AI · cyber security · semantic knowledge graphs · open source

Dinis Cruz

I build security and AI products in the open, and I write down what I learn while building them. Right now that means sgit.ai, git for encrypted vaults, built for humans and AI agents. Before that came The Cyber Boardroom, MyFeeds.ai and a long run of open-source security tooling going back to the OWASP O2 Platform.

Founder of sgit.ai, sgraph.ai, MyFeeds.ai, The Cyber Boardroom, RiskMandate.ai and VoiceDebrief.ai. Former OWASP Board member. Based in the UK.

Read the writing → What I am building → About me →

Latest writing

Essays, research briefs and project proposals. Many were written with an LLM as co-author, and the byline says so. 103 pieces so far, all under CC BY 4.0. All writing →

2 Oct 2025

GenLegalAdvise Project Plan

Small businesses, freelancers, and independent consultants regularly encounter legal documents -- consulting agreements, NDAs, service terms, EULAs, data sharing…

2 Oct 2025

Time as a Calibrator of Credibility and Trust in Information Systems

In an era of information overload and rampant misinformation, time emerges as a critical factor in determining what information we trust. Traditional approaches to…

2 Oct 2025

Project Voice2SIEM: Turning Customer Support Audio Into Real-Time Security Events

Phone-based social engineering and vishing (voice phishing) attacks are on the rise, targeting customer support and help desk agents. Attackers impersonate customers or…

1 Sep 2025

Next-Generation API Security Platform: Semantic Graphs, GenAI Testing & Ephemeral Environments for 2025

Modern API security requires going beyond traditional scanning -- it must blend into the API testing lifecycle and leverage cutting-edge AI to map and probe complex…

1 Sep 2025

Dinis Cruz's Research on API Security (2009-2025)

API security has been a persistent theme in Dinis Cruz's work, spanning early insights in 2009--2010 through to innovative ideas in 2025. His contributions center on how…

23 Aug 2025

LLM Workflows/Stateflow Service - Technical Brief

The LLM Workflows/Stateflow Service is a proposed stateless web service for executing AI-driven workflows with well-defined, deterministic steps. It acts as a state…

What I am building

Six companies, one strategy. Everything they ship is open source, and so are their investor materials. What they sell is the running, maintained, trusted service, not the code.

Now · Apache-2.0

sgit.ai

Git for encrypted vaults. Clone, commit, branch and merge files that are encrypted before they leave your machine. The server stores ciphertext it cannot read.

Commercial home

sgraph.ai

Where the sgit layer turns into revenue: SG/Send, the secure file-sharing service, and hosted SG/Vaults.

Semantic graphs

MyFeeds.ai

Role-aware cybersecurity briefings built on semantic knowledge graphs, with CISO, engineer and board views of the same news and the source attribution kept.

Security & the board

The Cyber Boardroom

An AI-powered platform for the conversation between technical security teams and the board. Also the UK company behind sgit.ai and RiskMandate.ai.

Autonomous systems

RiskMandate.ai

The business risk layer for autonomous systems. A named human underwrites the exposure, and the interval is the decision.

In the browser

VoiceDebrief.ai

Voice recordings into transcripts and debriefs, entirely in the browser. No account, and nothing uploaded to a server.

Research, by topic

The writing grouped into the areas I keep coming back to. Each hub is a curated reading list, not a tag cloud.

AppSec

Cyber security & threat modeling

Semantic threat models, supply-chain security, MCP and OAuth risks, API security from 2009 to 2025, and security as a board conversation.

G³

Semantic knowledge graphs

Graphs of graphs of graphs, LLMs as ephemeral graph databases, evolving ontologies, and why meaning lives in the edges.

Engineering

AI & development

Deterministic GenAI pipelines, Iterative Flow Development, surrogate dependencies, and the joy of programming with AI.

Trust

The future of news

Fact provenance, identity graphs for authors and sources, micro-payments, and fair compensation for AI crawling.

Sovereignty

Europe & learning

An open-source sovereign cloud for Europe, Europe's GenAI opportunity, and generative AI in education.

The lab

Projects & innovation

Project briefs and MVPs: VulnAI, InsightFlow, Voice2SIEM, JSync, SupplyShield and the rest of the innovation lab.

The record

The parts of my track record that the writing here builds on.

WhatWhy it matters here
Former OWASP Board memberAnd organiser of the OWASP Summits, Lisbon 2011 and Woburn 2017: working sessions with no spectators, only participants. The Open Security Summit series went on to build on that format.
Creator of the O2 PlatformThe OWASP static-analysis engine of 2010 to 2012, and the first of a line of open-source tooling that continues in OSBot, MGraph-DB, memory_fs, Issues-FS and sgit-ai.
CISO and security practitionerSecurity leadership inside UK companies, and one UK company taken through to an exit. This is where the threat-modeling and "security for the board" work comes from.
Founder, six times overThe companies above, all run on the same idea: open source is a strategy, not a charity. Trust is what gets sold.

The long version, with the interests I should declare, is on the about page.

Elsewhere

Most of what I write is posted first on LinkedIn. The code is on GitHub. The sgit.ai network is a set of focused sites that each take one argument further than a blog post can.

Fastest route

LinkedIn

Where the essays are first posted and discussed, and the best way to reach me.

Code

GitHub

The open-source work, including the sgit CLI, OSBot, MGraph-DB and the source of this site.

Position

open-source.sgit.ai

My position on open source as a strategy: the licences, survivability, the history checked against its sources.

The network

The sgit.ai network

Sites on graphs, threat modeling, standards, risk, agent identity and more, each publishing its argument before its implementation.