<!-- generated from index.html by admin/build/build.py — do not edit by hand -->

*[diniscruz.ai](/index.md) · site v0.1.1 · canonical: https://diniscruz.ai/index.html*

> Dinis Cruz: founder of sgit.ai, MyFeeds.ai and The Cyber Boardroom, former OWASP Board member. Essays and research on GenAI, AppSec, threat modeling and knowledge graphs.

---

AI · cyber security · semantic knowledge graphs · open source

# Dinis Cruz

I build security and AI products in the open, and I write down what I learn while building them. Right now that means [**sgit.ai**](https://sgit.ai), git for encrypted vaults, built for humans and AI agents. Before that came The Cyber Boardroom, MyFeeds.ai and a long run of open-source security tooling going back to the **OWASP O2 Platform**.

Founder of [sgit.ai](https://sgit.ai), [sgraph.ai](https://sgraph.ai), [MyFeeds.ai](https://investor.myfeeds.ai/), [The Cyber Boardroom](https://thecyberboardroom.com), [RiskMandate.ai](https://riskmandate.ai) and [VoiceDebrief.ai](https://voicedebrief.ai). Former OWASP Board member. Based in the UK.

[Read the writing →](writing/index.md)[What I am building →](building/index.md)[About me →](about/index.md)

## Latest writing

Essays, research briefs and project proposals. Many were written with an LLM as co-author, and the byline says so. 103 pieces so far, all under CC BY 4.0. [All writing →](writing/index.md)

### [GenLegalAdvise Project Plan](2025/10/03/genlegaladvise-project-plan.md)

*2 Oct 2025*

Small businesses, freelancers, and independent consultants regularly encounter legal documents -- consulting agreements, NDAs, service terms, EULAs, data sharing…

### [Time as a Calibrator of Credibility and Trust in Information Systems](2025/10/02/time-as-a-calibrator-of-credibility-and-trust-in-information-systems.md)

*2 Oct 2025*

In an era of information overload and rampant misinformation, time emerges as a critical factor in determining what information we trust. Traditional approaches to…

### [Project Voice2SIEM: Turning Customer Support Audio Into Real-Time Security Events](2025/10/02/project-voice2siem-turning-customer-support-audio-into-real-time-security-events.md)

*2 Oct 2025*

Phone-based social engineering and vishing (voice phishing) attacks are on the rise, targeting customer support and help desk agents. Attackers impersonate customers or…

### [Next-Generation API Security Platform: Semantic Graphs, GenAI Testing & Ephemeral Environments for 2025](2025/09/01/next-generation-api-security-platform-semantic-graphs-genai-testing-ephemeral-environments-2025.md)

*1 Sep 2025*

Modern API security requires going beyond traditional scanning -- it must blend into the API testing lifecycle and leverage cutting-edge AI to map and probe complex…

### [Dinis Cruz's Research on API Security (2009-2025)](2025/09/01/dinis-cruz-research-on-api-security-2009-2025.md)

*1 Sep 2025*

API security has been a persistent theme in Dinis Cruz's work, spanning early insights in 2009--2010 through to innovative ideas in 2025. His contributions center on how…

### [LLM Workflows/Stateflow Service - Technical Brief](2025/08/23/llm-workflows-stateflow-service-technical-brief.md)

*23 Aug 2025*

The LLM Workflows/Stateflow Service is a proposed stateless web service for executing AI-driven workflows with well-defined, deterministic steps. It acts as a state…

## What I am building

Six companies, one strategy. Everything they ship is open source, and so are their investor materials. What they sell is the running, maintained, trusted service, not the code.

### [sgit.ai](https://sgit.ai)

*Now · Apache-2.0*

Git for encrypted vaults. Clone, commit, branch and merge files that are encrypted before they leave your machine. The server stores ciphertext it cannot read.

### [sgraph.ai](https://sgraph.ai)

*Commercial home*

Where the sgit layer turns into revenue: SG/Send, the secure file-sharing service, and hosted SG/Vaults.

