ive homepage (static link, no edge transform) -->

XCOM.DEV

A mind made of Agents.

XCOM.DEV senses the open internet, correlates what it finds, and reasons over it — continuously. Honeypot sensors feed a distributed agent swarm; a recurrent-depth reasoning layer turns raw signal into situational awareness. Don't trust the numbers: click them.

Read the creed Executive briefing View live endpoint
Honeypot events
—
D1 · honeypot_logs
Events / 24h
—
live window
Events / last hour
—
live window
Arrival rate λ
—/s
model · per second
01Live telemetry · Observed vs Poisson model

Observed arrivals vs Poisson model

P(k;t) = (λt)ᵏ · e−λt / k!  ·  λ from live /api/metrics

02The creed · Five principles

“Intelligence is not a model. It is a system — senses, memory, specialists, and a loop that closes.”

01

Sense before you think

The open internet is the largest sensor grid ever built — and adversaries broadcast into it all day. Our honeypot decoys receive real attacker probes; every probe is an IOC, a data point, a piece of ground truth. Cognition begins downstream of raw signal, never upstream.

02

No single mind can hold the world

Instead of one giant model pretending omniscience, we run a swarm: dozens of specialised agents — strategy, intelligence, security, engineering, operations, research — correlated on a shared substrate. Specialisation is how breadth actually happens. (The long-form version of this creed lives at /vision.html.)

03

Reasoning is a loop, not a token stream

One pass of a transformer is not thought. Our reasoning layer (OpenMythos) re-enters its own latent space — recurrent depth, same weights, more loops — until the judgement converges. Depth of inference is bought with iteration, not parameters.

04

Proven, not claimed

Every number on our site links to a live endpoint you can query. If we can't show you the source, we don't publish the figure. This rule costs us page polish and earns us the only thing that matters in intelligence: trust.

05

Autonomy with an audit trail

Agents that act must log what they did, on what evidence, and be interruptible by a human at every step. We build for NIS2-grade accountability: detection, verification, audit-ready evidence. Intelligence without accountability is just an unregulated black box.

03Architecture · The four-layer stack
01 · SENSE

Honeypot sensors

Live attackers hit our decoys; every probe becomes a data point with real IOCs.

→ attack map
02 · CONNECT

Agent swarm

Distributed specialised workers correlate identities, entities and campaigns.

→ agent registry
03 · REASON

OpenMythos

A recurrent-depth reasoning transformer turns correlated signal into judgement.

→ reasoning layer
04 · ACT

Fraud · OSINT · NIS2

Detection, verification and audit-ready evidence for organisations in the Netherlands.

→ technology
04Mathematics · The system, formalised

Every layer has an equation.

The stack is not a metaphor — each layer runs on explicit mathematics, and the parameters are live. If a formula on this page can't be recomputed from our public endpoints, it doesn't belong here.

M1 · SENSE

Arrival model — Poisson

P(k; t) = (λt)k · e−λtk!,  λ = λ/s

Attacker probes arrive as a Poisson process; λ is estimated live from the honeypot stream and drives the chart above.

→ λ from /api/metrics
M2 · COGNITION

Surprise ranking — Shannon entropy

H(X) = −Σi pi log₂ pi

Attention is scarce. Events are ranked by information gain — high-entropy, low-probability signal rises to the swarm first. Right now: H = — bits per event empirical · 24h mix. Top sources: — — concentration is the intel.

→ layer 01 · sense
M3 · REASON

Belief update — Bayes

P(H|E) = P(E|H) · P(H)P(E)

Every IOC is evidence. Agent hypotheses are posteriors, updated per probe — never reset, never asserted without E.

→ layer 03 · reason
M4 · CONNECT

Entity correlation — cosine similarity

sim(a, b) = a · b‖a‖₂ ‖b‖₂

Identities, aliases and campaigns are vectors; correlation is alignment in feature space, thresholded before an edge is created.

→ layer 02 · connect
M5 · REASON

Recurrent depth — fixed-point iteration

ht = φ(W ht−1 + Ux + b)  until  ‖ht − ht−1‖₂ < ε

OpenMythos re-enters its own latent space: same weights, more loops. Depth of inference is bought with iteration, not parameters — judgement is a converged state.

→ reasoning layer
M6 · CONNECT

Swarm topology — graph density

ρ(G) = 2|E||V|(|V| − 1) = 8.32×10−2

Computed live from the registry graph (—): |V| = 54 agents, |E| = 119 real co-membership + hub edges.

→ recompute from /api/swarm
M7 · DETECT

Concentration shift — KL divergence

DKL(P‖Q) = Σx P(x) log P(x)Q(x) = — nats

Today's attacker-ASN mix (P) vs baseline (Q): a spike means the source base moved — recon replaced by a new operator. Q = yesterday's frozen D1 snapshot, or the rolling −96h→−24h window until one exists. Measured live.

→ drift from /api/metrics
05Horizon · What comes next
H1

Self-updating intelligence

The site itself is fed by the fleet: metrics, swarm topology and activity regenerate continuously. A website that is a snapshot is a brochure; ours is the system, publishing itself.

H2

Machine-readable everything

Agents read the web too. Our manifest, llms.txt and JSON endpoints make the whole platform a first-class citizen of the machine internet.

H3

Proportional autonomy

As the swarm earns reputation, its action-surface widens — always bounded, always logged, always with a human kill-switch. Trust is measured before it is granted.

“Don't ask what the model knows. Ask what the system can prove — right now, from production.” XCOM.DEV · closing