CHELYS SECURITY

Coordinated intelligence, unrestricted coverage.

Unlike legacy scanners that execute rigid, linear checklists, Chelys deploys 8 specialized agents in parallel — each with distinct expertise, tools, and objectives — coordinating over a shared ledger to pivot seamlessly from reconnaissance to compliance reporting.

8 Specialist Agent Roles

Meet the nodes of the Chelys autonomous offensive security swarm.

RECON

Phantom

Attack Surface Mapping
Phantom

Maps the attack surface, identifies open ports, fingerprints services, and discovers subdomains. Feeds structured asset inventory to the orchestrator for downstream agent targeting.

EXPLOITATION

Viper

Vulnerability Exploitation
Viper

Attempts exploitation of confirmed vulnerabilities. On success, captures proof-of-exploitation output and passes credentials or shells to the Lateral Movement agent.

LATERAL MOVEMENT

Serpent

Post-Exploitation Pivoting
Serpent

Executes pass-the-hash, Kerberoasting, and credential relay attacks. Maps Active Directory attack paths. Attempts to pivot to adjacent hosts within authorized scope, capped at 3 hops by Safety Oracle.

EVASION

Wraith

Detection Validation
Wraith

Validates whether the target's detection controls (SIEM, EDR, WAF) are alerting on the attack traffic. Tests detection gaps and recommends compensating controls. Generates Sigma detection rules for findings where the target was not alerted.

REPORTING

Oracle

Findings Synthesis
Oracle

Synthesizes all agent outputs into structured findings. Maps to MITRE ATT&CK, NIST, PCI-DSS, SOC2, and HIPAA. Generates remediation recommendations. Drafts full PDF reports with executive summary, technical evidence, and compliance mapping tables.

SAFETY MONITOR

Safety Oracle

Constitutional AI Guardrail
Safety Oracle

Constitutional AI agent that reviews every proposed tool call before execution. Enforces scope, reversibility, and authorization constraints. Blocks destructive operations. Maintains an immutable action log for post-scan audit. Cannot be overridden by other agents.

QUALITY ASSURANCE

Analyst

Evidence Validation
Analyst

Reviews findings for false-positive risk, validates evidence quality, and scores confidence levels. Flags findings where AI reasoning may have over-concluded and queues them for human verification before delivery to the customer.

COMPLIANCE

Auditor

Regulatory Framework Mapping
Auditor

Specialized in regulatory frameworks. Reviews findings against PCI-DSS 4.0, SOC2, HIPAA, NIST 800-53, and ISO 27001 requirements. Generates the compliance mapping section of deliverable reports and tracks remediation verification status.

Real-Time Attack Graph Construction

As agents execute scanning and exploit commands, they register findings to a live attack path model. The SwarmOrchestrator continually evaluates paths of least resistance, computing breach likelihood and identifying high-value targets (e.g. Active Directory DCs or staging database nodes) dynamically.

Living Attack Graph

AUTO-ROTATING
15 nodes 17 edges
Hover to pause

Safety Oracle & Blast-Radius Mitigation

Offensive operations inside live enterprise subnets require strict boundaries. The Safety Oracle acts as a deterministic barrier, evaluating every exploit proposal against pre-authorized scope rules and destructive command lists. High-risk movements trigger automated hold states awaiting explicit operator clearance.

Safety Oracle — Live Decision Feed

ACTIVE GUARD
0 PASS 0 BLOCK 0 HOLD
Evaluating in real-time

MITRE ATT&CK® Framework Mapping

Every technique executed by the swarm is automatically tagged to the MITRE ATT&CK® Enterprise framework in real time — tactic, technique ID, and sub-technique. Findings arrive compliance-ready, with full adversary behavior lineage mapped to the industry-standard knowledge base.

14
TACTICS
200+
TECHNIQUES
v14.1
ATT&CK VER.

ATT&CK® Technique Mapper

0 techniques 0 / 8 tactics
MITRE ATT&CK Enterprise v14.1 · Auto-tagged per execution Click a tactic to explore

Continuous Compliance Mapping

The Auditor agent maps every finding to SOC 2, PCI DSS 4.0, and HIPAA controls automatically. Security posture stays audit-ready — not just at point-in-time scans.

3
FRAMEWORKS
25
CONTROLS
PDF
EXPORT

Framework Coverage

LIVE SYNC
0%
SOC 2
8 controls
0%
PCI DSS
9 controls
0%
HIPAA
8 controls
Q1 External Assessment · 3 findings resolved

SOC 2 Type II — Control Status

5 pass 2 fail 1 warning
Auto-mapped from assessment findings · Auditor Agent

Generated Assessment Reports

The Oracle agent synthesizes all findings into four tailored report formats — each auto-generated from the same assessment run and targeted to a different audience.

Executive_Summary.html

PREVIEW
Auto-generated by Oracle Agent · Oracle v2.1 Export as PDF · HTML · CSV

Immutable Audit Log

Every user action, agent decision, and system event is recorded in a tamper-evident audit log. Filter by action type or user, export for compliance review. Required for SOC 2 CC7.2 and PCI DSS 10.2.

100%
COVERAGE
<1ms
WRITE LATENCY
SOC 2
CC7.2 READY

Live Audit Stream

RECORDING
Filter by action (e.g. login)
Filter by email
0 events recorded Tamper-evident · SOC 2 CC7.2 · PCI DSS 10.2

See the Swarm Orchestrator in action.

Request a guided environment staging where we'll simulate a swarm security assessment on mock infrastructure to verify speed, path logic, and compliance logging.

REQUEST DEMO