Open-source security orchestration

An evidence-driven security staff, orchestrated for real assessments.

MiniCISO coordinates specialized security agents for threat modeling, architecture, code review, AppSec, compliance, offensive validation, recon, and quality assurance—while keeping evidence, uncertainty, and human accountability visible.

Built for human-authorized, evidence-driven security work. Not a replacement for accountable professional judgment.

Evidence artifacts flow into a coordinator and specialist network, through a quality gate, and into a structured report.
Evidence inCoordinated analysisQA-reviewed output

Project overview

See how MiniCISO turns evidence into accountable security work.

This short overview introduces the project, its specialized security staff, and the operating discipline behind every assessment.

MiniCISO project overview

01 / Why MiniCISO

Security work needs a chain of reasoning, not a pile of output.

Assessments break down when evidence is scattered, tools are disconnected, and early signals become premature conclusions. MiniCISO makes the operating discipline explicit.

01

Evidence before narrative

Claims start from traceable artifacts. Scanner output and recon remain inputs—not findings by default.

02

Specialists, not one generic prompt

The Chief of Staff delegates to focused SMEs whose scopes and boundaries are public.

03

Explicit validation gates

Conclusions pass through adversarial checks and mandatory Security QA before delivery.

04

Uncertainty stays visible

Assumptions, confidence, residual risk, and missing evidence remain part of the record.

05

Human accountability

Authorization and consequential judgment stay with accountable security professionals.

02 / How it works

One engagement. Nine disciplined stages.

The Chief of Staff scopes the work, selects the right specialists, correlates their analysis, and enforces QA before synthesis.

  1. 01Intake & scope
  2. 02Evidence collection
  3. 03Hypothesis formation
  4. 04Selective retrieval
  5. 05SME analysis
  6. 06Cross-SME correlation
  7. 07Security QA
  8. 08Final synthesis
  9. 09Reflection & lessons
Evidence input flows through a central coordinator and eight specialized agent nodes, then through a mandatory QA gate into a structured assessment.

03 / Meet the security staff

Coordinated roles. Clear boundaries.

Each profile has a public mission, defined scope, mandatory assumptions, confidence, and residual-risk reporting.

Coordinator

Chief of Staff

Scopes engagements, delegates work, correlates evidence, and owns the final synthesis.

Who should investigate? What is ready to deliver?
Specialist

Threat Modeling

Maps assets, trust boundaries, threats, and mitigations.

What can go wrong? Where are the critical paths?
Specialist

Security Architecture

Reviews system design, boundaries, controls, and resilience.

Do controls fit the design? Where does trust accumulate?
Specialist

Code Review

Inspects implementation evidence for security-relevant defects.

Is the weakness reachable? What code proves the claim?
Specialist

AppSec Assessment

Examines application risk across design, code, and deployment context.

What is exploitable? What evidence is still needed?
Specialist

Compliance Mapper

Maps technical evidence to relevant control requirements.

Which controls apply? What supports compliance?
Specialist

Offensive Security

Performs explicitly authorized validation within defined boundaries.

Can the path be validated safely? Is impact demonstrated?
Specialist

Recon & Attack Surface

Prioritizes exposed surfaces without turning discovery into findings.

What is exposed? What deserves controlled validation?
Quality gate

Security QA

Challenges evidence, impact, confidence, and reporting quality.

Is the conclusion supported? What would invalidate it?

Meet the full staff

04 / The first assessment

Start with scope, evidence, and a clear objective.

A good first request names the target, boundaries, known constraints, available artifacts, and desired output. MiniCISO may pause to ask for what is missing.

Input

What should I provide?

  • Objective and success criteria
  • Scope boundaries and restrictions
  • Repository, diffs, architecture docs
  • Relevant screenshots, logs, or scan results
  • Deployment and threat context
Process

What will MiniCISO do?

