Black Cube Defence (Pty) Ltd · Reg. 2017/254145/07 · South Africa DSM-SOC · Digital Social Media Security Operations Centre
The platform

One capability, from first mention to measured response.

DSM-SOC watches the public information environment around a principal 24×7, turns raw noise into graded, decision-ready intelligence, counters manufactured narratives with lawful measured response — and, when the evidence justifies it, anticipates the next surge before it breaks. Every judgment carries its confidence, its sources and its audit trail. Every claim the client repeats in public can be traced to evidence within the hour.

Phase 1 · See Phase 2 · Respond Phase 3 · Anticipate One append-only spine Configuration gates, never rebuilds
Screen 37 · Build view

One picture of the machine.

Collection adapters into an append-only event stream; analytic services that propose; a human gate no output can bypass; six client and operator surfaces. Phase 3 services land on the same spine behind configuration flags. Phases never fork the system.

Confidential — client use only Specimen — fictitious data For the build team
Black Cube Defence · Build View · System Architecture

One picture of the machine

Collection adapters → evidence store + event stream → analytics → human gates → client surfaces · one data spine, three phases, no rebuilds

Normative · Build Scope §1
x_publicfb_publictiktok_public news_rsschannel_samplerbroadcast_monitor media_forensics posts · profiles · trendsgroups · pagesvideo · captions 38 outlets · blogspublic WA/TG · sampledsimulcasts · summaries P3 · synthetic sweep APPEND-ONLY EVENT STREAM + EVIDENCE STORE (hashed, immutable) every mention, flag, decision, alert and release is an event · analytics read ONLY from here · SA-region resident classify_sentimentdetect_anomalycluster_cibnarrative_tracker forecast_enginenetwork_mappersynthetic_detector 5 languages · P1baselines · velocity · P1fingerprints · templates · P1register · lifecycle · P1 P3 · trained on P1–2 corpusP3 · cross-platformP3 · voiceprint-tuned HUMAN GATE — VALIDATION QUEUE · QA REVIEW · RELEASE APPROVAL nothing machine-classified is reported unreviewed · nothing AI-drafted reaches a client surface without a named decision Analyst WorkbenchCommand CentreReport Factory Client PortalResponse Cell BoardAdmin & Config queues · casework · ACHP1 dashboard → P3 commandWIR · MER · ALR · EDB library · decisions · receiptsP2 ops · enforcement · E&Mclient config · SLA · audit COLLECTION ADAPTERS (PUBLIC SOURCES ONLY) ANALYTIC SERVICES (MACHINE-PROPOSED) CLIENT & OPERATOR SURFACES Data spine (one, append-only) Human gates (contractual) Phase 3 services — same spine, no rebuild every adapter has a documented contract + certified stub
ARCH-01…07 normative · adapters swap per client/country · core code contains no client logic Phases add services around one spine — they never fork the system

The one-sentence architecture. One append-only data spine; analytic services propose; named humans dispose; phases are configuration gates earned by evidence. A second principal, a second ministry or a second country is a configuration file — a deployment, not a rebuild.

Phase 1 · See · Running

Separating what is observed from what is assessed.

Sources graded on the Admiralty scale, probability words fixed to numeric ranges, attribution tested against competing hypotheses rather than asserted, and every machine classification human-validated before it reaches a report. When an attack is artificial, the client can prove it — documented behaviourally, not alleged — and calibrate the response to real opinion instead of manufactured outrage.

01–02

The picture

The week in one look, and the split that decides the response: excluding cluster-amplified content, the week's negative shift nearly vanishes. Organic criticism is specific and remediable; amplified criticism is generalised and accusatory. They require different answers.

03–04

The register

Every storyline under observation, graded CRITICAL to POSITIVE, each carrying origin with source grade, trajectory, authenticity split, verification status and escalation tripwires. Registering a claim never endorses it.

05–07

The proof

Six mutually corroborating behavioural indicators, the creation-date histogram, the template library with its replicated typo, DISARM technique mapping — and structured attribution scored against rival hypotheses.

