Astrid is a portable, capability-secure operating system for composable software.
-
Updated
Aug 1, 2026 - Rust
Astrid is a portable, capability-secure operating system for composable software.
Jacquard is a small programming language designed for a regime in which most code is written by machine-learning models and reviewed by people.
An actor-based systems language that compiles to readable C. Native, no VM, no garbage collector.
Sandboxed plugin VM with typed capabilities, deterministic replay, and time-travel debugging — written in Rust.
Native Rust runtime for adversarial extension workloads with deterministic replay, cryptographic decision receipts, and fleet-scale containment.
A scripting language for cowboy coders
plan-bound authorization architecture for governing privileged effects in untrusted computational agents.
Electron runtime layer providing protocol-based separation, component assembly, and capability-based process control.
KAIROS-ARK is a high-performance, Rust-based Agent Runtime Kernel built for industrial-grade reliability. It delivers sub-100µs dispatch latency, event-sourced deterministic replay, and kernel-enforced capability sandboxing, bridging Python prototypes and production AI systems.
A statically-typed scripting language and bytecode VM for sandboxed execution of AI-generated code, built in C++ with no GC or JIT.
A ground-up Rust microkernel operating system exploring intent-centric computing, capability security, semantic knowledge, and privacy-first system architecture.
Agent-first display server: a small trusted core speaking a capability-native protocol, with every legacy app confined to its own per-app shim. Humans and AI agents operate the same GUIs under revocable, capability-scoped authorization.
Resource-safe, effect-typed programs in syntax you already know. A checked affine core with familiar Faces — JavaScript-, Python-, functional-, and pseudocode-shaped surfaces — compiling to typed WebAssembly.
The Estate's primary MCP server — GitHub, GitLab, and 115+ capability cartridges. Formally verified BoJ-server-ABI in Idris2 0.8.0 (%default total) with safety lemmas for credential isolation.
A capability-typed language that emits machine-verifiable supply-chain SBOMs by construction: per-function CycloneDX, SPDX, VEX and SLSA artefacts that match the code, not a scanner's guess.
my tinkering notebook (blog)
A capability-native research kernel for explicit authority, isolated execution, temporal state, and verifiable system boundaries. It is particularly efficient with WebAssembly
AXIOM Mesh 0.12.0-dev.3: local-first, fail-closed coordination kernel with zero-dependency setup, authenticated Gateway contracts, cryptographic evidence, and an experimental loopback AXIOM One PWA for governed owner memory and bounded provenance links. No live deployment or production promotion claimed.
A deterministic, deny-by-default safety membrane for machine-generated software. One .bio constitution, three membranes, two products. Patent pending.
Add a description, image, and links to the capability-security topic page so that developers can more easily learn about it.
To associate your repository with the capability-security topic, visit your repo's landing page and select "manage topics."