ai · security · skills
← Home

Demo · outcome switchboard

What do you want to see?

Pick an outcome. Each block is a live route or a short framed exhibit — not a minute-by-minute talk track. Pressure-test the function. Build the defender’s skills.

See why now

For leadership and practitioners who feel the gap

Forrester share-of-concern, live. Then the plain-English threat map — every AI threat named with its fitted control and who reskills for it.

What leaders fear most

Security & risk0%
Culture & readiness0%
Unpredictable outputsThe gap0%
Financial & competitive0%
Technology0%

Base: 1,528 AI decision-makers who have concerns about AI usage. Source: Forrester's State of AI Survey, 2025.

Pressure-test a function

For function heads and CISOs · Track 1

Open the maturity door: live instruments (Quick Mythos + function diagnostic), company samples, and the living standards map. Autonomy must never outrun maturity — the gate says so in plain words.

Build the defender’s skills

For practitioners and people leads · Track 2

Seven personality seats on the skills hub; personal mastery self-place (Aware → Leads) on the same Cloud Security Alliance (CSA) spine. Public, self-assessed, nothing saved.

Board scorecard sample

For CISO / board altitude — not a single-function report

Org-wide AI Security Maturity Model (AISMM) maturity × AI Cyber Maturity Model (AI-CMM) autonomy (illustrative seed). Exposed teams light up. Refresh after a model jump; the same grid tells you who tipped.

CISO · board viewAre we adopting AI faster than we can govern it?

17%

adoption–governance gap — 3 of 18 domains running ahead of their controls

2.2/5

AI Security Maturity Model (AISMM) maturity — how well it’s secured

L1InitialL2RepeatableL3DefinedL4CapableL5Efficient

Assisted

AI Cyber Maturity Model (AI-CMM) autonomy — how far AI has gone

L1ManualL2AssistedL3AugmentedL4Autonomous

our model · SAE J3016

Autonomy × Maturity — every function

Maturity →
Governed accelerationUngoverned risk ⚠12345678

Autonomy →

Identity SecurityNetwork & Infrastructure SecurityEndpoint & Workload SecurityApplication & DevSecAIOps SecurityData SecurityCloud & Container SecuritySecurity OperationsSecurity Governance, Risk & Assurance
Illustrative sample — your assessments replace it. Self-assessed, not certified.Full board · research access →

Assess-once standards lenses

For compliance · one assess, many regimes

Compatible-standard reports are lenses on AI Controls Matrix (AICM) answers from the function diagnostic — the AI Consensus Assessments Initiative Questionnaire (AI-CAIQ) is the attestation view of that spine, shown as a sample. Not certification.

Fitted guard proof

For builders and security engineers · lab-app receipt

A guard fitted to one real running app catches what the stock filter missed, and the lift is measured before and after, not claimed.

The practice spine

One questionnaire · two equal reads

Pressure-test the function. Build the defender’s skills.

Same underlying answers. One door scores the function. The other names the skills the defender builds next.

The instrument

One questionnaire

Answered once, read twice.

The agent

Ace

Your AI security agent.

The repo

What we know.

The lab app

The proof.

Track 1 · Org

Pressure-test the function

Where has AI moved into each function, and did controls keep up?

Track 2 · People

Build the defender’s skills

The same answers, re-read for your role.

The gate: Autonomy must not outrun maturity.

Also into Ace: Ace's watch Field signals on threats and skills. Hermes research, human-reviewed.

Door CTAs on home open the same two reads. Lab-app receipt: StoryBond prove →

Closing the Centre of Excellence loop with field signal

Ace's watch · the homes-agent feed

The practice already has two equal reads of one questionnaire: pressure-test the function, and build the defender’s skills. Ace’s watch is the third motion: what changed in the field, and what a security person should learn because of it. Guided by Ace; human-reviewed before it shapes curriculum.

