Astrid is a portable, capability-secure operating system for composable software.
-
Updated
Sep 24, 2026 - Rust
Astrid is a portable, capability-secure operating system for composable software.
Jacquard is a small programming language designed for a regime in which most code is written by machine-learning models and reviewed by people.
An actor-based systems language that compiles to readable C. Native, no VM, no garbage collector.
Sandboxed plugin VM with typed capabilities, deterministic replay, and time-travel debugging — written in Rust.
SQL over RPC, safely
Native Rust runtime for adversarial extension workloads with deterministic replay, cryptographic decision receipts, and fleet-scale containment.
A scripting language for cowboy coders
A ground-up Rust microkernel operating system exploring intent-centric computing, capability security, semantic knowledge, and privacy-first system architecture.
A local, open-source capability gateway for AI agents — one AI-native self-describe endpoint so any agent can discover, understand, be granted, and call the software on your machine, under a trust model you can see, scope, and revoke.
Electron runtime layer providing protocol-based separation, component assembly, and capability-based process control.
Self-hosted AI agent for terminal and Telegram with a deterministic permission kernel, human-scoped approvals, Claude/Codex workers, and an append-only audit trail.
AegisIDE: capability-secured agent development environment for local AI models. Rust.
A statically-typed scripting language and bytecode VM for sandboxed execution of AI-generated code, built in C++ with no GC or JIT.
KAIROS-ARK is a high-performance, Rust-based Agent Runtime Kernel built for industrial-grade reliability. It delivers sub-100µs dispatch latency, event-sourced deterministic replay, and kernel-enforced capability sandboxing, bridging Python prototypes and production AI systems.
A programming language that reads like English — and can't touch your machine unless you say so. Capability sandbox, pattern matching, gradual types. pip install she-lang
SENTINEL: an authority-attenuating immune architecture for AI agents. Detect and contain compromised agents without giving the defenders unrestricted authority.
An orchestration DSL and embedded runtime for hosting agentic systems. Durable, inspectable workflows with deterministic step ordering, running in-process under a capability jail — the model lives in your host, not in the runtime. 30+ companion packages for memory, transport and governance.
Loment — a systems programming language. Compiles to native x86-64 (Linux ELF, Windows PE, or freestanding for bare metal) with no runtime and no libc. The toolchain is itself written in Loment; source can be written in its Rust-flavored base syntax or six more: C, C++, Java, C#, Go, Python.
Agent-first display server: a small trusted core speaking a capability-native protocol, with every legacy app confined to its own per-app shim. Humans and AI agents operate the same GUIs under revocable, capability-scoped authorization.
To associate your repository with the capability-security topic, visit your repo's landing page and select "manage topics."