Public processing boundary
- No account or incident upload
- No model/API call from the workspace
- No attribution claim
- No irreversible-action authorization
- Operator-visible scoring rules
The public MVP runs deterministically in the browser. It turns authorized text evidence into indicators, timeline events, visible risk drivers, defensive courses of action, and fingerprinted exports without transmitting the incident text.
cognilode.incidentloom.incident_brief.v1
Generated time, severity score, evidence confidence, evidence SHA-256, summary, risk drivers, indicators, timeline, defensive courses of action, and Markdown rendering.
Replace pasted text with one customer-controlled signal adapter, map organization vocabulary and escalation boundaries, then write to one approved case or evidence system with provider readback.