store.sgit.ai / who runs it / Dinis Cruz
Dinis Cruz
Runs the correction at £500 and the two sessions at £1,500. Founder of the sgit.ai network, RiskMandate.ai, The Cyber Boardroom, MyFeeds.ai and VoiceDebrief.ai; former OWASP Board member and organiser of the OWASP Summits; creator of the O2 Platform.
Where this comes from. Every line below is read off a published page, and the pages are named. Nothing here is written from what anybody told us — a biography this store composed would be the worst thing on it to stand next to a price.
- https://open-source.sgit.ai/about/index.html — The author page on open-source.sgit.ai, published CC BY 4.0. Every row of the record below is read off it. Read 16 September 2026.
- https://sgit.ai/demos/vaults/index.html — The published vault catalogue, which is where the delivered work is. Read 16 September 2026.
The record
And organiser of the OWASP Summits — Lisbon 2011 and Woburn 2017 — the working-session format that the Open Security Summit series went on to build on. Open-source work still ships under the owasp-sbot organisation.
The OWASP static-analysis engine of 2010 to 2012, and the first of a line of open-source tooling that continues in the osbot-* and mgraph-* families, memory_fs, Issues-FS and sgit-ai — all Apache-2.0, all on PyPI.
The business risk layer for autonomous systems — the site the fifteen Agent Behaviour Policy templates this store sells are published on.
Encrypted vaults with git semantics, under Apache-2.0, and the network of nineteen sites of which this store is one. Each site publishes its argument before its implementation, so the commitments stay checkable.
A platform for the conversation between technical security teams and the board, and role-aware security briefings built on semantic knowledge graphs — CISO, engineer and board views of the same material. Both Apache-2.0.
The code is Apache-2.0, roughly 1,100 working documents are CC BY 4.0, and the investor materials for two of the companies are on GitHub rather than behind a data room.
What they run on this store
The vault, with the mandate corrected against your situation rather than against a starting assumption, and a written note of what changed.
Two half-hour sessions with your team, the behaviour policy built from the interview, and a security professional's review and sign-off.
The method this store sells is theirs. The fifteen published templates, the grant-and-mandate model, the delta and the barrier taxonomy, and the six published vaults of exactly this work were all built by the person who would be doing yours.
Work you can open right now
Not a portfolio and not a case study — the vaults themselves, each opened by a read key published on its own page.
posrhzp3 · 13 MB, 121 files · 4 September 2026“One agent, its grant of 12 capabilities, its mandate of 4, and the 8-capability delta no policy covers — with a simulated conversation where every reply carries its cost against a live policy”
This is the thing this store sells, built and published. One agent, its grant of twelve capabilities, its mandate of four, and the eight-capability delta no policy covers — which is the exact shape of every document on this site.
wu365g94 · 2.7 MB, 71 files · 25 August 2026“An eleven-step risk-acceptance walk, running SQLite in the browser”
A risk register walked from a first finding to an accepted position, over one evolving record. The £500 level is this, done against your situation instead of that one.
0ict6flm · 4.1 MB, 53 files · 27 August 2026“ThreatModCon 2025: eleven linked threat models across 51 nodes and 179 threats”
Delivered to a room at a conference in Barcelona, and published afterwards with the models in it. Evidence that the method survives being presented to people who do this for a living.
Reach them
Everybody who runs a review here
Which agent do you run? → How buying works → Every claim, with its state →