Confidential — client use only Specimen — fictitious data DSM-SOC · 24×7
Black Cube Defence · DSM-SOC · Sentiment Intelligence

What is real opinion — and what is manufactured

AI-assisted classification across en · zu · xh · st · af · human-validated on every high-impact item

Live Week 27 Jul – 02 Aug Precision 85–88% on code-switched
Sentiment distribution
Share of 247,860 classified mentions
247.9k MENTIONS
Positive29.7%
Neutral41.9%
Negative28.4%
Excluding cluster-amplified content, negative share would be ≈24.9% — a shift of +2.6 pts, not +6.1 pts.
Daily sentiment trend — the 30 July event is visible, and artificial
Negative share peaked at 38% on Fri 31 Jul before partially recovering
40%30% 20%0% Mon 27Tue 28Wed 29 Thu 30Fri 31Sat 01Sun 02 06:02 cluster launchMinistry statement Positive share   Negative share   -- Neutral intervention markers annotated by the duty analyst
Organic vs amplified — the split that decides the response
Negative mentions attributed by cluster fingerprint
Organic negative (genuine, mostly specific & remediable)58%
Cluster-amplified negative (CL-2026-019)34%
Undetermined8%

Organic criticism is specific and remediable ("when will Ward 14 be connected?"). Amplified criticism is generalised and accusatory. They require different answers.

Reaction ratios by programme
Positive reactions among engaged users
N-02 Limpopo electrification71%
best quarter
N-03 Sizanani Youth Works64%
Ministry corporate content38%
#KhanyisaSA campaign hashtag 31% ▼ sarcasm quote-posts +34% w/w

Early indicator: the campaign hashtag itself may be contested territory next week — hijack watch I-5 is live at the 30% trigger.

Language of conversation
Share of classified mentions · glossary-protected terms stay English
English54%
isiZulu19%
isiXhosa11%
Sesotho9%
Afrikaans7%
All high-impact items human-corrected; sarcasm and code-switching precision limits are declared, not hidden.
Feeds WIR §3 · classification model + analyst validation · thresholds in client configuration What is observed is separated from what is assessed — everywhere

Screen 02 · Sentiment Intelligence. The number that changes the decision is not the negative share — it is the fact that a third of it was manufactured, and that the organic remainder names a fixable delivery problem.

Phase 2 · Respond · Month 3 gate

Intelligence turned into lawful action.

Alerts become action inside agreed rules of engagement: claims graded against evidence within four hours; verified facts published faster than falsehood spreads; inauthentic networks removed through the platforms' own rules, tracked to conclusion; credible neutral voices equipped with checkable material; and every campaign measured — framing shift, share-of-voice decay, honest attribution.

The seven-stage response cycle

Every action has an owner, a status and a measured result. The doctrine is fixed: respond to the claim, never the hashtag; never engage inauthentic accounts directly; measure the framing shift every news cycle.

DetectVerifyDecide RespondEnforceAmplifyMeasure

Message discipline — approved lines

Core line. "The contract followed the full prescribed procurement process. Evaluation scores and the audit trail are published; we invite anyone to examine them."

Bridge from the hashtag. "We understand the concern. Here are the facts, and here is where to verify them independently."

What we do not do. Engage, name or amplify inauthentic accounts; speculate on motive; over-claim.

Confidential — client use only Specimen — fictitious data Phase 2 · Response Cell
Black Cube Defence · Phase 2 · Response Command Dashboard

Who is winning — one shared picture

Every active response operation, enforcement progress, the verification queue and the early-warning watchlist · runs on Phase 1 tooling, no new platform

Live Snapshot 14 Aug Review Fri 10:00
Composite risk indexModerate
54/100
▼ −14 since 30 Jul · back below ELEVATED
Active response ops
3
N-04 · #KhanyisaFail watch · exec protection
Cluster removalOn track
74%
158 of 214 accounts actioned
Active operations board
Stage-coloured per the response cycle · owner and next review on every line
OpNarrativeStageOwnerNext
NRP-011N-04 tender allegationAmplify · day 9Comms + Response CellDaily review
ENF-019CL-2026-019 takedownsEnforce · 56 pendingBlack Cube DefenceWeekly tracker
WATCH-021#KhanyisaFail variantDetect · seeded by known amplifiersDuty analystCluster-linkage test
EDP-004Executive digital protectionSteady · 2 impersonations downResponse CellMonthly harden

Doctrine on every op: respond to the claim, not the hashtag · never engage inauthentic accounts directly · measure framing shift every news cycle.

