Maxifai.
Preview · Phase 0 · founding cohort
Singularity · Structural Vulnerability Atlas

The inventory becomes a risk map.

Singularity is the Event Horizon structural-signature layer. It identifies files whose structure matches the spectral signatures of known weakness classes — and ranks them into four review buckets. Deterministic. On-premises. No AI in the loop.

Event Horizon maps the stars.
Singularity reads their spectral signatures.
Why this layer exists

Mythos finds known weakness classes in new locations.

The 17-year-old FreeBSD NFS bug. The 27-year-old OpenBSD TCP race. The 16-year-old FFmpeg H.264 heap overflow. All recognised CWE categories. The novelty in Mythos's disclosed findings is the location, not the class.

If known classes have known structural signatures, then a structural pattern matcher pointed at the right files can surface a meaningful fraction of those same classes without LLM inference cost. That structural pattern matcher is Singularity.

“Singularity identifies files whose structure matches the spectral signature of a known weakness class. It does not confirm exploitability. It prioritises where human review and downstream tools should look first.”
Two layers, one workflow

Same instrument. Second deliverable.

Event Horizon and Singularity ship from the same scanner. Same structural-recognition engine, same deterministic discipline. The inventory layer earns trust first; the signature layer extends it.

Event Horizon

Inventory layer

Event Horizon scans C/C++ code and maps structural crypto fingerprints. It tells teams where crypto-like structure is present and how files cluster by form. Four buckets: Unknown / Boundary / Consistent / Mute.

Singularity

Structural-signature layer

Singularity applies deterministic structural signatures for known weakness classes and ranks files into review buckets. It is a triage layer for expert investigation. Four buckets: Signature-Match / Signature-Adjacent / Signature-Cleared / Out-of-scope.

Singularity buckets

Every file-class result lands in one of four buckets.

Four buckets, mirroring the Event Horizon inventory layer's four-bucket discipline. No bucket asserts a vulnerability finding. Every bucket is a triage signal.

Signature-Match

Core structural signature present. Candidate for prioritised review.

Signature-Adjacent

Related structure present; full signature does not fire. Review as secondary queue.

Signature-Cleared

Clearing structure present for this class. Historically vulnerable family, currently hardened shape.

Out-of-scope

File form does not match this class context.

Phase 0 certification status

All configured thresholds and sample floors are satisfied.

Phase 0 defines the minimum sample floors and calibration thresholds a structural-signature class must satisfy before it can ship as a preview deliverable. The current state of those gates:

PASS
Phase 0 status
All configured thresholds and sample floors are satisfied. No current blockers.
TPR floor (strict)
≥ 0.85
FPR ceiling (strict)
≤ 0.10
Min curated positive
≥ 20 per class
Min curated negative
≥ 20 per class
Per-class calibration evidence

Strict-match performance on curated labels.

Calibration metrics from the Phase 0 curated label set. Production-threshold claims are not yet made; each class is at preview level.

Class Positives Negatives TPR (strict) FPR (strict) Precision (strict) Production claim
R2-HEAP-OVF-PARSER 22 68 1.000 0.000 1.000 Preview — not claimed
R2-INT-OVF-SIZE 21 69 1.000 0.043 0.875 Preview — not claimed
R2-UAF-STATE 24 52 1.000 0.000 1.000 Preview — not claimed
Validation pack bucket distribution

Where the Phase 0 detectors send files.

Total bucket assignments across the full Phase 0 validation pack (every file-class result from the three Phase 0 detectors):

Signature-Match
70
Signature-Adjacent
2,774
Signature-Cleared
166
Out-of-scope
3,410
FFmpeg libavformat benchmark

Recall@K — triage concentration on a historical fix corpus.

A practical large-sample Recall@K proxy on FFmpeg's libavformat module. This benchmark reports how concentrated security-fix-related files (identified by keyword in commit subjects) are within higher-ranked structural hotspots.

Of 53 historical commit-file pairs identified by security-relevant keywords (52 of which are in the heatmap), the following fractions appear within the top-K ranked structural hotspots:

@1
0.250
@5
0.288
@10
0.327
@20
0.558
@50
0.635
@100
0.827
@200
0.885

Claim boundary

Calibration evidence only; not exploitability proof. These outputs prioritise where human and downstream security analysis should focus first. Singularity does not confirm exploitability, reachability, or security impact — it identifies structural signatures consistent with known weakness classes and surfaces candidates for human review.

Honest constraints

What Singularity is — and what it is not.

The product's defensible perimeter is structural classification. The honesty rails below name what Singularity does not do so that when we describe what it does, it can be believed.

Singularity is

  • A deterministic, on-premises, hand-written structural-signature instrument
  • A triage layer that ranks files into four review buckets, mirroring Event Horizon's inventory discipline
  • The upstream step that makes downstream tools (AI scanners, SAST, red teams) economically and operationally rational
  • An auditable, reproducible measurement — same input gives same output, every time, forever
  • Calibration evidence: structural signatures consistent with known weakness classes

Singularity is not

  • A bug-finder. Downstream tools and human reviewers confirm exploitability.
  • A CVE database scanner. Singularity matches structural signatures, robust to refactoring and reimplementation.
  • A SAST replacement. SAST finds bugs by data-flow or rule matching. Singularity locates files where structural conditions historically associated with bug classes are present. Different layer.
  • A Mythos competitor in framing. Singularity is the structurally defensible map of where confirmation effort should be directed.
  • A production-claim instrument today. Phase 0 is preview calibration; production claims require gap-closure work still in flight.
Availability

Singularity is not for sale yet. Join the waitlist.

Singularity is Phase 0 — a calibration preview, not a shipping product. It is not sold, bundled, or promised as a deliverable while it is at preview status. When it reaches production-claim, the waitlist is told first.

What happens between now and then

  • NowPhase 0 calibration preview. Detector families and thresholds published as evidence, on this page.
  • NextCatalogue expansion — additional weakness-class families calibrated and evidenced.
  • ThenExternal ground-truth validation against in-the-wild codebases, not only seeded labels.
  • Production-claimSingularity becomes a standard output of every Event Horizon scan. Waitlist is contacted first.

Event Horizon is the product you can buy today. Singularity is the layer being built on top of it — shown here so you can judge the evidence yourself, not so it can be sold ahead of what it can prove.

Singularity is preview today, production-claim tomorrow.

As the catalogue expands and external validation completes, Singularity becomes a standard output of every Event Horizon scan. Join the waitlist and you will hear when it does — or talk to Rob directly.

Join the Singularity waitlist

rob@maxifai.com