Skip to content

Trust Center & Epistemic Integrity


1. Empirical Evidence

Every risk score is backed by observable ground truth: CVE IDs, CISA KEV entries, EPSS percentiles, and weaponized exploit repositories.

2. Auditable Provenance

Observations carry explicit state labels: LIVE, RETROSPECTIVE, REPLAY, or SYNTHETIC. Pre-epoch events are never disguised as live predictions.

3. Versioned Methodology

All scoring algorithms (HTS-3.1, HTR-2.0, FORECAST-1.4) are published with equations, weighting constants, and semantic changelogs.

4. Calibrated Track Record

Past forecasts are scored mathematically against real outcomes using the Brier Score ($BS = 0.1043$), eliminating retrospective hindsight bias.


Hermes replaces single-number โ€œconfidence ratingsโ€ with a 5-dimensional breakdown:

โš–๏ธ Epistemic Confidence Vector (5D) Empirical calibration without theatrics
Evidence Confidence High (94%)
Model Confidence High (88%)
Forecast Probability 78%
Data Completeness 91%
Decision Confidence High (85%)

๐Ÿšซ What Hermes Does Not Know (Epistemic Boundaries)

Section titled โ€œ๐Ÿšซ What Hermes Does Not Know (Epistemic Boundaries)โ€

Trust requires explicit transparency regarding limitations:

  1. Zero-Day Telemetry: Hermes cannot predict zero-day vulnerabilities prior to initial observable telemetry (e.g. honeypot anomaly, crash dump, researcher advisory).
  2. Proprietary Internal Networks: Hermes does not scan private internal networks. Its threat intelligence reflects internet-facing and supply-chain exposure.
  3. Analyst Inferences vs Facts: Statistical model inferences are never presented as ground truth facts. Inferences remain hypotheses until validated by external oracles.
  4. Data Completeness Fluctuations: When upstream sources (NVD, vendor feeds) experience downtime or indexing delays, Hermes marks observation states as INSUFFICIENT_DATA.