Open source by Hlinor

Tools that make AI work provable.

Every Hlinor audit runs on tools we publish and maintain in the open. Declare what your AI agents may do, verify what is actually running, and keep contracts aligned with reality - inspectable, deterministic, free to audit yourself.

Open source is our evidence: the method behind every audit report is public and reviewable.

The toolchain

Each tool works on its own. Together they cover the full path from declared intent to accepted evidence.

01

Agent Registry

Declarative YAML contracts for AI agents: allowed actions, blocked actions, budgets and approvals. Ed25519-signed bundles, runtime enforcement, LangChain and CrewAI wrappers. On PyPI.

Learn more

02

Agent Control Plane

Read-only scanner that inventories agents, models, tools and MCP servers in a codebase, then flags deterministic risk findings with file/line evidence. SARIF output for CI gates.

Learn more

03

ScopeGuard

Finds scope drift between the signed agreement and the message thread before it eats your margin. Deterministic rules, evidence trail, human decisions. Hosted pilot available.

Learn more

Why open source?

An audit you cannot inspect is an opinion. Our detection rules, policy formats and scanners are public, so your engineers can verify exactly how findings are produced - before trusting the report.

What this gives you

  • No black box: the method is on GitHub, reviewable line by line.
  • No lock-in: YAML policies and SARIF reports work with your existing tooling.
  • Self-service first: run the tools yourself, call us when you want independent review.
From tools to proof

Want an independent review on top of the tools?

We run fixed-scope governance reviews of AI agents and workflows: policy inventory, runtime permission checks, audit-log gaps and a client-ready report in 72 hours.

Agent Governance Review