Open source program

Security tooling for
people who will never hire a consultancy

A standing commitment of engineering time, published free and permissively licensed. An agentic bug bounty toolkit, a generator that builds agent skill files from public vulnerability disclosures, and a smart contract security skill library - all public repositories you can clone today.

Repositories
03
GitHub stars
4,768
Licences
Apache 2.0, MIT
Telemetry
None
fig. 01Released, not demonstrated
Built by the team that secured:
NASAGoogleMetaAmazonSonyAllstateChatGPTToyotaWordPressNetflixXTrip.comNASAGoogleMetaAmazonSonyAllstateChatGPTToyotaWordPressNetflixXTrip.com

Consultancies protect whoever can pay. That leaves out almost everybody: the clinic whose receptionist takes the fraudulent call, the school district with one part-time IT contractor, the family business that loses its working capital to a redirected invoice, the pensioner whose son’s voice was cloned.

We do not think those people are somebody else’s problem, and charity is a fragile way to solve it. Tools are not. A detection engine written once and released freely keeps working long after any individual engagement ends, in places we will never hear about. That is the most leverage we have, so we fund it deliberately rather than when there is spare time.

Why we publish

Tools, released free

Everything we build for the program is permissively licensed and self-hostable. No telemetry, no gated tier, no upgrade path that quietly becomes the product.

Research in the open

The pretexts we see in engagements get anonymised and published, so defenders learn about a technique before it reaches them rather than after.

Tutorials and video

Short, practical walkthroughs that a non-technical person can follow: verifying a caller, locking down an account, spotting a cloned voice.

Free sessions for those without budget

We reserve capacity every month for schools, clinics, charities and community groups. Being underfunded should not mean being undefended.

Our commitments

Rules we hold ourselves to

Permissive licences only

Apache 2.0 or MIT. Fork it, rebrand it, ship it inside your own product. We are not building a funnel disguised as a community edition.

No telemetry, ever

Nothing phones home. Tools that analyse suspicious messages must be safe to run on the most sensitive thing in your inbox, which means they cannot send it anywhere.

Maintained, not dumped

Reserved engineering capacity every sprint. A tool that stops receiving security updates is worse than no tool, so we archive loudly rather than letting things rot quietly.

Built with the people using it

Feature direction comes from the help desks, community groups and fraud teams who run these day to day, not from what would look good in a sales conversation.

Contribute

You do not need to be a security engineer

The most valuable contributions we receive are usually not code.

01

Write code

Issues are labelled by difficulty and every repository has a good-first-issue queue. Detection rules, language packs and integrations are the most useful contributions right now.

02

Send us pretexts

If you received something clever, send it. Anonymised samples of real lures make the detection corpus better for everyone, and we credit contributors unless asked not to.

03

Translate and localise

Scams are local. Templates, playbooks and warning copy in more languages helps far more people than another detection heuristic.

04

Run a session

Use our materials to teach a session at your school, workplace or community centre. Everything is licensed for that and we will help you prepare it.

Need help and cannot pay for it?

We keep monthly capacity for schools, clinics, charities and community groups: a session, a review, or help standing up one of these tools. Tell us who you serve and we will find a slot.