Skip to content
NagaHana

The model

A world model for networks, built to see ahead.

Most security models label what they see. NagaHana models the world that produced it — and runs that world forward. This is how it thinks.

01Two kinds of physics

What can be known is built in. What can’t is learned.

A network obeys rules you can write down — and behaviour you can’t. NagaHana keeps the two apart, so it spends its learning only on what is genuinely unknown.

Known physics — built in

Specified, not guessed.

  • Topology — how devices and segments connect
  • Protocol rules and legal state changes
  • Physical limits — bandwidth, latency, packet size
  • The logic of identity and access

Behaviour — learned

Inferred from how your network actually lives.

  • What normal looks like, hour by hour
  • How benign and hostile activity differ
  • How intruders move and adapt
  • How the whole network drifts over time

That split is why a world model — and not a classifier — can forecast. A classifier labels a snapshot. A world model plays the present forward, under the rules it knows and the behaviour it has learned.

02Four parts, one loop

Simulator. Renderer. Planner. Verifier.

Each part has one job. Together they form a loop around a shared memory — and every hand-off between them is on the record.

Memory

Select a part to see what it does

  • Physics-informed
  • Self-supervised
  • Energy-based
  • Multiplex graph
  • Space · time · cause
  • Frozen, certifiable core

03One graph, every layer

Space, time and cause — modelled together.

Your network is not one graph but several, stacked on the same machines and people: who talks to whom, who signs in where, what resolves to what, what is encrypted how. NagaHana reads them as one.

TrafficIdentityNamingEncryption
  • Space

    Structure and reach — which entities connect, broker and bridge.

  • Time

    Rhythm and drift — from bursts in seconds to patterns across months.

  • Cause

    Enablement — which step makes the next one possible.

04The envelope

What’s impossible. What’s normal. And the space in between.

Everything a network does falls into one of three regions. Intrusions live in the middle one — possible, but not normal — and knowing the boundaries shrinks the space an intruder can hide in.

NormalPossible, but not normalImpossible
  1. Impossible

    Breaks the rules of the protocols or the physics. Significant on its own.

  2. Possible, but not normal

    Allowed by the rules, unusual for this network. Where intrusions live.

  3. Normal

    Your network’s own everyday behaviour, learned on site.

05What attacks must do

Tools change. Objectives don’t.

An intruder can rename every file and rotate every address. What it cannot avoid is doing what it came to do. NagaHana anchors its judgement there.

  • 01

    Exfiltration

    Information must leave — flowing out from where it lives to somewhere it shouldn’t.

  • 02

    Lateral movement

    Reach must grow — new paths opening toward higher privilege.

  • 03

    Command & control

    A channel must persist — a recurring, two-way line to the outside.

  • 04

    Reconnaissance

    Many things must be touched — cheaply, quietly, one after another.

Judging by what must happen, rather than by what looks familiar, is what brings renamed tools and never-seen malware into view.

06Suspicion

Never zero. Earned by evidence.

NagaHana doesn’t flip between safe and unsafe. For every part of your network it carries a level of suspicion that starts above zero — because a breach is always possible — and rises only as evidence accumulates.

Keep watchingLook closerRaise it

Evidence over time

  • Assume breach

    Suspicion never falls to zero, so an intruder already inside is never waved through.

  • Patient with ambiguity

    Where ordinary and hostile look alike, it gathers more evidence before it speaks.

  • Sooner where it matters

    Around your most critical assets, it raises its concerns earlier.

07Memory

Built around memory, not just computation.

Memory in NagaHana is not a by-product of processing. It is a structured, auditable record that the model reasons over — organised in tiers, from this moment to the last several months.

Working memoryEntity profilesLong-horizon memoryLossless archiveRecall
  • 01

    Working memory

    The model’s immediate picture of what is happening now.

  • 02

    Entity profiles

    How each host, account and service normally behaves — kept for every one.

  • 03

    Long-horizon memory

    Compact summaries of what is rare and new across months, so slow patterns surface.

  • 04

    Lossless archive

    The full record, compressed and kept — for the questions no one thought to ask in advance.

  • 05

    Recall

    “Have we seen this before?” — answered across the whole history.

A frozen, certifiable core

The model’s learned knowledge is fixed at release: hashable, auditable, and not rewritable while it runs.

An adaptive memory

Everything specific to your network adapts in memory — bounded, auditable and reversible, so it can be inspected or rolled back.

08Forecasting

Many futures, each with a likelihood and a clock.

A forecast from NagaHana is never a single guess. It is a set of possible futures, each with a probability and an expected window — and an honest limit on how far ahead it can be trusted.

  • 01

    Many paths, many steps

    It explores many possible futures, several steps deep. How many, and how far, is configured for each site.

  • 02

    A window, not a moment

    “When” comes as a distribution — the likely window, never a single falsely precise time.

  • 03

    Early signals

    It learns what tends to come before an intrusion — the quiet precursors that make lead time possible.

  • 04

    Scored like the weather

    Every forecast is checked against what happened and against a naive baseline. Skill is measured, not claimed.

09Open the brain

Look inside while it thinks.

In a sandbox, open NagaHana up and follow a single forecast through every stage — what it noticed, what it remembered, how it reasoned across space, time and cause — all the way to the answer. Built for analysts, auditors and the mathematicians who want to check the work.

Sandbox · read-only
ObservationGraph encodingMemory recallWorld dynamicsForecast

10How it learns

Trained to learn principles, not your floor plan.

A model that memorises the networks it was trained on fails on yours. NagaHana is trained so that what it learns carries over.

  • 01

    Self-supervised

    It learns the structure of network behaviour from the data itself — not only from labelled attacks.

  • 02

    Cause, not coincidence

    Controlled attack emulation shows it what actually causes what, not just what tends to appear together.

  • 03

    Variety by design

    Training deliberately varies layouts, devices, protocols and sensor coverage, so it learns what stays true across them.

  • 04

    Tested on unseen networks

    Every release is judged on networks it never trained on — the only honest test of whether it will work on yours.

See what’s lurking in your network.

A private briefing, shaped around your environment.