Trustworthy systems
for the agent era.

Open-source infrastructure that makes AI agents, cloud development, and software supply chains safe enough for real work.

100% open source · 113 repositories · 6K+ followers

113
Repositories
public on GitHub
6K+
Followers
across GitHub & LinkedIn
33
Recommendations
from peers & leaders
100%
Open source
tools built in the open
Selected work

Work that stands on its own

Distinct builds across agent infrastructure, developer tools, supply-chain security, secure data exchange, and local cloud infrastructure — each with its own brief and craft.

Agent infrastructure

Aletheia

The unconcealment layer for autonomous agents.

Twelve products on one stack — governance, verification, optimization, infrastructure and the physical frontier. Every action an agent takes is constrained, verified, attributed and auditable, so nothing it does can be hidden.

  • Layered constraint enforcement — each layer bounds the one below
  • Formal verification of agent-generated code against specifications
  • Causal provenance graphs with cost and energy attribution for every decision
  • Self-healing infrastructure with regression detection and rollback
Explore Aletheia
AI Coding Agent

ax

The AI coding agent built without the trade-offs.

A terminal-native coding agent with local-first architecture and security-first defaults. Multi-provider, cost-aware, and secure by default — own your agent instead of renting it from a single vendor.

  • Multi-provider: Anthropic, OpenAI, Gemini, Ollama, vLLM
  • Local-first architecture with security-first defaults
  • 30+ built-in tools, sub-millisecond code search, 253 tests
Explore ax
Evolutionary code engine

EvolveHandsAI

Code that breeds better code.

An evolutionary optimization engine that breeds implementations instead of prompting for them. Define a fitness function and mark the mutable regions; an LLM ensemble evolves hundreds of candidates across island populations, MAP-Elites preserves diversity, and anything that breaks the tests is rejected automatically. The page itself runs a real engine in your browser — every gauge is live.

  • LLM ensemble — Claude, GPT-4o and Haiku with adaptive model weighting
  • MAP-Elites quality-diversity grid across feature dimensions
  • Island parallelism — 2–5 populations with periodic migration
  • Isolated Docker sandboxes: read-only filesystem, no network, 256 MB · MIT licensed
Explore EvolveHandsAI
Supply Chain Security

VIM

Vulnerability Inheritance Map.

Frontier models now find zero-days faster than anyone can track where they live. VIM is the lineage layer: an open-source graph database that maps a single upstream finding to every fork, vendored copy, and compiled binary that inherits it. Apache 2.0, targeting the OpenSSF Sandbox.

  • Traces vulns across forks, vendored deps & binaries
  • Graph-native blast-radius analysis
  • Apache 2.0 — aimed at the OpenSSF
Explore VIM
MCP Server

Wharf

A dock for your Managed Agents.

An MCP server that exposes Anthropic's Managed Agents API through a conversational interface. Deploy, message, update and retire autonomous agents — all from Claude, without leaving the chat.

  • MCP server for Anthropic Managed Agents
  • Deploy, message, update & retire from chat
  • Runs where your Claude client already is
Explore Wharf
Secure data exchange

X-Road

Secure data exchange that watches, predicts, and explains itself.

X-Road moves data between organisations with end-to-end integrity and non-repudiation. This edition adds an opt-in intelligence layer that runs beside the system — reading operational metadata only, never a payload, never in the signing path — to detect anomalies, correlate incidents and brief operators in plain language.

  • Anomaly detection over federated temporal call-graph models
  • Collapses edge alerts into correlated incidents, with breach forecasting and confidence scores
  • Grounded copilot — source-cited, plain-language incident briefings
  • Read-only sidecar on X-Road 7.8.1 · 0 payloads read · advisory-only · MIT
Explore X-Road
Local cloud for agents

LoopbackCloud

The local cloud for AI agents.

Runs AWS, Azure and GCP on your own machine so agents — and the people building them — can provision and stress real resources with zero spend and zero blast radius. The same SDKs, CLIs and IaC you already use, behind one unified console with a gated multicloud interconnect.

  • 70+ services across AWS, Azure & GCP in one local stack
  • Drop-in for standard SDKs, CLIs, Terraform & CDK
  • Built-in MCP server so agents can inspect, provision and stress real infrastructure
  • Native GraalVM image — 24 ms cold start, MIT licensed
Explore LoopbackCloud
Trust isn't a feature you bolt on at the end. It's the architecture you start with — in your agent, your cloud, and your supply chain.
Abdul Jaleel Kavungal — the studio principle

Let's build something worth trusting.

Open to opportunities, collaborations, and design-partner conversations across AI, platform engineering, and supply-chain security.