Explore research

Research blog

Incident intelligenceBlog

Why alarm correlation needs a causal model, not a time window

Rule engines group alarms by closeness in time and space. We look at what that misses when background noise rises, and what a self-exciting model does differently.

Raincurve Research · Sep 2026
RemediationBlog

What trading desks can teach a NOC about rollout pacing

Optimal execution and network remediation share the same trade-off: move fast and pay in churn, move slowly and pay in exposure.

Raincurve Research · Sep 2026
Formal methodsBlog

Runbooks are not proofs: checking actions against live state

Most unsafe maintenance actions look safe in isolation. Here is why the check has to see in-flight work and lost backup paths.

Raincurve Research · Sep 2026
SystemsBlog

Inside Curve-1: from raw telemetry to ranked hypotheses

A walkthrough of the four stages that turn fragmented operational signals into an explainable root-cause ranking.

Raincurve Research · Sep 2026
Incident intelligenceExperiment note

Turning Alarm Floods into Incidents with Hawkes Processes

Topology-aware Hawkes models find the root-cause device for 75% of simulated incidents vs 42% for tuned rule-based correlation, with no labels.

Raincurve Research · 2026
RemediationExperiment note

How Fast Should a Network Fix Roll Out? Almgren-Chriss for Operations

Optimal-execution pacing from trading, adapted to network rollouts. A hard churn limit cuts expected damage 43% vs plain Almgren-Chriss.

Raincurve Research · 2026
Formal methodsExperiment note

Proving a Network Action Is Safe Before It Runs

Runbook checks approved 98% of unsafe actions. Exact graph methods made zero errors and check 14,680 devices in 0.19 s.

Raincurve Research · 2026
SystemsPaper

Curve-1: A Reasoning Architecture for Cross-Layer Infrastructure Intelligence

A staged reasoning pipeline that converts fragmented operational telemetry into ranked, explainable root-cause hypotheses in near real time.

Raincurve Research · 2026
SystemsPaper

Compact Contracts: Compressing Telemetry for Cross-Layer Reasoning

A compression layer that preserves cross-layer diagnostic context while reducing raw MELT telemetry volume by roughly 6,000×.

Raincurve Research · 2026
SecurityPaper

Firecracker Sandboxing for Secure Execution

A microVM and copy-on-write snapshotting model for safely executing reasoning and remediation workloads inside customer infrastructure.

Raincurve Research · 2026

Make infrastructure intelligence operational.

Start with a conversation about your environment.