Evidence
Router-only reality
Reason from router-visible logs, flows, ports, DNS, rules, and device-local configuration.
NARI Nano CD
NARI Nano CD is the compact cyber-defense track for routers and local network devices: router-only evidence, traffic reasoning, Suricata-rule proposals, policy boundaries, and operator-approved action.
Nano CD loop
observe router logs, flows, rules, ports, services, and local policy context
separate evidence, suspicion, anomaly, policy issue, and confidence
prepare Suricata-rule proposals, inspect notes, alerts, or escalation packets
preserve no-direct-mutation, audit, rollback, and operator approval
Small cyber-defense brains should be precise, local, and cautious.
Router scope
The product direction keeps the cyber domain narrow and reviewable: local router evidence, local policy, explainable proposals, and clear limits around what the system knows and can do.
Evidence
Reason from router-visible logs, flows, ports, DNS, rules, and device-local configuration.
Rules
Generate reviewable rule proposals with evidence, confidence, expected impact, and rollback notes.
Edge
Target compact local hardware where privacy, latency, and independence from cloud inference matter.
Authority
Keep mutation, blocking, and high-impact changes behind human review and explicit approval.
Defense posture
The product should avoid endpoint claims when the evidence is router-only.
Rule proposals can carry rationale, uncertainty, expected effect, and rollback guidance.
Local reasoning can preserve privacy and reduce dependence on remote inference.
Nexus CD can later coordinate many Nano CD brains across broader infrastructure.