Sovereign by default·Federated by policy·Audited by design

Defend the mission
inside the boundary.

Kybernao runs on your site, under your authority, with or without a link. You decide where it runs, what it may touch, who can act, and what, if anything, ever leaves.

0cloud dependenciesEvery engine runs on the node
3execution levelsObserve, Twin, Live. Operator-gated
4node form factorsBackpack, DIN rail, rack, rugged
1audit ledgerWritten on the node, streamed on your terms

Built for the people who sign the authorization.

Identity, sovereignty, audit, and evidence are properties of the node, not features of a vendor cloud. Your ISSO, your assessor, and your mission owner get the same answer from the same source.

Sign-in and roles

CAC/PIV, Entra ID, or Okta sign-in. Roles decide who may view the graph, approve a containment plan, or raise an execution level, and every decision is attributed to a person.

SAML 2.0 · OIDC · SCIM

Data sovereignty

The graph, findings, telemetry, and models never leave the node unless you say so. Federation is store-and-forward, scoped to the state you allow, and reversible with a purge.

Per-site retention · Purge on demand

Signed ledger

Every run, finding, approval, containment action, and login is written to the node's ledger first. Stream to your SIEM when a link exists. Keep it inside when it does not.

Splunk · Sentinel · Elastic

ATO
evidence

Findings, retests, and audit events export as an evidence package mapped to NIST SP 800-53 and 800-82, in the shape your assessors already work from.

RMF · ATO · CMMC

Decide where the node lives.

A connected site with optional federation, or fully disconnected at the tactical edge. Same brain, same controls, same evidence.

Site NODE-RNODE-I

The full platform inside your datacenter, plant, or substation. It operates alone and federates to Kybernao Cloud only on the schedule and scope you set.

  • NODE-R for datacenter and enterprise coordination
  • NODE-I for passive industrial and OT visibility
  • Local cyber-physical graph and data lake
  • Optional Kybernao Cloud federation
Edge (disconnected)NODE-SNODE-X

The same platform in a backpack or a vehicle. It keeps mapping, testing, and defending through denied, degraded, and intermittent links, with nothing waiting on a cloud.

  • NODE-S and NODE-X for tactical and expeditionary use
  • Red, Sentinel, and Guardian run entirely on the node
  • Store-and-forward operation under D-DIL
  • Operates entirely inside your boundary

For the systems a mission, a city or a grid cannot lose.

One terrain graph for defense missions, public utilities, and civilian agencies, from cloud identity to the physical process it can reach.

Kybernao Edge puts the whole platform in a vehicle, a forward position, or a backpack. It keeps mapping, testing, and defending through denied, degraded, and intermittent links, and shares only what you choose when a link returns.

  • Red, Sentinel, and Guardian run on NODE-S and NODE-X with no reach-back.
  • Radios, C2, vehicles, and sensors sit in the same terrain graph as identity and cloud.
  • FedSpace exchanges only the findings and state you authorize, across sovereign nodes.
NODE-X · fwd-site-07DEFENSEGRAPH · 11 ASSETSLINK · SATCOM LOST · LOCAL

From one node to a program of record.

Start with one site or mission. Prove the paths that matter. Scale to a fleet of sovereign nodes with a mission engineer who stays with the program.

  1. Week 1Pilot

    One node on site. Terrain graph built from your own environment. First path walked to its physical consequence.

    NODE-R or NODE-X · 1 site
  2. Month 1Validate

    Red proves paths in the twin, then under Level 2 controls where you authorize it. Sentinel measures. Guardian holds containment.

    7 paths · retests attached
  3. Quarter 1Program

    A fleet of nodes federating through FedSpace, with evidence flowing into your authorization package on every cycle.

    Fleet · FedSpace · ATO evidence

Operate inside the
mission stack.

Every node exposes findings, assets, plans, and audit events through a local API that works when the WAN does not. Evidence reaches the tools your operators already watch, under the identifiers they already use.

Node audit log

  1. Path reproduced · 27m ago
  2. Plan opened · 16m ago
  3. Retest running …
  4. KYB-004Unsigned Modbus write path reaches cooling PLC-07
  5. KYB-018Historian API exposes controller tags without auth
  6. KYB-021CI runner token grants OT jump-host access

SIEM and ticketing

Stream every run, finding, approval, and containment event to Splunk, Microsoft Sentinel, Elastic, or ServiceNow when a link exists. Queue them when it does not.

Operational picture

Surface validated paths and their physical consequence in the C2 or operations console your operators already use, with the same identifiers as the node.

Retest window · 21:00

3/3vectors
0:14duration
Passresult
MTWTFSSMTWTFS

Local API on every node

Build operator tooling against the node itself with scoped API keys or your identity provider's access tokens. No cloud round-trip.

CAC/PIV and SSO

SAML 2.0 or OIDC through Entra ID or Okta, with smart-card sign-in where policy requires it.

Scoped API keys

Machine-to-machine access for automation and internal tools, scoped per site and per role.

Operator views

Use Kybernao Command, or put findings and retests into the dashboard or ticketing system your team already runs.

Nothing moves without a named operator.

Governance is built into the node, not bolted on. Each control below writes its own audit record.

