Astrid is a portable, capability-secure operating system for composable software.
-
Updated
Aug 19, 2026 - Rust
Astrid is a portable, capability-secure operating system for composable software.
Jacquard is a small programming language designed for a regime in which most code is written by machine-learning models and reviewed by people.
An actor-based systems language that compiles to readable C. Native, no VM, no garbage collector.
Sandboxed plugin VM with typed capabilities, deterministic replay, and time-travel debugging — written in Rust.
SQL over RPC, safely
Native Rust runtime for adversarial extension workloads with deterministic replay, cryptographic decision receipts, and fleet-scale containment.
A scripting language for cowboy coders
A ground-up Rust microkernel operating system exploring intent-centric computing, capability security, semantic knowledge, and privacy-first system architecture.
plan-bound authorization architecture for governing privileged effects in untrusted computational agents.
Electron runtime layer providing protocol-based separation, component assembly, and capability-based process control.
A statically-typed scripting language and bytecode VM for sandboxed execution of AI-generated code, built in C++ with no GC or JIT.
KAIROS-ARK is a high-performance, Rust-based Agent Runtime Kernel built for industrial-grade reliability. It delivers sub-100µs dispatch latency, event-sourced deterministic replay, and kernel-enforced capability sandboxing, bridging Python prototypes and production AI systems.
Agent-first display server: a small trusted core speaking a capability-native protocol, with every legacy app confined to its own per-app shim. Humans and AI agents operate the same GUIs under revocable, capability-scoped authorization.
Resource-safe, effect-typed programs in syntax you already know. A checked affine core with familiar Faces — JavaScript-, Python-, functional-, and pseudocode-shaped surfaces — compiling to typed WebAssembly.
One MCP stdio endpoint for a whole toolchain — GitHub, GitLab, cloud, mail, browser and research tools — with capability-gated dispatch, a machine-checked ABI, and cartridges fetched on demand from boj-server-cartridges. Zero runtime dependencies.
A microkernel operating system written entirely in ManiT, the balanced ternary systems language. Trit-addressed memory with trit-trie page tables, three privilege rings one trit deep, photon-schedule capability security. Builds and runs on Linux today.
An autonomous agent you can hand a shell to, because it can prove what it will not do.
An orchestration DSL and embedded runtime for hosting agentic systems. Durable, inspectable workflows with deterministic step ordering, running in-process under a capability jail — the model lives in your host, not in the runtime. 30+ companion packages for memory, transport and governance.
my tinkering notebook (blog)
Add a description, image, and links to the capability-security topic page so that developers can more easily learn about it.
To associate your repository with the capability-security topic, visit your repo's landing page and select "manage topics."