AI · Threat Intelligence · Detection Assurance

Start with the threat.
Validate your defence.

X3M.AI connects threat understanding, controlled adversary emulation and AI-assisted evidence reasoning through Merlino and Morgana — free to download from Camelot.

A connected method

From organisational context to evidence

Validation only matters when it starts from what the organisation actually needs to protect. The method moves from context and relevant threats, through clearly scoped validation, to evidence that supports real decisions.

  1. 01

    Understand

    Organisation context, important services and exposure shape what actually matters.

  2. 02

    Prioritise

    Threat scenarios and a Threat Profile focus validation on the behaviours that matter most.

  3. 03

    Design

    A Catalogue and coherent Validation Packages define clear, traceable objectives.

  4. 04

    Validate

    Morgana plans controlled tests and gathers evidence in the real environment.

  5. 05

    Learn

    Detection reasoning turns evidence into confidence, gaps and priorities.

The ecosystem

Merlino & Morgana, one validation loop

Two products with equal weight and distinct responsibilities. Merlino explains why and what to validate. Morgana plans how, records what happened, and reasons over the evidence.

Merlino

Understands the threat

Merlino turns organisation context and threat intelligence into a Threat Profile and Catalogue — a structured, traceable view of what actually deserves validation.

  • Threat understanding and CTI
  • Assessment and relevance
  • Validation Package handoff
Explore Merlino →

Morgana

Operationalises validation

Morgana resolves what can actually be tested, plans controlled validation, executes it and gathers evidence — then reasons over what that evidence shows.

  • Planning and controlled execution
  • Evidence and telemetry
  • Detection reasoning and assurance
Explore Morgana →
How Merlino and Morgana connect into evidence and learning
MERLINOUnderstands the threatThreat Profile · CatalogueValidation PackagesWHY · WHATMORGANAPlans & executes validationPlans · TestsEvidence · reasoningHOW · WHAT HAPPENEDHANDOFFscope onlyEVIDENCE · ASSURANCEDetection reasoning, gaps, confidence, learnedLEARNING FEEDBACK
Merlino defines why and what to validate; Morgana planshow and records what happened. Evidence returns into learning for the next cycle.

AI across the validation lifecycle

Intelligence that stays under your control

Merlino combines assessment and AI-assisted threat analysis inside Excel. Morgana brings cognitive agents and evidence reasoning into operational validation. Together, they connect the reasons for a test with what the test reveals.

AI in Merlino

Analyse selected workbook context, run repeatable Promptbooks and produce AI-assisted explanations and report narratives — always reviewed by the analyst.

See Merlino AI

Morgana's cognitive core

The Executive Brain coordinates specialist cognitive agents and a local inference engine to support planning and evidence reasoning.

See Morgana AI
  • Human-approved scope — what gets validated is always a human decision.
  • Explicit execution authority — nothing runs without deliberate authorisation.
  • Evidence-backed conclusions — reasoning is anchored to what was observed.

Assurance that supports action

Evidence you can act on

The point of validation is not a score — it is knowing where your defences held, where they did not, and what to do next.

  • TraceabilityEvery conclusion traces back to a test and its evidence.
  • GapsVisibility and detection gaps become explicit, not implied.
  • ConfidenceConfidence is separated from raw relevance.
  • PrioritiesImprovements are prioritised by what the evidence showed.
See the methodology

Contact

Talk to the founder

Nino Crudele · Founder of X3M.AI

For product access, collaboration or a conversation about threat-informed validation, connect with Nino on LinkedIn.

Contact Nino on LinkedIn