A return path for collective defense

nur

from shared guidance to aggregate action

Trusted security communities are good at sending alerts and guidance. The missing loop is what happened next: did members act, what blocked them, and should the guidance be repeated, revised, or retired? nur is testing a 60–120 second categorical action receipt for that return path.

4 Categorical outcomes
<2m Proposed response time
0 Real member records

Concept artifact only: synthetic data, no collection endpoint, and no production anonymity or security claim.

Security communities know what they sent. Not what changed.

The first user is a program lead inside a trusted information-sharing community deciding which guidance to repeat, revise, or retire. The hypothesis is that a tiny return path can produce a more useful decision signal than opens, downloads, or a long attributable survey.

1. Guidance goes out

The community keeps the trusted channel it already has. nur begins after one specific recommendation is distributed; it is not another threat-feed or vendor marketplace.

2. A member returns one small signal

Implemented, planned, blocked, or not applicable—plus a coded blocker and coarse timing. The concept is designed to take less than two minutes and avoid free-text posture disclosure.

3. The coordinator gets an aggregate

The prototype demonstrates a minimum-cohort release rule and an aggregate coordinator view. It contains no member-provided or organization-provided data and has no collection endpoint. Open the prototype →

Distribution already exists. The outcome evidence does not.

nur is testing the space between a recommendation and the next coordinator decision.

Vendors see only part of the outcome.

A vendor can observe its own product, but not the full member workflow or why an organization could not act on community guidance.

Traditional feedback is expensive.

Interviews and long surveys can produce rich answers, but they arrive slowly and may ask members to reveal more attributable security posture than the decision requires.

nur starts with the smallest useful return.

One categorical receipt cannot prove effectiveness. It can test whether low-burden, cohort-gated feedback changes a real coordinator decision before a larger system is built.

Public binaries reveal presence. Not effectiveness.

A static July 2026 scan applied 44 SDK signatures to 320 public-app records and detected 27 SDKs across 11 categories. The alphabetically biased sample is not representative, and code presence does not establish use, configuration, or effectiveness. That limitation is what pointed nur toward the missing return path.

# Start with the current hypothesis
open https://getnur.org/prototype/action-receipt

# Then inspect the public-binary experiment
open https://getnur.org/sdk