One public investigative layer
Shared meaning for every cyber investigation
TENSOR is being developed as a public standard for cyber investigations. Humans, agents, and mixed teams use the same model to describe questions, evidence, uncertainty, assessments, decisions, and revisions. Those meanings should survive a handoff between people, organizations, and tools.
The scope includes incident response, threat hunting, forensics, identity, cloud, network, endpoint, application, and AI-system investigations. AI security teams governing agents and autonomous systems are the first adoption community; they do not define the limits of Core.
What stays at the center
The existing investigative questions and explicit yes, no, and unknown outcomes remain useful. Core now distinguishes a reusable investigation definition from the record of a particular investigation. A question instance binds a question to a subject, time, and parameters.
The legacy question catalog and published graph releases remain available. Their content needs semantic review before it can become a candidate definition; no historic record or evidence has been invented during migration.
Public Core, open room to build
| Layer | Responsibility |
|---|---|
| Public TENSOR Core | Identity, context, attribution, provenance, uncertainty, decisions, revisions, and exchange. |
| Public domain profiles | Reviewed questions, evidence requirements, vocabulary, and standards references. |
| Vendor layer | Interfaces, connectors, storage, analytics, and execution systems. |
| Business layer | Organizational policy, authority, thresholds, escalation, and retention. |
Vendor and business layers may specialize behavior. They must not silently rewrite shared meaning. Core does not require a particular platform, interface, model provider, or execution engine.
Current status
Core 0.1.0-draft.1 is an implementation candidate. It is not ratified, independently certified, or institutionally endorsed. The founding package proposes public stewardship; named appointments and a stable release remain open work.
Read the founding charter · Inspect the Core candidate · Review proposed governance