Dinis Cruz
I have spent my career at the point where security, software development and, more recently, generative AI meet. I have been a security practitioner, a CISO for UK companies, an OWASP leader and a founder. What I build now, I build in the open, and this site is where the writing behind it lives.
The record
| Role | What it involves |
|---|---|
| Founder, sgit.ai | Encrypted vaults with git semantics: clone, commit, branch and merge files that are encrypted before they leave your machine, under Apache-2.0. It is also the hub of a network of focused sites, each of which publishes its argument before its implementation, so the commitments can be checked. |
| Founder, sgraph.ai | Where the strategy turns into revenue: the commercial home of SG/Send, the secure file-sharing service built on the open-source sgit layer, and of hosted SG/Vaults. The code stays Apache-2.0. What is sold is the running, maintained, certified service. |
| Founder, MyFeeds.ai | Role-aware cybersecurity briefings built on semantic knowledge graphs, with source attribution: CISO, engineer and board views of the same news. Open source and serverless, with the seed pitch and unit economics published in the open. |
| Founder, The Cyber Boardroom | An AI-powered platform for the conversation between technical security teams and the board, bridging the two with knowledge-graph technology. Apache-2.0, with the community edition and the investment repository public. The Cyber Boardroom Limited, a UK-registered company, is the commercial vehicle behind sgit.ai and RiskMandate.ai. |
| Founder, RiskMandate.ai | The business risk layer for autonomous systems. |
| Founder, VoiceDebrief.ai | Voice recordings into transcripts and debriefs, entirely in the browser, with nothing uploaded to a server. |
| Former OWASP Board member | And organiser of the OWASP Summits, Lisbon 2011 and Woburn 2017. That working-session format, with no spectators and only participants, is the one the Open Security Summit series went on to build on. My current open-source work still ships under the owasp-sbot organisation. |
| Creator, the O2 Platform | The OWASP static-analysis engine of 2010 to 2012, and the first of a line of open-source tooling that continues in the osbot and mgraph families, memory_fs, Issues-FS and sgit-ai. All of it is Apache-2.0 and on PyPI. |
| Thirty years in the UK | A security practitioner, a CISO for UK companies and a founder, with one UK company taken through to an exit. My stated intent is to grow more UK-based companies on this technology, in the open. |
What I write about
The writing on this site runs from February 2024 onwards. Most of it is research briefs and project proposals, written to be used rather than just read. The themes keep recurring:
- Application security that finally works. Threat modeling as semantic knowledge graphs, threat models as mandatory disclosures, and security as a conversation the board can take part in.
- Semantic knowledge graphs. G³ (graphs of graphs of graphs), LLMs as ephemeral graph databases, and ontologies that evolve rather than being designed top-down. The graphs hub →
- Deterministic, provable GenAI. Outputs with provenance, small models plus code in place of large models, and data pipelines you can debug. AI & development →
- Trust in news. Fact provenance, identity graphs for authors and sources, and new ways to fund journalism. The future of news →
- Europe and sovereignty. An open-source sovereign cloud, and Europe's opportunity in GenAI. Europe & learning →
Writing elsewhere
| Where most of the essays are first posted and discussed, and the fastest route to reach me. | |
| sgit.ai articles | The first-person articles on the sgit.ai site: the future of news as a story vault, the SaaS apocalypse, and Fractal Semantic Graphs. The byline there links to a sibling of this page. |
| open-source.sgit.ai | My position on open source as a strategy rather than a charity, with the licences, the investor materials published in the open, and the interests declared there. |
| graphs.sgit.ai | The Fractal Semantic Graphs argument in full: the grammar, the worked examples and the evidence. |
| GitHub | The code, including the sgit CLI and this site's source. |
Interests declared
I run companies whose strategy the writing here describes, and they sell the running, maintained service rather than the code. The markets many of these essays describe are markets I intend to be in. Read the arguments knowing that. The project proposals on this site were written to start conversations with specific organisations, and they say so in their titles.
Many of the documents here were written with LLMs (ChatGPT Deep Research, Claude and others) as co-authors, and the byline names them. The ideas, the direction and the editing are mine. The prose is often shared work.
Reach me, or correct me
LinkedIn is the fastest route. The repository for this site takes issues and pull requests. If you find something wrong here, I would rather know.