Skip to content

Releases: sandrexa1111/threatveil-oss

ThreatVeil v0.1.1 — guided tour fix

Choose a tag to compare

@sandrexa1111 sandrexa1111 released this 24 Sep 11:59
d4b1cfd

A small patch release. Everything in v0.1.0 still applies; this fixes one real bug found by re-running the full suite after release.

Fixed

The guided tour could restart itself and cancel its own navigation (#24). The ?tour=start effect depended on the state it was updating while calling both an API fetch and a URL replace, so it refetched in a loop and a late replace cancelled the move to the prepared example system. A captured trace of a failing run showed 36 /v1/home fetches and 52 /app navigations in three seconds, ending back on Home with the tour reset even though the example had been created.

Anyone opening Explore how ThreatVeil works could hit this. The start path now runs once per ?tour=start, and resume no longer depends on that state.

Also: the browser suite in CI now compiles /app before it starts, since CI runs the web app in dev mode and first-hit compilation was being charged to a navigation timeout.

Known and unchanged

Restoring assurance after a source change still works only on the synthetic fixture, nothing schedules collection from live sources, evidence stays bounded to 24 hours and staging environments, and nothing has been validated in production or with a customer. See KNOWN_LIMITATIONS.md.

A related, milder instance of the same defect class is open as #25 (good first issue).

Quick start

git clone https://github.com/sandrexa1111/threatveil-oss.git
cd threatveil-oss
make demo

ThreatVeil v0.1.0 — First Open-Source Release

Choose a tag to compare

@sandrexa1111 sandrexa1111 released this 14 Sep 08:23

ThreatVeil v0.1.0: first open-source release

ThreatVeil is open-source assurance infrastructure for changing autonomous AI systems. It tracks
whether the security evidence that justified a system's authority still applies after its tools,
permissions, models or configuration change.

This first public release is experimental. It comes from a 2026 startup experiment and has not
been validated in production or with real customers.

What ThreatVeil explores

TEST → PASS → MODEL / TOOL / PERMISSION / CONFIG CHANGES → ?

A security conclusion can be historically correct and no longer apply. ThreatVeil models the chain
from system state and authority, through security claims and state-bound evidence, to changes,
evidence invalidation, re-verification and current assurance. It exposes that assurance to
machines (the Assurance Gate) and to other organizations (signed Passports, where authentic is not
the same as current).

What works

  • Append-only assurance kernel on PostgreSQL with forced row-level security and split roles.
  • Deterministic parsing of Claude Code settings, .mcp.json, subagent files, MCP tool catalogues,
    CrewAI and a ThreatVeil manifest.
  • Authority-direction classification, reviewed dependency mapping and per-claim evidence
    invalidation.
  • Proposed-change impact before shipping, through the UI, CLI and a pull-request check body.
  • Assurance Gate API; Ed25519 DSSE-signed Passports and receipts with offline verification.
  • One-command local stack (docker compose up --build) and demonstration (make demo).
  • About 700 Python tests against real PostgreSQL, plus browser, SDK and Terraform tests, with
    security scanning in CI.

Demo

git clone https://github.com/sandrexa1111/threatveil-oss.git && cd threatveil-oss
make demo

The synthetic Finance Agent is cleared. Then the tool gateway stops requiring approval.
Authority expands, one of three claims loses its evidence, the prior clearance is superseded, the
Gate changes, and a previously issued Passport stays authentic but is no longer current.

Architecture

FastAPI control plane, Next.js workspace, PostgreSQL security memory, and a broker and worker for
approved checks. See docs/ARCHITECTURE.md.

Known limitations

  • Restoring assurance after a source-observed change works only on the synthetic fixture.
  • The Business Effect Observer Contract produces no evidence; only signed collectors do.
  • Live sources are not collected on a schedule.
  • Evidence expires within 24 hours, and production environments cannot be cleared.
  • Code-defined agents (LangGraph tools, OpenAI Agents SDK) stay UNKNOWN.
  • The GitHub App, the GCP Terraform and the commercial integrations were never accepted in real use.

The full list is in docs/KNOWN_LIMITATIONS.md.

Where contributors can help

Generic restoration, observer unification, scheduled collection, framework adapters, numeric
authority semantics, Gate consumers and research on evidence applicability. See
ROADMAP.md and CONTRIBUTING.md.

Quick start

cp .env.example .env    # optional
docker compose up --build
# open http://127.0.0.1:3000

Licensed under Apache-2.0.