Open Source Projects

We believe in building in the open and contributing to the broader community. Here are some of the projects we've built or are actively working on.

Sigstore

Production

Sigstore is an open-source software supply chain security project that provides cryptographic signing and verification for software artifacts. It eliminates long-lived signing keys by using short-lived certificates tied to OpenID Connect identities. The system includes Cosign, Rekor, and Fulcio, creating a comprehensive solution for establishing provenance and integrity in software distribution.

Technology Stack

GoCryptographyTransparency LogsX509 Certificate Signing

AgentUP

In Development

The Operating System for AI Agents. Built on operating system principles, AgentUp provides a robust foundation for creating AI agents through its highly extensible architecture. Its pluggable design lets you customize and add functionality without touching core code - giving you the flexibility to build exactly what you need while maintaining system stability, and ensuring your agents are portable and maintainable.

Technology Stack

AI/MLFastAPIPydantic

Akta

Research Phase

Akta is a prototype project designed to enable secure and verifiable interactions between AI agents. It establishes a framework for time-bound capability-based access control, allowing agents to delegate tasks and share resources with fine-grained control. The system leverages decentralized identity and verifiable credentials to create a cryptographically and auditable environment for autonomous agent operations.

Technology Stack

AI/MLPythonDecentralised IdentityVerifiable Credentials

Promptwright

In Development

Create huge datasets for model training or Agent evals. Used by Hugging Face and numerous other organizations and researchers.

Technology Stack

Synthetic DataModel DistillationLLM / Agent Evaluation

Bandit

Production

Bandit is a Python security analysis tool that identifies common security vulnerabilities in Python codebases through static analysis. It examines source code for security issues like SQL injection, hardcoded passwords, and unsafe cryptographic practices. The tool integrates into development workflows through CI/CD pipelines, providing configurable reports to help developers address security flaws.

Technology Stack

PythonSecure CodingAST

Sigstore A2A

Research Phase

Sigstore signing of the A2A (Agent-to-Agent) protocol providing full provenance attestations of an AI Agent's origin. Enables verifiable supply chain security for AI agents through cryptographic verification, identity constraints, and transparency log verification using short-lived certificates.

Technology Stack

PythonSigstoreSLSACryptographyAI Agents

Want to learn more about the Vision?