Verification briefsIn SLA
5
Median turnaround 3h 52m · SLA ≤4h
Alert → response
74min
Limited by approvals, not analysis
Verification queue
4-hour SLA from tasking
VB-07 · R48m tender steering claim
FALSE / UNSUPPORTED · 3h 52m · deployed reactively
VB-08 · "Ward 14 was promised June"
PARTLY TRUE · date was Q3 target — rebuilt with schedule
VB-09 · #KhanyisaFail seed claim
In assessment · due 14:00 · analyst B
Grades issued this month — TRUE 1 · PARTLY 3 · FALSE/UNSUP 4
Early-warning watchlist
Expanded channel sampling · by-election window
#KhanyisaFail — new hashtag variant Rising
Seeded by known amplifiers · 3,400 uses · linkage test running
By-election "referendum" frame Building
Forecast to intensify to 26 Aug · pre-positioned material ready
Load-shedding rumour (Khanyisa-linked) Incubating
Incubating in two community groups · 24–48h lead time
CL-2026-019 re-activation Quiet
Fingerprints silent since 01 Aug · tripwire armed
Phase 2 is service-led: people and playbooks on existing tooling — affordable now, and it scales down as easily as up Phase 1 tells you; Phase 2 turns intelligence into action

Screen 13 · Response Command Dashboard. Risk back below ELEVATED, three active operations with stages and owners, the verification queue inside its four-hour SLA, and the early-warning watchlist for the by-election window — one shared picture on existing tooling.

Phase 3 · Anticipate · Month 12+ gate

Anticipation, earned from evidence.

Phase 3 is the platform, and it is specified from two phases of the client's own record — which is exactly why it is aimed at their real threats rather than a brochure's. The forecaster learns from observed narrative lifecycles. The network mapper is calibrated on real coordination signatures. The deepfake detector knows the principal's verified voice. The risk weights reflect what actually threatened this client — not a vendor's averaged industry profile.

Forecast

The surge before it breaks

Five weeks of forecast per narrative with confidence bands and a published backtest hit-rate. Every miss is reviewed monthly and the model retrained. A forecast is decision-support — never a headline.

Detect

Is this recording real?

Acoustic forensics, biometric voiceprint comparison against the consented baseline, breath and prosody analysis, provenance. A fabricated clip caught at three accounts and ~1,200 plays, with the rebuttal kit pre-built.

Command

The highest-tempo fortnight

Election mode is a configuration, not a build: the same platform compressed to what matters in the final twelve days — provincial pressure, integrity watch items, a countdown forecast. Issue-mood only; never candidate polling.

Confidential — client use only Specimen — fictitious data Phase 3 · Intelligence Platform
Black Cube Defence · Phase 3 · Executive Threat Command Centre

Everything, on one screen, in real time

The single pane of glass every Phase 3 capability feeds — every AI output reviewed by a duty analyst before it surfaces

Live · all feeds 06:00 brief issued Duty analyst · shift A
Composite riskModerate
54/100
▼ −2 overnight
Forecast · by-election weekRising
W+3
Hostile peak · 80% confidence
Synthetic media flagConfirmed
1
SD-2026-014 · contained early
Active threat clusters
2
CL-019 residual · CL-022 forming
AI outputs awaiting reviewHuman loop
4
Oldest 6 min · analyst-gated
Entity risk — principal
58
Model-scored hourly · analyst-weighted
Live intelligence feed
Machine-proposed · analyst-disposed — nothing surfaces unreviewed
05:58  Forecast update: #KhanyisaFail projected to cross 10k uses by 17 Aug (likely, 55–80%)
Analyst approved
05:41  Cluster watch: 12 new accounts match CL-2026-019 fingerprints at 0.88 similarity — provisionally grouped CL-2026-022
In review
05:22  Enforcement: overnight platform action removed 12 further cluster accounts (total 170 of 214)
Verified
04:50  Synthetic media: SD-2026-014 rebuttal pack holding · no re-uploads detected in 6h sweep
Verified
04:12  Narrative: N-04 SOV 8%→7% · decay on model · no action proposed
Auto-logged

The safeguard that keeps automation trustworthy: the platform proposes; the analyst disposes. Every card above carries its review state.

Entity risk scores
Model-scored hourly · analyst-weighted
E-01 · The Principal58 · MODERATE
E-03 · Project Khanyisa52 · MODERATE
E-02 · Infrastructure agency44 · GUARDED
E-07 · Sizanani Youth Works18 · LOW
E-06 · Deputy Minister22 · LOW
Daily executive brief — 06:00
AI-generated, analyst-reviewed · writes itself from the risk matrix

Overall risk MODERATE (54/100, ▼2). N-04 continues to decline (SOV 8%→7%); overnight enforcement removed 12 further cluster accounts. Two items rising: #KhanyisaFail seeded by known amplifiers, and the contained synthetic-audio deepfake of the Minister (94% AI-probability). Forecast: hostile-narrative pressure will rise into the 26 Aug by-election peak (W+3, 80% confidence). Recommended focus today: sustain positive delivery amplification in the Eastern Cape; hold the deepfake rebuttal ready; watch #KhanyisaFail for cluster linkage.

