I build security and AI products in the open, and I write down what I learn while building them. Right now that means sgit.ai, git for encrypted vaults, built for humans and AI agents. Before that came The Cyber Boardroom, MyFeeds.ai and a long run of open-source security tooling going back to the OWASP O2 Platform.
Essays, research briefs and project proposals. Many were written with an LLM as co-author, and the byline says so. 103 pieces so far, all under CC BY 4.0. All writing →
Small businesses, freelancers, and independent consultants regularly encounter legal documents -- consulting agreements, NDAs, service terms, EULAs, data sharing…
2 Oct 2025In an era of information overload and rampant misinformation, time emerges as a critical factor in determining what information we trust. Traditional approaches to…
2 Oct 2025Phone-based social engineering and vishing (voice phishing) attacks are on the rise, targeting customer support and help desk agents. Attackers impersonate customers or…
1 Sep 2025Modern API security requires going beyond traditional scanning -- it must blend into the API testing lifecycle and leverage cutting-edge AI to map and probe complex…
1 Sep 2025API security has been a persistent theme in Dinis Cruz's work, spanning early insights in 2009--2010 through to innovative ideas in 2025. His contributions center on how…
23 Aug 2025The LLM Workflows/Stateflow Service is a proposed stateless web service for executing AI-driven workflows with well-defined, deterministic steps. It acts as a state…
Six companies, one strategy. Everything they ship is open source, and so are their investor materials. What they sell is the running, maintained, trusted service, not the code.
Git for encrypted vaults. Clone, commit, branch and merge files that are encrypted before they leave your machine. The server stores ciphertext it cannot read.
Commercial homeWhere the sgit layer turns into revenue: SG/Send, the secure file-sharing service, and hosted SG/Vaults.
Semantic graphsRole-aware cybersecurity briefings built on semantic knowledge graphs, with CISO, engineer and board views of the same news and the source attribution kept.
Security & the boardAn AI-powered platform for the conversation between technical security teams and the board. Also the UK company behind sgit.ai and RiskMandate.ai.
Autonomous systemsThe business risk layer for autonomous systems. A named human underwrites the exposure, and the interval is the decision.
In the browserVoice recordings into transcripts and debriefs, entirely in the browser. No account, and nothing uploaded to a server.
The writing grouped into the areas I keep coming back to. Each hub is a curated reading list, not a tag cloud.
Semantic threat models, supply-chain security, MCP and OAuth risks, API security from 2009 to 2025, and security as a board conversation.
G³Graphs of graphs of graphs, LLMs as ephemeral graph databases, evolving ontologies, and why meaning lives in the edges.
EngineeringDeterministic GenAI pipelines, Iterative Flow Development, surrogate dependencies, and the joy of programming with AI.
TrustFact provenance, identity graphs for authors and sources, micro-payments, and fair compensation for AI crawling.
SovereigntyAn open-source sovereign cloud for Europe, Europe's GenAI opportunity, and generative AI in education.
The labProject briefs and MVPs: VulnAI, InsightFlow, Voice2SIEM, JSync, SupplyShield and the rest of the innovation lab.
The parts of my track record that the writing here builds on.
| What | Why it matters here |
|---|---|
| Former OWASP Board member | And organiser of the OWASP Summits, Lisbon 2011 and Woburn 2017: working sessions with no spectators, only participants. The Open Security Summit series went on to build on that format. |
| Creator of the O2 Platform | The OWASP static-analysis engine of 2010 to 2012, and the first of a line of open-source tooling that continues in OSBot, MGraph-DB, memory_fs, Issues-FS and sgit-ai. |
| CISO and security practitioner | Security leadership inside UK companies, and one UK company taken through to an exit. This is where the threat-modeling and "security for the board" work comes from. |
| Founder, six times over | The companies above, all run on the same idea: open source is a strategy, not a charity. Trust is what gets sold. |
The long version, with the interests I should declare, is on the about page.
Most of what I write is posted first on LinkedIn. The code is on GitHub. The sgit.ai network is a set of focused sites that each take one argument further than a blog post can.
Where the essays are first posted and discussed, and the best way to reach me.
CodeThe open-source work, including the sgit CLI, OSBot, MGraph-DB and the source of this site.
PositionMy position on open source as a strategy: the licences, survivability, the history checked against its sources.
The networkSites on graphs, threat modeling, standards, risk, agent identity and more, each publishing its argument before its implementation.