SSO, CAC/PIV, and SCIM

Sign in with CAC/PIV, or federate Entra ID or Okta over SAML 2.0 or OIDC. Directory changes flow in through SCIM, so a departure revokes access the same day.

Ledger and SIEM forwarding

Every run, finding, approval, containment action, and material state change is recorded on the node and can be streamed to Splunk, Sentinel, or Elastic.

Execution levels

Observe, Twin, and Live. Nothing runs against a live process without an operator raising the level, and every raise is logged.

Encryption and root of trust

Secure boot and a hardware root of trust on every node. Data encrypted at rest and in transit, with keys that never leave the site.

Retention and purge

Each site keeps data for as long as you set, and you can wipe it at any time. Federate only the state you allow.

Evidence ready for the people who review it.

RMF and ATO evidence

Findings, retests, and audit events organized for RMF and ATO packages, with the evidence your ISSO and assessors need.

Framework crosswalk

Every finding carries the control IDs your assessors test against, from NIST SP 800-53 to program overlays.

Acquisition

Pilot, evaluation, and program pathways. Which vehicles apply depends on the program, and we will tell you which ones do.

EVIDENCE PACKAGEpower-site-03 · ATO cycle 2026-Q314 artifacts
  1. Terrain graph snapshotgraph.json · 2.1 MB
  2. Validated attack paths7 paths · twin + live
  3. Retest logs3 runs · all closed
  4. Containment approvals2 · attributed
  5. Audit ledger exportsigned · 90 days
  6. Control crosswalkSP 800-53 r5 · 800-82
SHA-256 · a91f…c4e2Ready for assessor
RMF / ATOEvidence packages for the AO
NIST SP 800-53 · 800-82Control crosswalk
  • CMMCPractice mapping
  • FedRAMPEvidence packages · program-specific
  • NERC CIPRequirement crosswalk
  • IEC 62443Zone and conduit mapping
  • CJISRequirement crosswalk
  • DFARS 7012Requirement crosswalk
  • ITAR / EARExport handling review
  • OTA / SBIRPathway support · program-specific
  • Shared contract vehiclesGuidance on eligibility
  • DPA / MSAAgreement support

Kybernao provides evidence and mappings. Authorization decisions remain with your program and its authorizing official.

Evidence flows to the mission systems you already run.

Proven routes open tickets in the queues your watch floor already monitors.

  • Microsoft Entra IDEntra ID
  • OktaOkta
  • Amazon Web ServicesAWS
  • Microsoft AzureAzure
  • GitHubGitHub
  • KubernetesKubernetes
  • SiemensSiemens
  • SplunkSplunk
  • Sentinel
  • ServiceNowServiceNow
  • PalantirPalantir
  • CrowdStrikeCrowdStrike
  • STIX/TAXIISTIX/TAXII
INPUTS · IDENTITY, CLOUD, CODE, OTOUTPUTS · SIEM, C2, TICKETS, INTEL

Frequently asked questions

Can Kybernao run with no connection to the internet or a vendor cloud?

Yes. Every node runs the terrain graph, Red, Sentinel, Guardian, and Command locally. Federation through FedSpace is optional and store-and-forward, so a node never depends on it. Air-gapped sites are a supported configuration.

Who has to sign before Red touches a live system?

Nothing touches a live process at Level 0 (Observe) or Level 1 (Twin). Raising to Level 2 (Live) requires an operator with the right role to approve the specific path, and the approval is recorded in the audit log. Safety-critical assets can be excluded from Live entirely by policy.

Where does our data live, and who can see it?

On the node, inside your boundary. Kybernao staff have no standing access. If you enable federation, you choose which state leaves the site. Retention is configurable per site and data can be purged on demand.

How does Kybernao support RMF and ATO work?

Findings, retests, containment actions, and audit events are exported as evidence with control mappings to NIST SP 800-53 and 800-82. Your ISSO and assessors work from that package. Authorization decisions remain with your program and authorizing official.

Can operators sign in with CAC/PIV?

Yes, through your identity provider using SAML 2.0 or OIDC, with smart-card authentication where your policy requires it. Roles decide who can view the graph, approve plans, or raise execution levels.

Which hardware do we deploy for a tactical mission versus a plant?

NODE-S and NODE-X for tactical and expeditionary use, NODE-I for industrial and OT sites, NODE-R for datacenters and program coordination. All four run the same platform and federate with each other.

How can an agency buy Kybernao?

Pilot and evaluation engagements are available directly. Program pathways including OTA, SBIR, and cooperative purchasing depend on the program, and we will tell you plainly what applies to yours.

See your own terrain graph in 30 minutes.

Bring one site or mission. We build the graph from your environment, walk the first path to its consequence, and leave you the evidence.

Site design sessions open

Request a Kybernao demo

Tell us a little about your environment. A Kybernao engineer will follow up to arrange a focused walkthrough.

  • 01Focused architecture walkthrough
  • 02Mapped to your mission environment
  • 03Led by a Kybernao engineer
SECURE INTAKE→ENGINEERING
01Contact coordinatesRequired fields
02Mission profileFor a focused session

By submitting, you agree that Kybernao may contact you about this request.