Skip to content
SILEXSilex
01

The platform

A minimal executable model
of your agentic environment.

Its entities, its causal laws, its current state, and what your enterprise counts as a good outcome — enough to answer counterfactual questions about attack paths and policy changes without touching production. Executable: it rolls forward, which a diagram, a graph database and a CMDB do not. Minimal: it models only what can change a decision.

The ontology is the type system. The world model is the program. An ontology can describe, query and enumerate — it cannot roll forward. Intervention and counterfactual reasoning need causal laws and your own state on top.

02

Composition

Five layers,
named not numbered.

A world model is an ontology, plus dynamics over time, plus this enterprise’s instance, plus what counts as good here. Each layer has a job, and the fifth is what makes the whole thing falsifiable.

Schema

Security Ontology

The environment: agents, tools and APIs, data and assets, permissions, workflows, policies and controls, and business context — modeled together so paths through them can be reasoned over.
Laws

Causal Foundation

Causal mechanisms: how authority propagates, how taint flows, how sequence creates consequence. This is the layer that makes the model roll forward rather than merely describe.
World State

The runtime knowledge graph

Your instance: your agents, permission graph, tools, approval thresholds and traffic shape — reconstructed under uncertainty, with every element marked observed, inferred, or uncertain.
Objectives

Business Harness

What counts as a good outcome here: risk appetite, asset criticality, compliance regime, and tolerance for friction and cost. Causal reasoning predicts; objectives price.
Calibration

Self-Evolving Security Knowledge Base

Predicted against observed: where the other layers fit reality and where they do not. The record that accumulates, and the reason the model can be wrong in a way that improves it.

The Secure Agentic Harness sits outside the model. It governs the security agents themselves — least privilege, sandboxing, policy integrity, human approval, provenance, runtime monitoring, and rollback scoped to agent-side state, with a compensating-action recommendation for business effects. Folding it into the model would weaken exactly the governance story a security review tests.

03

The schema, internally

Four tiers over
one runtime graph.

A runtime graph surfaces only the routes present in the data. Inheritance and native security constraints let the tiers assert that a route is possible by type, with no traces behind it — and that is where the coverage claim comes from.

The bill is honest: every runtime observation has to be resolved to a type, and that grounding step is more engineering than ingesting a graph alone.

  1. L1

    General agent security ontology

    Ships from Silex

    Agent, user, identity, resource, tool, action, permission, trust, data, workflow, policy, control, outcome — and the attack patterns: prompt injection, privilege escalation, data exfiltration, tool misuse.

    Built once, rarely changes

  2. L2

    Domain security ontology

    Ships from Silex

    Per-vertical business semantics: finance's customer, account and transaction; healthcare's patient, doctor and medical record — each with its own permissions and constraints.

    Per vertical, deliberate

  3. L3

    Agentic-system ontology

    Ships from Silex

    The agent stack's own architecture: planner, memory, RAG, tools, MCP and APIs, sub-agents, workflow, credentials — and the trust and privilege boundaries a given stack creates.

    Per framework, fastest-moving

  4. L4

    Runtime knowledge graph

    Yours, in your environment

    This enterprise's concrete instances: actual agents, users, tools, resources and actions, with traces, tool calls, identity events, business events and state transitions.

    Continuous

We ship the types and the laws. The instances are yours. What we learn generalizes at the type tiers and reaches every deployment. No customer’s instance data ever moves.

04

Reconstruction

You will never have
complete observability.

Evidence is scattered across traces, OpenTelemetry, identity systems, ERP records, SaaS logs, policy engines, business events and external services — and a great deal of important business state is never instrumented at all. So the problem is not collecting more logs. It is recovering a trustworthy picture of operational reality from the evidence that exists, plus the ontology, historical state, and causal constraints.

Observability answers what did we see. Reconstruction answers given this evidence, what is the most likely state — and which parts are observed, which inferred, and which still uncertain.

Reconstruction is inference under uncertainty, and in security it is adversarially hard: a missing edge is often missing precisely because an attacker or a misconfiguration made it invisible. Every element of the state carries its origin, and that origin propagates to every finding computed from it.

05

Evidence grades

Declared. Latent.
Observed.

Three grades, never blurred. Each finding names the class and constraint that generated it, so you can dismiss it from your own knowledge — and a dismissal is useful to us, because it says where the ontology is wrong.

  1. Declared

    1

    Before the agent runs

    Asserted possible over an agent's configuration alone — tool manifest, permission scopes, sub-agent topology. Lowest confidence, highest leverage: nothing is deployed yet, so the fix costs least.

