Open core

Open where trust requires inspection.

The local engine, CLI, MCP server, formats, fixtures, and evidence verifier are intended for public inspection after the release gate.

A clean public boundary—not a publicized private monorepo.

The future public repository will begin with fresh history and an explicit allowlist after brand clearance and a security review.

01

Local engine

Scan, simulate, repair, verify, and export without a hosted account.

02

Open formats

CycloneDX-compatible inventory, signed capsules, and portable evidence.

03

Agent interface

Local MCP resources and permissioned tools.

04

Reproducible fixtures

TypeScript and Python consumers plus public ChangeBench cases.

05

Commercial network

Hosted aggregation, registry, intelligence, console, and enterprise controls remain private.

06

Release gate

MIT license selected. Repository remains private until brand and security gates are complete.

Make the next change survivable.

Start with the local engine. Connect the network when it creates value.

Start building