Who does the work
Two of the four levels are somebody's time rather than a pipeline. Nothing here was written from what anybody told us: every line is read off a published page, with the page and the date it was read.
Sources
- https://open-source.sgit.ai/about/index.html↗ — read 16 September 2026. The author page on open-source.sgit.ai, published CC BY 4.0. Every row of the record below is read off it.
- https://sgit.ai/demos/vaults/index.html↗ — read 16 September 2026. The published vault catalogue, which is where the delivered work is.
Dinis Cruz
Runs the correction at £500 and the two sessions at £1,500.
Founder of the sgit.ai network, RiskMandate.ai, The Cyber Boardroom, MyFeeds.ai and VoiceDebrief.ai; former OWASP Board member and organiser of the OWASP Summits; creator of the O2 Platform.
Why them: The method this store sells is theirs. The fifteen published templates, the grant-and-mandate model, the delta and the barrier taxonomy, and the six published vaults of exactly this work were all built by the person who would be doing yours.
- Former OWASP Board member — And organiser of the OWASP Summits — Lisbon 2011 and Woburn 2017 — the working-session format that the Open Security Summit series went on to build on. Open-source work still ships under the
owasp-sbotorganisation. - Creator of the O2 Platform — The OWASP static-analysis engine of 2010 to 2012, and the first of a line of open-source tooling that continues in the
osbot-*andmgraph-*families,memory_fs,Issues-FSandsgit-ai— all Apache-2.0, all on PyPI. - Founder, RiskMandate.ai — The business risk layer for autonomous systems — the site the fifteen Agent Behaviour Policy templates this store sells are published on.
- Founder, sgit.ai and sgraph.ai — Encrypted vaults with git semantics, under Apache-2.0, and the network of nineteen sites of which this store is one. Each site publishes its argument before its implementation, so the commitments stay checkable.
- Founder, The Cyber Boardroom and MyFeeds.ai — A platform for the conversation between technical security teams and the board, and role-aware security briefings built on semantic knowledge graphs — CISO, engineer and board views of the same material. Both Apache-2.0.
- Works in the open, including the parts most companies do not — The code is Apache-2.0, roughly 1,100 working documents are CC BY 4.0, and the investor materials for two of the companies are on GitHub rather than behind a data room.
This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0).