Project status
An open-source research and engineering project.
ThreatVeil began as a commercial startup experiment and is now an open-source research and engineering project.
Why it is open source
ThreatVeil was built around one question: when an autonomous AI system changes, how do we know the security conclusions we previously relied on are still true? That question is broader and earlier than any single product. It touches agent frameworks, MCP, deployment platforms, identity and security testing, and it deserves to be tested and argued with by the people who work on those systems.
The architecture is substantial enough to be worth studying, and honest enough about its gaps that contributors can see exactly where to start. Read the full story →
Release
v0.1.0, the first public release. Experimental: not validated in production or with real customers. Licensed under Apache-2.0.
What is complete
Implemented and tested locally:
- Append-only assurance records on PostgreSQL with forced row-level security and split database roles.
- Deterministic agent-definition parsing for Claude Code settings,
.mcp.json, subagent files, MCP tool catalogues, CrewAI and the ThreatVeil manifest. - Authority-direction classification, reviewed dependency mapping and per-claim evidence invalidation.
- Proposed-change impact before shipping, without touching current state.
- The Assurance Gate, and Ed25519-signed Passports and receipts with offline verification.
- A one-command Docker Compose stack and an end-to-end synthetic demonstration.
- About 700 Python tests against real PostgreSQL, plus browser, SDK and Terraform tests.
What remains experimental
| Area | Status today |
|---|---|
| Restoring assurance after a source change | Works only on the synthetic fixture |
| Business Effect Observer Contract | Declares observers, but produces no evidence |
| Live sources | Collected only on request; no scheduler |
| Clearance scope | Staging environments, evidence at most 24 hours old |
| Code-defined agents | LangGraph tools and OpenAI Agents SDK stay unknown |
| GitHub App, GCP deployment of the platform | Implemented, never accepted in real use |
| Real-world validation | None yet |
Every limitation is documented in KNOWN_LIMITATIONS.md, and the internal audit that found them is published unedited.
How to contribute
- Run it locally:
docker compose up --build, thenmake demo. - Read the roadmap and pick an issue labelled good first issue, help wanted or research.
- Follow the contributing guide. Any change that modifies assurance truth needs tests and documentation.
- Report vulnerabilities privately through GitHub (see the security policy).