History

History as told by CISOware founder, Craig Brown

CISOware 1.0

On November 30, 2022, OpenAI launched ChatGPT as a free research preview. This was the first time most people ever thought about artificial intelligence. From that point on, the words artificial intelligence meant the software services offered by the frontier AI companies. But there was another kind of simulated intelligence developed many years prior.

In 1995, Floater Corporation introduced what it called “Artificial Intelligence” in a product known as Floater. That is approximately 20 years before OpenAI was founded and approximately 27 years before the release of ChatGPT. I now have a more succinct name for it: “Orchestrated Intelligence”.

Orchestrated Intelligence (OI): A domain-specific computational intelligence trained to reproduce the decision patterns of a particular user or organization. Unlike generative AI, it does not simulate human conversation or require natural-language understanding; it is queried programmatically and produces decisions or structured outputs within its trained domain.

In short, it is not trying to provide the illusion of “thinking”. Instead, it asks the question, “What would my orchestrator do in this situation?” It does not gain its intelligence by scraping web data. It does not use a model. It is trained by its orchestrator and then learns as it is used.

After a debriefing that followed my three-year stint in Russia, I attended an FBI-sponsored conference that addressed seemingly unsolvable problems with information security. In 2013, two years before OpenAI began operations, I wrote the functional specification for a platform that would solve these problems. At the core of this solution was “Orchestrated Intelligence”. The product is called Reflex.

I had already been thinking about the implementation of “intelligence” for 20 years before approaching Reflex. It was a “chicken and egg” problem. How could AI make decisions and learn without already having intelligence? I took the egg route and built an application that creates its own data.

Reflex is a model for an entirely new type of application. Reflex creates a “closed-loop cognizant flywheel” independent of external data.

CISOware 2.0

Everything stopped with Covid. CISOware was ready to seek funding with a completed, enterprise-grade product. To my knowledge, it was the first enterprise-scale platform released by a self-funded entrepreneur. No seed money from friends or family.

At that time, I started looking at large language models (LLMs). I viewed these models as a potential component in my system. I invented the concept of a “fuzzy component,” which required a major modification in the way a software application is developed.

When a company creates a model, it’s safe to assume that the company will release an upgrade to that model within some short period of time. If the assumption is that the new model is “smarter” than the old model, and there is an existing procedure that relies on the decisions made by the older model, all previous observations must be reevaluated. In order to achieve this, all previous bits of data that were initially used must be available. The patent-pending Eternal Archive technology was created. The Eternal Archive is not a backup. Backup data is lost if there is some structural change in future data structures that don’t match those used when the backup was created. The Eternal Archive is self-healing and contains a blueprint for how every piece of data was saved.

As of today, September 26, 2026, following a number of AI disasters, the hottest topic being discussed is HITL (Human-in-the-Loop). In other words, not trusting AI to make important decisions. I reached this conclusion the first time I heard a billionaire talking about AI. The following shows the data flow of the entire process. It introduces new symbols never before seen in a flow diagram of a software application: two human beings standing next to an LLM. These two individuals serve a purpose. That purpose is to ensure that when the system thinks it has learned something, it is not a hallucination. Before it is stored as a fact, one of these humans has expertise in AI and reviews the parameters that led to this conclusion.

A large language model is built by reviewing an enormous amount of data and may require weeks to compile and several million dollars of compute time. Once completed, it is read-only. It cannot learn. A system supplemented with a database does not change what is embedded in an LLM. Reflex OI (Orchestrated Intelligence) does learn.

Going back to the chicken and egg analogy, one of the major benefits of choosing the egg model is that I can control the processing of the data used by the system intelligence. The chicken methodology scrapes data and tries to determine its meaning. It cannot contact the creator of that data and ask for clarification. For example, let’s say the LLM has discovered something previously unknown about a malware attack. The AI expert conveys this information to his partner, who is a senior coder. This knowledge has been saved locally, but the application that creates all this data, in conjunction with the user’s activity, is unaware of this discovery. This coder contacts another human at the top of the process who is responsible for writing the code that creates the data. This new knowledge will be built into the application in its next release, thereby making it smarter.

A key component is that the gained benefits are transparent to the users of the system. What goes on beyond its core functionality is irrelevant to the people whose problems are being solved by the system. This is not a situation where a company is mining data from its users to be used for some nefarious purpose. It’s not a Trojan Horse; it’s more like a box of Cracker Jack with a delightful surprise inside.

Another interesting side effect of this architecture is the following. Let’s say the AI expert standing next to that model is looking at some results and realizes that if there were one more piece of data, a much better conclusion could be reached. Since CISOware controls this entire flow of data, a change request could be made where some user interface component is added that requires the user to enter this information. If viewing the humans as components in the system, this results in a closed-loop system that improves itself with no risk of destroying humanity.

This same philosophy was used to create a solution to another major problem with the way in which some companies are using agents. Companies are directly connecting trigger events with agents. This will lead to disaster, and I stake my 48-year track record on this as fact. However, while companies struggle to address this risk, Reflex already has the solution. As stated above, Reflex already considers people important components in the system. Adding support options for activating agents was already built into the code years before frontier AI used the word “agent”.

CISOware 2.0+

A very important point about everything discussed above: when discussing Reflex, all documentation presents Reflex as an information security product. But Reflex can actually be viewed as a template in which there are several industries that fall into its use case. The system was designed using a syntax that can be swapped out for another. For example, a demonstration was made using the exact same code, but collecting information about procedures done by nurses. The code could be used for research studies and limitless other applications. If CISOware were being run by a frontier AI company, it could select a specific area and generate entirely new data regarding the chosen topic. But only if the following criteria are met: from a user’s perspective, the application has to be providing some valuable service that makes people want to use it. As they are now discovering, people do not willingly record everything they do in order to hand it over to an AI company. There needs to be some incentive.

In summary, while the news coming from the frontier AI companies is not good, and the progress in which the data centers that they have staked their future on are not being completed, there is one thing they can do to achieve their trillion-dollar valuation: acquire CISOware and solve meaningful problems today instead of at some hypothetical time in the future.