Astrid is a portable, capability-secure operating system for composable software.
-
Updated
Aug 7, 2026 - Rust
Astrid is a portable, capability-secure operating system for composable software.
Jacquard is a small programming language designed for a regime in which most code is written by machine-learning models and reviewed by people.
An actor-based systems language that compiles to readable C. Native, no VM, no garbage collector.
Sandboxed plugin VM with typed capabilities, deterministic replay, and time-travel debugging — written in Rust.
SQL over RPC, safely
Native Rust runtime for adversarial extension workloads with deterministic replay, cryptographic decision receipts, and fleet-scale containment.
A scripting language for cowboy coders
plan-bound authorization architecture for governing privileged effects in untrusted computational agents.
Electron runtime layer providing protocol-based separation, component assembly, and capability-based process control.
A ground-up Rust microkernel operating system exploring intent-centric computing, capability security, semantic knowledge, and privacy-first system architecture.
A statically-typed scripting language and bytecode VM for sandboxed execution of AI-generated code, built in C++ with no GC or JIT.
KAIROS-ARK is a high-performance, Rust-based Agent Runtime Kernel built for industrial-grade reliability. It delivers sub-100µs dispatch latency, event-sourced deterministic replay, and kernel-enforced capability sandboxing, bridging Python prototypes and production AI systems.
Agent-first display server: a small trusted core speaking a capability-native protocol, with every legacy app confined to its own per-app shim. Humans and AI agents operate the same GUIs under revocable, capability-scoped authorization.
Resource-safe, effect-typed programs in syntax you already know. A checked affine core with familiar Faces — JavaScript-, Python-, functional-, and pseudocode-shaped surfaces — compiling to typed WebAssembly.
One MCP stdio endpoint for a whole toolchain — GitHub, GitLab, cloud, mail, browser and research tools — with capability-gated dispatch, a machine-checked ABI, and cartridges fetched on demand from boj-server-cartridges. Zero runtime dependencies.
A capability-typed language that emits machine-verifiable supply-chain SBOMs by construction: per-function CycloneDX, SPDX, VEX and SLSA artefacts that match the code, not a scanner's guess.
my tinkering notebook (blog)
A capability-native research kernel for explicit authority, isolated execution, temporal state, and verifiable system boundaries. It is particularly efficient with WebAssembly
Canonical registry of BoJ capability cartridges — each one a machine-checked ABI, a five-symbol C-ABI implementation and a loopback adapter, minted from a single template. Hosts (boj-server, panll) fetch from here on demand.
Add a description, image, and links to the capability-security topic page so that developers can more easily learn about it.
To associate your repository with the capability-security topic, visit your repo's landing page and select "manage topics."