which are specified, and which are neither.