The triage agent records the detections, enrichment sources, and asset context it consulted, together with the detection logic version in force.
Verifiable AI for cybersecurity.
Threat intelligence that compounds across agents.
Security teams run a growing fleet of detection and response agents, yet threat reasoning stays trapped in single-vendor SIEMs and siloed threat databases. nOS records detection rationale, escalation paths, and cross-team response decisions as shared, replayable traces, so intelligence compounds across agents instead of being re-derived. Every decision is independently verifiable, giving auditors and downstream teams a trustworthy record without vendor lock-in.
What gets captured
Shared & Verifiable
Working memory captures private agent reasoning. Shared memory is where multi-party context coordinates. Verifiable memory is where decisions are enshrined.
Security teams across regulated industries
Real enterprise data, processed in production, with decision traces enshrined as Knowledge Assets in the OriginTrail DKG.
Powering Umanitek’s Guardian internet safety agents.
The case for verifiable decisions in cybersecurity.
Security operations already run on machine speed. Agents triage alerts, enrich indicators, and increasingly take containment actions. What they do not produce is a defensible record of judgement: which signals were weighed, which were dismissed, and on whose authority a host was isolated at 03:00.
That gap becomes expensive under NIS2 and DORA, where incident reporting runs to fixed deadlines and supervisors ask how a classification was reached. It is also why threat intelligence rarely compounds: each vendor platform holds its own context, so the fiftieth investigation starts almost where the first one did.
How a decision becomes verifiable.
Threat context that peers or a sector CERT are entitled to see moves into shared memory, so intelligence accumulates across teams instead of per vendor.
Containment and escalation decisions record the reasoning: severity rationale, the exception that permitted an out-of-hours action, and the precedent from similar incidents.
The trace is enshrined in the DKG, giving auditors and regulators an independently verifiable account of how the incident was handled.
What this changes in practice.
The operational change is that judgement becomes an asset rather than a byproduct. Today an analyst decision lives in a ticket comment and evaporates when the ticket closes. Captured as a trace, it becomes precedent the next investigation inherits, which is what makes a security program improve rather than merely repeat.
For leadership the change is evidentiary. When a supervisor or board asks why an incident was classified as it was, the answer is retrieved rather than reconstructed, and it holds up because it was recorded at the moment of the decision by the system that made it.
Questions about cybersecurity.
Does nOS replace our SIEM or EDR?
How does this help with NIS2 or DORA reporting?
Can we share threat intelligence without exposing our environment?
What stops an agent from acting outside policy?
Does this slow down response?
How does this help a new analyst?
Power up your business with the OriginTrail DKG.
Create Knowledge Assets, build shared context graphs, enshrine decision traces. Open-source infrastructure. Community support. Zero cost.
The full Network Operating System.
Custom agent frameworks (Hermes, OpenClaw, LangChain, Claude). Custom data pipelines. Custom integrations with your enterprise systems. Dedicated infrastructure and support.