### [MyFeeds.ai](https://investor.myfeeds.ai/)

*Semantic graphs*

Role-aware cybersecurity briefings built on semantic knowledge graphs, with CISO, engineer and board views of the same news and the source attribution kept.

### [The Cyber Boardroom](https://thecyberboardroom.com)

*Security & the board*

An AI-powered platform for the conversation between technical security teams and the board. Also the UK company behind sgit.ai and RiskMandate.ai.

### [RiskMandate.ai](https://riskmandate.ai)

*Autonomous systems*

The business risk layer for autonomous systems. A named human underwrites the exposure, and the interval is the decision.

### [VoiceDebrief.ai](https://voicedebrief.ai)

*In the browser*

Voice recordings into transcripts and debriefs, entirely in the browser. No account, and nothing uploaded to a server.

## Research, by topic

The writing grouped into the areas I keep coming back to. Each hub is a curated reading list, not a tag cloud.

### [Cyber security & threat modeling](research/cyber-security.md)

*AppSec*

Semantic threat models, supply-chain security, MCP and OAuth risks, API security from 2009 to 2025, and security as a board conversation.

### [Semantic knowledge graphs](research/graphs.md)

*G³*

Graphs of graphs of graphs, LLMs as ephemeral graph databases, evolving ontologies, and why meaning lives in the edges.

### [AI & development](research/development-and-genai.md)

*Engineering*

Deterministic GenAI pipelines, Iterative Flow Development, surrogate dependencies, and the joy of programming with AI.

### [The future of news](research/the-future-of-news.md)

*Trust*

Fact provenance, identity graphs for authors and sources, micro-payments, and fair compensation for AI crawling.

### [Europe & learning](research/europe-and-learning.md)

*Sovereignty*

An open-source sovereign cloud for Europe, Europe's GenAI opportunity, and generative AI in education.

### [Projects & innovation](research/projects.md)

*The lab*

Project briefs and MVPs: VulnAI, InsightFlow, Voice2SIEM, JSync, SupplyShield and the rest of the innovation lab.

## The record

The parts of my track record that the writing here builds on.

| What | Why it matters here |
|---|---|
| **Former OWASP Board member** | And organiser of the OWASP Summits, Lisbon 2011 and Woburn 2017: working sessions with no spectators, only participants. The [Open Security Summit](https://open-security-summit.org/) series went on to build on that format. |
| **Creator of the O2 Platform** | The OWASP static-analysis engine of 2010 to 2012, and the first of a line of open-source tooling that continues in OSBot, MGraph-DB, memory_fs, Issues-FS and sgit-ai. |
| **CISO and security practitioner** | Security leadership inside UK companies, and one UK company taken through to an exit. This is where the threat-modeling and "security for the board" work comes from. |
| **Founder, six times over** | The companies above, all run on the same idea: [open source is a strategy, not a charity](https://open-source.sgit.ai/). Trust is what gets sold. |

The long version, with the interests I should declare, is on the [about page](about/index.md).

## Elsewhere

Most of what I write is posted first on LinkedIn. The code is on GitHub. The sgit.ai network is a set of focused sites that each take one argument further than a blog post can.

### [LinkedIn](https://www.linkedin.com/in/diniscruz)

*Fastest route*

Where the essays are first posted and discussed, and the best way to reach me.

### [GitHub](https://github.com/DinisCruz)

*Code*

The open-source work, including the sgit CLI, OSBot, MGraph-DB and the source of this site.

### [open-source.sgit.ai](https://open-source.sgit.ai/)

*Position*

My position on open source as a strategy: the licences, survivability, the history checked against its sources.

### [The sgit.ai network](https://sgit.ai/network/index.html)

*The network*

Sites on graphs, threat modeling, standards, risk, agent identity and more, each publishing its argument before its implementation.

---

*This page is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0).*
