Produced with model assistance. Every page on this site, and every document in the dev packs area, was drafted with a large language model and reviewed by a person before publication. Nothing on this site is a compliance assessment, and no page claims conformity to any standard. What we do not say, and why · how every claim here is evidenced

store.sgit.ai / who runs it / Dinis Cruz

Dinis Cruz

Runs the correction at £500 and the two sessions at £1,500. Founder of the sgit.ai network, RiskMandate.ai, The Cyber Boardroom, MyFeeds.ai and VoiceDebrief.ai; former OWASP Board member and organiser of the OWASP Summits; creator of the O2 Platform.

Where this comes from. Every line below is read off a published page, and the pages are named. Nothing here is written from what anybody told us — a biography this store composed would be the worst thing on it to stand next to a price.

The record

Former OWASP Board member

And organiser of the OWASP Summits — Lisbon 2011 and Woburn 2017 — the working-session format that the Open Security Summit series went on to build on. Open-source work still ships under the owasp-sbot organisation.

Creator of the O2 Platform

The OWASP static-analysis engine of 2010 to 2012, and the first of a line of open-source tooling that continues in the osbot-* and mgraph-* families, memory_fs, Issues-FS and sgit-ai — all Apache-2.0, all on PyPI.

Founder, RiskMandate.ai

The business risk layer for autonomous systems — the site the fifteen Agent Behaviour Policy templates this store sells are published on.

Founder, sgit.ai and sgraph.ai

Encrypted vaults with git semantics, under Apache-2.0, and the network of nineteen sites of which this store is one. Each site publishes its argument before its implementation, so the commitments stay checkable.

Founder, The Cyber Boardroom and MyFeeds.ai

A platform for the conversation between technical security teams and the board, and role-aware security briefings built on semantic knowledge graphs — CISO, engineer and board views of the same material. Both Apache-2.0.

Works in the open, including the parts most companies do not

The code is Apache-2.0, roughly 1,100 working documents are CC BY 4.0, and the investor materials for two of the companies are on GitHub rather than behind a data room.

What they run on this store

Can you correct it for my situation?

The vault, with the mandate corrected against your situation rather than against a starting assumption, and a written note of what changed.

£500 · 1 to 3 days
Can somebody go through it with my team?

Two half-hour sessions with your team, the behaviour policy built from the interview, and a security professional's review and sign-off.

£1,500 · 1 to 5 days

The method this store sells is theirs. The fifteen published templates, the grant-and-mandate model, the delta and the barrier taxonomy, and the six published vaults of exactly this work were all built by the person who would be doing yours.

Work you can open right now

Not a portfolio and not a case study — the vaults themselves, each opened by a read key published on its own page.

Licence to Operateposrhzp3 · 13 MB, 121 files · 4 September 2026

“One agent, its grant of 12 capabilities, its mandate of 4, and the 8-capability delta no policy covers — with a simulated conversation where every reply carries its cost against a live policy”

This is the thing this store sells, built and published. One agent, its grant of twelve capabilities, its mandate of four, and the eight-capability delta no policy covers — which is the exact shape of every document on this site.

RiskMandate · File securitywu365g94 · 2.7 MB, 71 files · 25 August 2026

“An eleven-step risk-acceptance walk, running SQLite in the browser”

A risk register walked from a first finding to an accepted position, over one evolving record. The £500 level is this, done against your situation instead of that one.

Scaling Threat Modeling with Semantic Knowledge Graphs0ict6flm · 4.1 MB, 53 files · 27 August 2026

“ThreatModCon 2025: eleven linked threat models across 51 nodes and 179 threats”

Delivered to a room at a conference in Barcelona, and published afterwards with the models in it. Evidence that the method survives being presented to people who do this for a living.

Reach them

LinkedIn.

Everybody who runs a review here