The model
A world model for networks, built to see ahead.
Most security models label what they see. NagaHana models the world that produced it — and runs that world forward. This is how it thinks.
01Two kinds of physics
What can be known is built in. What can’t is learned.
A network obeys rules you can write down — and behaviour you can’t. NagaHana keeps the two apart, so it spends its learning only on what is genuinely unknown.
Known physics — built in
Specified, not guessed.
- Topology — how devices and segments connect
- Protocol rules and legal state changes
- Physical limits — bandwidth, latency, packet size
- The logic of identity and access
Behaviour — learned
Inferred from how your network actually lives.
- What normal looks like, hour by hour
- How benign and hostile activity differ
- How intruders move and adapt
- How the whole network drifts over time
That split is why a world model — and not a classifier — can forecast. A classifier labels a snapshot. A world model plays the present forward, under the rules it knows and the behaviour it has learned.
02Four parts, one loop
Simulator. Renderer. Planner. Verifier.
Each part has one job. Together they form a loop around a shared memory — and every hand-off between them is on the record.
Select a part to see what it does
- Physics-informed
- Self-supervised
- Energy-based
- Multiplex graph
- Space · time · cause
- Frozen, certifiable core
03One graph, every layer
Space, time and cause — modelled together.
Your network is not one graph but several, stacked on the same machines and people: who talks to whom, who signs in where, what resolves to what, what is encrypted how. NagaHana reads them as one.
Space
Structure and reach — which entities connect, broker and bridge.
Time
Rhythm and drift — from bursts in seconds to patterns across months.
Cause
Enablement — which step makes the next one possible.
04The envelope
What’s impossible. What’s normal. And the space in between.
Everything a network does falls into one of three regions. Intrusions live in the middle one — possible, but not normal — and knowing the boundaries shrinks the space an intruder can hide in.
Impossible
Breaks the rules of the protocols or the physics. Significant on its own.
Possible, but not normal
Allowed by the rules, unusual for this network. Where intrusions live.
Normal
Your network’s own everyday behaviour, learned on site.
05What attacks must do
Tools change. Objectives don’t.
An intruder can rename every file and rotate every address. What it cannot avoid is doing what it came to do. NagaHana anchors its judgement there.
- 01
Exfiltration
Information must leave — flowing out from where it lives to somewhere it shouldn’t.
- 02
Lateral movement
Reach must grow — new paths opening toward higher privilege.
- 03
Command & control
A channel must persist — a recurring, two-way line to the outside.
- 04
Reconnaissance
Many things must be touched — cheaply, quietly, one after another.
Judging by what must happen, rather than by what looks familiar, is what brings renamed tools and never-seen malware into view.
06Suspicion
Never zero. Earned by evidence.
NagaHana doesn’t flip between safe and unsafe. For every part of your network it carries a level of suspicion that starts above zero — because a breach is always possible — and rises only as evidence accumulates.
Evidence over time
Assume breach
Suspicion never falls to zero, so an intruder already inside is never waved through.
Patient with ambiguity
Where ordinary and hostile look alike, it gathers more evidence before it speaks.
Sooner where it matters
Around your most critical assets, it raises its concerns earlier.
07Memory
Built around memory, not just computation.
Memory in NagaHana is not a by-product of processing. It is a structured, auditable record that the model reasons over — organised in tiers, from this moment to the last several months.
01
Working memory
The model’s immediate picture of what is happening now.
02
Entity profiles
How each host, account and service normally behaves — kept for every one.
03
Long-horizon memory
Compact summaries of what is rare and new across months, so slow patterns surface.
04
Lossless archive
The full record, compressed and kept — for the questions no one thought to ask in advance.
05
Recall
“Have we seen this before?” — answered across the whole history.
A frozen, certifiable core
The model’s learned knowledge is fixed at release: hashable, auditable, and not rewritable while it runs.
An adaptive memory
Everything specific to your network adapts in memory — bounded, auditable and reversible, so it can be inspected or rolled back.
08Forecasting
Many futures, each with a likelihood and a clock.
A forecast from NagaHana is never a single guess. It is a set of possible futures, each with a probability and an expected window — and an honest limit on how far ahead it can be trusted.
- 01
Many paths, many steps
It explores many possible futures, several steps deep. How many, and how far, is configured for each site.
- 02
A window, not a moment
“When” comes as a distribution — the likely window, never a single falsely precise time.
- 03
Early signals
It learns what tends to come before an intrusion — the quiet precursors that make lead time possible.
- 04
Scored like the weather
Every forecast is checked against what happened and against a naive baseline. Skill is measured, not claimed.
09Open the brain
Look inside while it thinks.
In a sandbox, open NagaHana up and follow a single forecast through every stage — what it noticed, what it remembered, how it reasoned across space, time and cause — all the way to the answer. Built for analysts, auditors and the mathematicians who want to check the work.
10How it learns
Trained to learn principles, not your floor plan.
A model that memorises the networks it was trained on fails on yours. NagaHana is trained so that what it learns carries over.
- 01
Self-supervised
It learns the structure of network behaviour from the data itself — not only from labelled attacks.
- 02
Cause, not coincidence
Controlled attack emulation shows it what actually causes what, not just what tends to appear together.
- 03
Variety by design
Training deliberately varies layouts, devices, protocols and sensor coverage, so it learns what stays true across them.
- 04
Tested on unseen networks
Every release is judged on networks it never trained on — the only honest test of whether it will work on yours.
See what’s lurking in your network.
A private briefing, shaped around your environment.