  • Define scope and select SMEs
  • Inventory available evidence
  • Separate evidence from assumptions
  • Form and test hypotheses
  • Expose gaps and submit conclusions to QA
Output

What will I receive?

  • Scope and evidence inventory
  • Findings, observations, and hypotheses
  • Confidence, limitations, and residual risk
  • Traceable support and next actions
  • A QA-reviewed final synthesis
Boundary

What will it not do?

  • Treat every anomaly as a vulnerability
  • Hide missing evidence
  • Claim authorization not provided
  • Turn recon directly into a finding
  • Replace human review or decisions
Finding

A supported claim with sufficient evidence.

Observation

A useful condition without full impact closure.

Hypothesis

A candidate path still needing validation.

Missing evidence

The exact gap blocking a stronger conclusion.

See what to expect from your first assessment

05 / Evidence-driven by design

Fewer unsupported conclusions. More accountable decisions.

MiniCISO preserves the difference between what is known, what is inferred, and what still needs research.

Evidence ≠ inference

Source artifacts and analyst interpretation remain distinguishable and traceable.

GO / RESEARCH / NO-GO

Finding candidates advance, return for evidence, or stop based on explicit gates.

Recon is not a finding

Discovery prioritizes attack surface; validated evidence is required for a security claim.

Mandatory Security QA

An adversarial quality gate checks scope, impact, evidence sufficiency, and confidence.

Headroom

Structured artifact handling preserves provenance while controlling the context used for analysis.

KAG-oriented retrieval

Selective retrieval connects scope, vulnerability, evidence, and decision context when useful.

Institutional learning

Prior lessons can shape analysis plans, raise evidence thresholds, tighten claims, and trigger QA guardrails—without replacing evidence from the current engagement.

Read the finding validation model

Institutional Learning

Memory stores information. Experience stores judgment.

MiniCISO evaluates relevant lessons from prior engagements before, during, and after security analysis. Previous experience can expose known failure modes, strengthen evidence discipline, and inform Security QA—but it cannot substitute proof from the current case.

Institutional learning cycle with direct evidence as the non-substitutable basis for every engagement.
Non-substitutable basisDirect evidence
  1. 01Current engagement
  2. 02Retrieve relevant lessons
  3. 03Evidence-driven reasoning
  4. 04Independent QA & reflection
  5. 05Register new lessons
  6. 06Future engagementsReturn to current engagement
Before analysis

Relevant lessons help shape the assessment plan and warn SMEs about previous failure modes.

During analysis

Prior experience helps detect repeated reasoning errors, weak analogies, and unsupported escalation of impact.

After analysis

NO-GO decisions, blocked work, and material QA corrections can become reusable lessons for future engagements.

Lessons guide reasoning. They never replace fresh evidence.

06 / Architecture overview

The human operator stays outside—and above—the automated trust boundary.

MiniCISO is a public overlay installed on a pinned Hermes Agent runtime. It is not a Hermes fork. Profiles, policies, templates, and shared workspace coordination remain reproducible without publishing credentials or private runtime state.

07 / Research

The Evidence Closure Loop

A Reference Architecture for Evidence-Driven Agentic Security Decisions

This practitioner whitepaper presents the architecture behind MiniCISO’s approach to evidence qualification, independent Security QA, decision control, and bounded autonomy.

Author
Cidade, Irlan de Alvarenga
Version
1.0
Published
DOI
10.5281/zenodo.21731494

08 / Open source & reproducible

An inspectable overlay, not a black box.

The repository packages profiles, prompts, templates, operating policies, bootstrap and validation scripts, public documentation, and sanitized configuration.

LicenseMIT
RuntimePinned Hermes dependency
Public stateSanitized by design
Private stateNever committed
MiniCISO network mark

About the project

Independent security engineering, built in public.

MiniCISO is an independent open-source security engineering project created by Irlan Cidade. It explores how specialized agents, explicit operating policies, evidence management, and human oversight can support more structured security assessments.