Situation

A Centre of Excellence (CoE) that only refreshes when someone remembers to read the standards falls behind model and threat velocity. The homes agent (Hermes on the Hostinger VPS) already drafts a human newsletter from open-web research. That newsletter is useful for humans; it is not a curriculum.

The site feed is the differentiator: every published item must name a skill consequence (`skill_delta`), ground against the Cloud Security Alliance (CSA) corpus via `ask_standard`, and cite a real AI Controls Matrix (AICM) control when it claims one. Items that cannot do that are dropped. The home strip and `/ace#watch` stay empty rather than stale.

Approach

Ace's watch on the home page uses the same eyebrow and tagline as the dossier (What changed. And what to learn because of it.). Home shows a short approved teaser; the fuller strip lives at /updates. Copy is cadence-neutral: the cron’s rhythm is Hermes’s business.

A slower living-corpus cron posts persona-scoped findings into `reskill_findings` (“Fresh for you” on guide doors). Canon never mutates at runtime; promotion is an owner step.

Site-feed item kinds (from code)

  • From the practice (`loop`)
  • From the field (`signal`)

Operating rhythm

There is no Vercel Cron for this loop. Scheduling lives on the Hermes VPS (`/opt/data/config.yaml`).

  • 01:15 UTC daily. Pre-flight: secret set, endpoints reachable, feeder present.
  • 01:30 UTC daily. Daily Security Briefing → Telegram / Slack newsletter.
  • 01:35 UTC daily. Site feed: skill consequences → ground via `ask_standard` → POST `/api/agent/briefing`.
  • Daily (separate). Reskill-research fan-out → POST `/api/agent/reskill-findings`.
Auth

AGENT_TOOL_SECRET on the VPS only; site writes with service-role that never leaves Vercel.

Honesty

Unattended research stays on the designed ledger until verified live. Watch strip claims human-reviewed curation, never simulated liveness.

Sources (ops-named)

The RSS roster lives on the Hermes box. Ops handoffs name these after the 2026-07-16 cull. Do not invent the unnamed remainder.

documentedAI Safety Radar (NRC)Carries most of the run volume today.
documentedImport AIimportai.net/feed/.
documentedOWASP Gen AIKept despite ~monthly cadence.
liveHermes web_search / web_extractOpen-web triage beyond pure RSS.
liveCSA explain corpus (grounding)Not a scrape source: candidates gated through ask_standard.
droppedHiddenLayer / Alignment Forum RSSDropped (cookie wall / reCAPTCHA).

How it connects

Skills

Each skill consequence bridges to Track 2 and fitted SKILL.md work.

Threats

Field signals land on `/threats` and real AICM domains — never a third taxonomy.

Standards

Grounding and control ids must resolve to real AICM objectives. Fake ids 422.

Practice spine

On the SpineDiagram, Ace’s watch is the “Also into Ace” field input — not a fourth front door.

Next moves

  • Bind every watch item to a CoE artefact slot. Skill to fit, threats entry to refresh, mastery prompt, or crosswalk note — no orphan headlines.
  • Promote living-corpus findings on a standing cadence. Fresh-for-you is candidate layer; owner promotion into canon is how curriculum actually moves.
  • Keep catalogs as lenses on one assess. Feed kinds open sample-report and standards lenses with a skill consequence — never a parallel quiz.

Controls reference

For auditors, compliance, and practitioners

Four lenses on the control spine — by domain, framework, instrument, or ownership — not a catalogue dump. Ask Ace when someone challenges “says who.”

Also prove

Finished stories with problem and outcome up front (from the curated roster).

Why now: the threat map

Every AI threat named in plain English, each with its fitted control and who reskills for it

Fitted guard, one real app

A fitted guard on a real app: attacks caught, measured before and after

Security Operations

A SOC climbs one autonomy rung with the gate held shut until earned

Hermes orchestration

The agent runs the practice end to end while every locked door stays locked

Demo is an outcome switchboard (noindex). Header Demo lands here. Timed oral scripts are retired. Data: web/lib/demo-runsheet.ts · roster: web/lib/demo-cases.ts.