XUNIA Authorized Security • Knowledge Graph • AI Triage • Remediation
The Red House is XUNIA’s authorized adversarial-security and remediation layer. It converts controlled security testing into structured findings, ontology-ready relationships, prioritized risk, evidence, and reviewable fixes that can flow back into the wider XUNIA ecosystem.
XUNIA Ecosystem Guide · Ecosystem Manifest · Full RedAmon Documentation · Security Policy
AUTHORIZED USE ONLY: The Red House is for systems you own or have explicit written authorization to assess. Cross-house membership, repository access, or ecosystem affiliation does not create authorization to test an external target.
XUNIA HQ / CONTROL PLANE
↓
🔴 THE RED HOUSE
├─ authorized reconnaissance
├─ controlled validation
├─ security knowledge graph
├─ AI finding triage
├─ risk normalization
└─ remediation / reviewable PRs
↓
SHARED XUNIA ONTOLOGY
↓
BLACK HOUSE • GREEN HOUSE / BIO • ZYRA • APPROVED SERVICES
The Red House wraps the upstream RedAmon security framework with a XUNIA integration contract. The underlying project provides containerized reconnaissance, security validation, Neo4j attack-surface graphs, AI-assisted triage, and remediation workflows. The XUNIA layer adds ecosystem identity, ontology bindings, cross-house boundaries, and machine-readable integration metadata.
| Object | Role |
|---|---|
Asset |
Approved host, service, repository, API, container, or environment |
Finding |
Normalized security observation or vulnerability |
Evidence |
Reproducible evidence attached to a finding |
Risk |
Severity, exploitability, exposure, confidence, and impact |
Relationship |
Graph edge linking assets, identities, findings, controls, and fixes |
Control |
Defensive policy or technical safeguard |
Remediation |
Proposed or implemented fix |
ChangeSet |
Reviewable code/configuration mutation |
Run |
Auditable execution record |
BIO / Green House boundary: biotechnology, health, pharma, research, or similarly sensitive workloads are treated as high-sensitivity and non-destructive by default. External activity requires explicit scope and authorization.
![]() Samuele Giampieri Upstream Creator, Maintainer & AI Platform Architect AI platform architect and full-stack lead behind RedAmon, with production experience across agentic AI, ML, cloud systems, and security automation. LinkedIn · GitHub · Devergo Labs |
![]() Ritesh Gohil Upstream Maintainer & Lead Security Researcher Security engineer and researcher with experience across Web, API, Mobile, Network, and Cloud penetration testing, CVE research, and security architecture. LinkedIn · GitHub |
![]() Douglas Brown XUNIA Ecosystem Maintainer & AI/Security Systems Builder Maintainer of the XUNIA / ZYRA integration layer, focused on governed agentic systems, security architecture, ontology-driven workflows, AI application development, and auditable human-controlled execution. ZYRA currently records a reconciled 34-record credential, training, and professional-development ledger with evidence tiered by issuer verification and supplied provenance. Selected credential evidence Palantir Foundry Aware · Introduction to Foundry & AIP for Enterprise Organizations · Deep Dive: Data Protection Tools in Foundry · Palantir Data Science Fundamentals · Google Cybersecurity Professional Certificate · Google AI Professional Certificate · IBM Quantum Machine Learning · Red Hat System Administration I training · Foundations of Business Intelligence. LinkedIn · GitHub · ZYRA Credential ledger |
Attribution boundary: Samuele Giampieri and Ritesh Gohil are identified here for their upstream RedAmon roles. Douglas Brown’s maintainer role applies to the sonoxo/theredhouse XUNIA integration/fork and does not imply maintainer status in the upstream
samugit83/redamonproject.
The Red House is built around the open-source RedAmon framework. To keep the complete technical documentation, architecture, installation instructions, tool matrix, security model, community information, and original maintainer material intact, the previous README is preserved verbatim here:
Upstream project: samugit83/redamon
Upstream website: redamon.org
The machine-readable integration contract lives at .xunia/ecosystem.json. Current Red House capabilities include:
- authorized reconnaissance and controlled security validation;
- security knowledge-graph generation;
- finding triage and risk normalization;
- remediation orchestration and reviewable GitHub PR flows;
- security telemetry export into approved XUNIA ontology consumers;
- explicit authorization context and human review for disruptive actions;
- no implicit cross-house authorization.
See XUNIA_ECOSYSTEM.md for the human-readable architecture and operating boundaries.
| Resource | Purpose |
|---|---|
XUNIA_ECOSYSTEM.md |
Red House role inside the ecosystem |
.xunia/ecosystem.json |
Machine-readable ecosystem identity and ontology contract |
UPSTREAM_REDAMON_README.md |
Preserved complete upstream-facing README |
SECURITY.md |
Security policy |
DISCLAIMER.md |
Authorized-use and legal boundaries |
LICENSE |
Repository license |
THIRD-PARTY-LICENSES.md |
Third-party licensing inventory |
ZYRA credential ledger |
Douglas Brown credential/provenance evidence used by this fork |
🔴 RED HOUSE // XUNIA
Authorized security in. Structured evidence out. Human control at consequential boundaries.



