Security-conscious AI systems, agent infrastructure, and cybersecurity tooling built for control, transparency, and evidence.
BlueDot IT develops open-source tools for local-first AI, authorized security work, vulnerability intelligence, and dependable agent operations. Our projects emphasize explicit authorization, inspectable behavior, practical safeguards, and reproducible results.
| Project | What it does |
|---|---|
| Ódinn Forge | Local-first AI assistant with inspectable memory, approval-gated tools, and auditable activity. |
| GhostMCP | Production-ready cybersecurity tooling MCP server for AI agents. |
| ExploitRank | Vulnerability ingestion, normalization, and exploit-intelligence scoring. |
| DemonClaw | Security-first purple-team agent runtime with WASM sandboxing and tamper-evident evidence logging. |
| SignalGate | Semantic routing layer for OpenClaw and OpenAI-compatible clients. |
| Ares | Autonomous penetration-testing runtime for authorized engagements. |
- Authorization first — consequential actions should be explicit, bounded, and reviewable.
- Evidence over claims — tests, logs, provenance, and reproducible artifacts matter.
- Control stays visible — users should be able to inspect what a system remembers and does.
- Security is part of the design — not an ornamental scan added at release time.
Use security tooling only on systems you own or are explicitly authorized to
test. For vulnerability reports, follow the reporting instructions in the
affected repository's SECURITY.md where available.
Explore our public repositories below to find documentation, contribution guidance, and project-specific licenses.