Technical evaluation

A small, auditable incident pipeline.

The public MVP runs deterministically in the browser. It turns authorized text evidence into indicators, timeline events, visible risk drivers, defensive courses of action, and fingerprinted exports without transmitting the incident text.

1 · Inputalerts, logs, notes
2 · Normalizelines and timestamps
3 · ExtractURLs, IPs, hashes, CVEs
4 · Explainrules, severity, confidence
5 · ExportMarkdown, JSON, SHA-256
Run the local MVP

Public processing boundary

  • No account or incident upload
  • No model/API call from the workspace
  • No attribution claim
  • No irreversible-action authorization
  • Operator-visible scoring rules

Export contract

cognilode.incidentloom.incident_brief.v1

Generated time, severity score, evidence confidence, evidence SHA-256, summary, risk drivers, indicators, timeline, defensive courses of action, and Markdown rendering.

Pilot integration seam

Replace pasted text with one customer-controlled signal adapter, map organization vocabulary and escalation boundaries, then write to one approved case or evidence system with provider readback.

Evaluation questions

  • Does the brief preserve the important evidence?
  • Are score drivers understandable and adjustable?
  • Does the output reduce first-brief assembly time?
  • Can the incident owner verify downstream custody?