AI-draftedAnalyst reviewed · shift A
Issued 06:00 · read receipt: Chief of Staff 06:14
Warning watchlist
!
Document-drop on N-04
Unlikely · high-impact · tripwired I-1
!
Deepfake re-upload wave
Fingerprint sweep 6-hourly
!
Final-week amplification surge
Forecast peak W+3 · pre-positioned
In a fast-moving incident, fragmented tools cost minutes and minutes cost reputation One authoritative screen keeps everyone on the same truth

Screen 21 · Executive Threat Command Centre. Composite risk, the forecast, synthetic-media flags, active clusters, entity scores, the live feed with its review states, and the 06:00 brief that writes itself from the matrix — with the safeguard on every card: the platform proposes, the analyst disposes.

Confidential — client use only Specimen — fictitious data Phase 3 · Intelligence Platform
Black Cube Defence · Phase 3 · Predictive Narrative Analytics

Which storyline surges next — and when

Learned from the lifecycle of thousands of narratives observed in Phases 1–2 · the difference between bracing for impact and preventing it

Model run 14 Aug 04:00 Backtest hit-rate 78%
Narrative risk heatmap — observed and five weeks of forecast
Left column = observed this week · right = model forecast · read across each row
NarrativeObservedW+1W+2W+3 · by-electionW+4W+5
N-04 tender allegation Decaying
#KhanyisaFail variant Surge
By-election "referendum" Surge
Load-shedding rumour
Khanyisa delivery (organic)
lowsteady elevatedhighsurge forecast hostile peak — the week before the 26 Aug by-election
What the forecast changes
Acting a week early instead of a day late
1
Pre-position messaging for the W+3 surge
Spokespeople briefed and delivery announcements staged before the peak
2
#KhanyisaFail ranked highest-risk emergent
Enforcement pack template pre-loaded pending cluster confirmation
3
Load-shedding rumour flagged from incubation
Detected in community channels — 24–48h before it can trend

Model discipline: forecasts carry confidence bands and a published backtest hit-rate; every miss is reviewed monthly and the model retrained on the growing corpus. A forecast is decision-support — never a headline.

Why this could not be built first: the model is trained on narrative lifecycles observed in Phases 1 and 2 for this client's actual threat environment. Built earlier, it would be powerful in theory and mis-aimed in practice.

Forecast horizon 5 weeks · re-scored daily · confidence bands on every cell Anticipation is earned from evidence, not bought from a brochure

Screen 22 · Predictive Narrative Analytics. Five weeks of forecast per narrative: the tender story decaying, the hashtag variant and the referendum frame surging into the by-election week.

Screen 44 · Delivery

Each phase earns the next.

The commercial architecture and the build plan are the same drawing. A single large leap of faith is replaced by three deliberate steps — so by the time the platform is bought, its specification was written by the client's own results.

Confidential — client use onlySpecimen — fictitious dataBuild view
PHASE 1 — SEE · running PHASE 2 — RESPOND · service-led PHASE 3 — ANTICIPATE · platform build monitoring spine · registers · validation queue report factory (WIR/MER/ALR/EDB) · SLA telemetry evidence vault · baselines · tripwire engine deliverables: 4 recurring products · current retainer response cell board · verification workspace enforcement tracker · effectiveness scorecards channel sampling · executive protection kit modest retainer uplift · real ops capex: on existing tooling forecast engine · network mapper · synthetic detector risk scoring · election mode · AI oversight console workflow automation (the 74-min lesson) · command centre capex+opex justified by two phases of measured evidence GATE · Phase 2 goGATE · Phase 3 scopeGATE · Phase 3 build M3M8M12 M0M18 validated alerts flowing · response need demonstrated RoE + legal sign-off · named client owner documented record + measured effectiveness automation needs identified · funded scoping only evidence-based spec + costed business case build in increments against the same spine Build sequencing (P3):oversight console and model registry ship FIRST — the gates exist before the first model output can reach anyone. Acceptance:every module carries acceptance criteria by requirement ID; a phase gate opens on evidence presented against them, witnessed and recorded. Standing rule:the platform never forks per phase — capabilities land behind client-config flags on the one spine, reversible and auditable.
In one sentence: a single large leap of faith replaced by three deliberate stepsEach phase earns the next