AI that works.Security that comes with it.
Open-source AI and security software, with remote consulting behind it to get it into production. No vendor lock-in, for small and mid-sized companies in Brazil and Germany.
- Published products87 open-source + 1 iOS app
- Applied cybersecurity10+ yearsAppSec · DevSecOps
- OperationRemoteBrazil + Germany
The products that carry the consulting
Eight published: seven open-source on GitHub and one iPhone app.
Okami Agent
Sovereign AI coding agent: capability parity across LLMs, self-improvement (skills, persona, memory) and mandatory design-system adherence. In the terminal, on Telegram, wherever you want.
Okami Monitor
Mission control for multi-agent environments: usage and cost per period, sessions, Kanban, logs, API keys and external runtime connections — in one cockpit.
OkamiCode
Local-first desktop cockpit for AI coding CLIs: folder-bound projects, native sessions per provider, chat, email, Kanban, usage/cost analytics and durable memory — without paying a second API bill.
Okami Maturity
OWASP SAMM v2 maturity assessment: 5 functions, 15 practices, 90 questions — with scorecard, radar, prioritized roadmap and a board-ready PDF report.
Okami Tally
An iPhone panel for your AI subscription quotas — Claude, Codex, Grok, Cursor, Minimax, MiMo and any service with a JSON endpoint. In the app, in widgets, on the Lock Screen and in the Dynamic Island. No backend, no telemetry.
Okami Sentinel
Local workbench for OpenAI Codex Security scans: run, inspect, compare up to six runs and gate changes with versioned guardrails — evidence, cost and context preserved in a local workspace.
OkTally
Every AI coding subscription quota in your macOS menu bar — Claude Code, Codex, Cursor, OpenRouter and more. Colored pins, a popover with the full picture and a notification before you hit the limit. All local, no telemetry.
OkamiUNI
Email and calendar together on the Mac. Unified inbox, macOS calendars and AI to summarize threads, draft replies and turn emails into appointments. Local data, your choice of AI provider.
Remote consulting in AI, AppSec and compliance
Four practices, all remote. Fixed scope or monthly retainer, with a documented technical hand-off.
Consulting
Technical and strategic diagnosis on AI, AppSec and DevSecOps — from architecture to roadmap.
Learn moreCompliance
We build the technical controls and evidence your company needs to pass any audit.
Learn moreDevelopment
Remote engineering with AI agents building products with embedded AI, multi-model gateway and secure infrastructure.
Learn moreYour site can also talk to agents
More and more people ask their assistant before opening a site. WebMCP is the standard that lets a page expose its actions as tools: the agent reads structured data, compares, and only acts with confirmation from the person on screen. We prepare your site for it, from llms.txt to tools, and this one is the proof.
Readable by AI
llms.txt, JSON-LD per page, sitemap with hreflang, robots for AI crawlers.
WebMCP tools
Your main actions exposed via navigator.modelContext, with human confirmation.
Security built in
Threat model for the tools, scope limits and logs. AppSec from the first tool.
Measurement
How assistants cite and use your site, before and after.
The numbers most SMBs find out too late.
Each article answers a question a client asked us, with the source next to it.
What AI really costs in 2026: three bands, with the arithmetic shown
LLM output prices vary 106× between vendors. Your SMB pays the ceiling.
OWASP LLM Top 10 (2025): five risks already in the incident record — and how to cover each
Talk to the people who deliver
No SDR, no drawn-out qualification: whoever answers is whoever delivers.
- sales
- [email protected]
- disclosure
- [email protected]
- where
- Brazil · Germany · 100% remote
Technical reply within 24 business hours.
