PYNTIX
License Engine
PYNTIX — Cyber Security Software
Enterprise Command Manual

Operational Resilience Protocol

The authoritative operational doctrine for the PYNTIX kinetic anomaly detection engine. This document defines the engine's directive classifications, command authority frameworks, audit provenance standards, and integration protocols for enterprise network security operations.

Engine Version 2.1.0Classification: DeterministicAudit-Ready
Network infrastructure monitoring
Security operations

Operational Mandate

The PYNTIX engine exists to provide deterministic, audit-ready network integrity monitoring for systemic-critical infrastructure. It does not predict. It does not infer. It computes.

Every directive the engine issues is the product of a fixed kinematic formula applied to observed traffic physics — bound to its input by cryptographic provenance and traceable to a single board-approved classification rule. There is no black box. There is no model drift. There is only the signal, the math, and the directive.

The engine operates under a human-in-the-loop command authority framework. It does not seize control of edge infrastructure without explicit operational consent — except in autonomous mode, where that consent was granted in advance by the license holder and remains reversible at any time.

Directive Classification Schema

The engine classifies every traffic reading into one of three deterministic directives. Classification is driven by deviation magnitude (D) and the kinematic rapidity index. The first matching rule in the decision framework fires — no ambiguity, no overlap.

NORMAL FLOW — ALLOW

R5_NORMAL / R1_FLAT_TRAFFIC

Throughput deviation remains within the operational volatility floor. No intervention is required. Traffic is permitted to traverse all edge infrastructure without restriction.

Required Response

None. Continue baseline observation.

ELEVATED THREAT — MONITOR & THROTTLE

R4_ELEVATED

Spike magnitude exceeds the monitoring threshold OR rapidity index indicates a gradual ramp signature (flash-load). Elevated risk is present but hostile intent is not yet confirmed.

Required Response

Escalate to SOC observation. Apply rate-based throttling at the action threshold. Prepare edge-level intervention if rapidity escalates.

CRITICAL INTRUSION — BLOCK ALL

R2_VERTICAL_SPIKE / R3_MAGNITUDE_CRITICAL

Rapidity index ≥ 1.0 (near-vertical volumetric signature) OR magnitude deviation ≥ 60%. The traffic profile matches a deterministic hostile intrusion classification.

Required Response

Drop all traffic at or above the action threshold. Engage circuit breaker at 2× baseline. Quarantine source. Notify Command Authority immediately.

Command Authority Modes

The license holder selects the engine's operational autonomy level. This governs whether directives auto-execute or await human approval. The mode is snapshotted into every traffic log at ingestion — creating an immutable audit record of the operational posture under which each directive was issued.

Advisory

The engine issues directives in observation mode only. No autonomous action is taken. A human operator must explicitly approve every counter-measure before it executes on the edge.

Use Case

Regulated environments where human sign-off is a statutory requirement for any traffic-shaping action.

Assisted

The engine pre-drafts precision response directives (action thresholds, stabilization targets, circuit breakers) and presents them for one-click human confirmation. The human retains final command authority.

Use Case

Standard enterprise security operations requiring speed without sacrificing human oversight.

Autonomous

The engine auto-executes directives the instant a hostile signature is detected. All actions are logged with full audit provenance. A human operator may revert any autonomous action with a single command.

Use Case

High-frequency edge infrastructure where millisecond latency on hostile traffic is operationally critical.

Kinematic State Doctrine

Kinematic State Doctrine

The engine does not rely on threshold counting or static rate limits. It derives a kinematic state from the physics of the traffic signal itself.

Velocity is the rate of change of throughput (pkt/s²). Acceleration is the rate of change of velocity (pkt/s³). The rapidity index normalizes velocity against the network's established baseline — producing a dimensionless measure of how fast the signal is moving relative to normal operating capacity.

A rapidity index ≥ 1.0 means the traffic is moving faster than the entire baseline would normally carry — a near-vertical spike signature consistent with a volumetric attack. A gradual, benign load ramp (such as a coordinated flash event) remains well below this threshold and is classified accordingly.

This kinematic approach allows the engine to deterministically distinguish a hostile SYN flood from a benign flash sale — without probabilistic inference, without behavioral baselining drift, and without black-box machine learning.

Audit Provenance Protocol

Audit Provenance Protocol

Every directive the engine issues is cryptographically bound to its exact input signals via FNV-1a provenance hashing. No directive exists without a deterministic receipt.

Each audit receipt contains the full kinematic snapshot (throughput, baseline, spike rate, structural mass, threat index, rapidity index), the exact classification rule that fired, the engine version, and a millisecond-precision timestamp.

A regulator or internal auditor can replay any historical directive against the engine offline and reproduce the identical result. The engine is provably deterministic. There is no probabilistic variance, no model drift, and no unexplained output.

This constitutes formal evidence of determinism and policy compliance for banking, cloud, and systemic-infrastructure regulatory frameworks.

Ingestion Integration Protocol

Ingestion Integration Protocol

The engine ingests traffic readings via a low-latency hot-path endpoint. Each POST is authenticated against the license's provisioned ingest API key and classified in real time — no LLM or heavy processing executes on the hot path.

Companies point their monitoring tool, SIEM, or custom collection script at the endpoint and push throughput readings (packets/sec or requests/sec) with optional source IP, direction, and network label fields.

The engine fetches the most recent prior reading for that license to compute kinematic history, then writes a fully provenanced PyntixTrafficLog record and returns the directive to the caller.

Narrative threat briefs are generated on demand from the dashboard — keeping the ingestion hot path free of any non-deterministic processing.

Operational Governance

Operational Governance

The engine undergoes automated weekly determinism audits against a canonical suite of test vectors. Each audit verifies that the engine's directives remain stable and policy-compliant across all classification rules.

A weekly operational summary aggregates all BLOCK and MONITOR directives, autonomous auto-actions, and manual interventions into a board-level report for enterprise governance review.

All audit results are archived and available to licensed operators on demand from the enterprise dashboard, providing a continuous compliance posture rather than point-in-time snapshots.

Activate the Engine

Licensed operators gain access to the enterprise dashboard, the live ingestion endpoint, the approval mode controls, and the full audit verification suite upon completing the annual license agreement.

© PYNTIX Enterprise. This protocol document constitutes operational documentation for licensed enterprise operators only. The engine is a kinetic anomaly detection tool and does not replace a dedicated firewall, IDS, or sovereign security operations center.