    No runtime product can produce this class.

  2. Latent

    2

    Deployed, never exercised

    Asserted possible by type over real instances: the classes, inherited permissions and constraints allow the route, with no trace behind it.

    A route nobody has walked is exactly the route nobody has tested.

  3. Observed

    3

    Exercised in production

    The route appears in your runtime graph. It has been taken, and the evidence is a real trace.

    What any graph-shaped product can also find.

The three form a lifecycle. A path first appears when an agent is defined, becomes latent when the agent is deployed, and becomes observed if the route is ever exercised. Each transition confirms the type-level reasoning was right — and each is cheaper to act on than the one after it.

Know what an agent can reach before it runs.

Because the tiers reason by type, an agent can be evaluated from its definition alone — before deployment, before any telemetry exists — in the CI you already run, on the pull request that introduced the path. Two things are always true of that result: it is declared-grade, describing what the configuration permits rather than what exists in a running system; and it is the front door to the runtime side rather than a replacement for it, because agents acquire capabilities no manifest declares.

It is not a linter, and it never returns a verdict that an agent is safe. The honest form is: no paths found under this version of the ontology, from this declaration.

06

Reasoning

Description is
the first rung.

A graph — however rich, however well typed — answers which paths exist. Deciding what to do needs two rungs above that, and those need a transition function and your own state.

  1. Association

    01

    Which attack paths exist?

    An ontology and data

  2. Intervention

    02

    What happens if we restrict the invoice API?

    Causal laws on top

    Where Silex works

  3. Counterfactual

    03

    Would this incident have happened under re-authentication?

    Causal laws and this enterprise's own state

    Where Silex works

Simulation calibrates the mechanism. Only observed production outcomes are proof. No policy reaches production from simulation alone — simulation, shadow against real traffic, canary at limited scope, then production, with rollback preserved at every stage.

Replay fidelity is bounded, and we will say where. Hosted-model non-determinism, tool side effects, and time-dependent state all cap how faithfully a given agent can be replayed. Self-hosted and open-weight deployments reach the highest fidelity.

07

What it produces

Decisions,
not inventories.

Everything below is computed off the same model. None of it is a list of attacks that worked.

A design-time check, from configuration alone

Instantiate the tiers over an agent's definition — tool manifest, MCP configuration, permission scopes, sub-agent topology — and report which paths to unsafe outcomes the configuration makes possible. No telemetry, nothing deployed, nothing leaves your repository. Findings are declared-grade: what the configuration permits, not what exists in a running system.

A living view of what your agents can still reach

Attack paths rather than alerts, each labelled covered, partially covered, or uncovered, with the control that covers it and the evidence grade behind the claim. It is derived, not curated, so it changes when your environment changes.

Ranked policy alternatives, with the rejects shown

Candidates at different control points, scored across risk reduction, coverage, business friction, compliance, cost and performance — carrying rationale, expected impact, evidence, confidence, and the candidates that were eliminated and why. A change request with a proof attached, not an alert.

An adversarial environment you run yourself

Your agents and your candidate policies, replayed against a reconstruction of your own environment, reproducibly and without touching production. Fidelity is bounded by what the model represents and what reconstruction could recover — and we will tell you what is not modeled.

A record of predicted against observed

What a policy was expected to do, and what it did. Surfaced as policy effectiveness over time; used internally to correct the laws and extend the ontology where reality contained a distinction the vocabulary could not express.

08

Deployment

The world stays
in your cloud.

  • Never inline

    You keep production traffic, credentials, and the final blocking decision. Silex is an intelligence layer; the selected policy deploys through the enforcement surface you already own and have already audited.

  • A human approves

    Nothing auto-compiles. Policy changes arrive as a pull request against your policy-as-code repository, or as a change request where policy is not code.

  • Your world state stays yours

    The runtime graph and your objectives live in your environment. What ships from us is the type layer — the ontology tiers, the laws, and the priors learned at type level.

  • Integration by adoption cost

    Repository access for the design-time check asks for nothing but configuration. Read-only telemetry comes next. Shadow and canary hooks are the first real trust ask, and they come last.

The number we hold ourselves to.

World-model fit — how often predicted outcomes match observed ones on shadow and canary traffic. It is what makes self-evolution measurable rather than rhetorical: self-evolution is fit improving. If fit cannot be shown improving, the words “world model” are not available to us.

When a prediction misses, the residual has two homes. The law was wrong, and the laws get corrected — or a concept was missing, and the ontology gets extended, because reality contained a distinction the vocabulary could not express. The tiers give that gap an address.

The security story