Projects
Software we build ourselves.
Expected Loss Calculator
Closed beta
Puts a number, with error bars, on cyber risk.
Makes cybersecurity risk measurable to find the highest ROI interventions. As analyst you define a threat scenario, assets, and effects. Stakeholders get a quick survey via email to estimate frequency and loss through a calibrated procedure that uses equivalent bets. A Monte Carlo simulation then combines the estimates into a loss distribution and a loss exceedance curve, presented in plain language for the executives and boards who have to decide what to spend.
Sampo
Closed beta
Runs agents for weeks at a time, on a Nextcloud.
Sampo is an Elixir application that supervises long-running agent harnesses. Messages arrive from Nextcloud Talk and are handed to an agent in a tmux session; the agent reads and writes files, calendars and chat through an MCP server that Sampo provides. Between sessions the agent keeps an append-only journal, and a background process consolidates it into a set of linked Markdown notes, so what the agent can learn and grow, while keeping everything transparent and private.
CruxHub
Public
For disagreeing productively.
CruxHub lets two or more people map an argument as a tree of statements, rate their confidence in each one, and see where their views diverge. Comparison views show the trees side by side. A language model helps with routine work such as extracting claims from a shared article; the judgments are made by the participants. CruxHub is live at fenc.es, and the source code is on GitLab.
Hardened Nextcloud hosting
Available
A Nextcloud you can put confidential files on.
Nextcloud deployed on an immutable OS and hardened at every layer, for organisations that need to keep their files, chats, and calls under their own control. We built it because the threat model for self-hosted collaboration has changed. Attackers now use language models to find and exploit weaknesses at a pace that used to require a team, and the agents an organisation runs itself can be turned against it through the documents and messages they read. A Nextcloud with one line of defence should be expected to fall to one or the other. This one assumes the outer layer will be breached: every service is confined to what it needs, secrets are readable only by the process that uses them, and an intrusion detection system cuts off attackers on its own. Deployments are reproducible and roll back automatically when something fails. The configuration has been through the same multi-round adversarial security review we run for clients.
Beta access and hosting.
The closed betas take on a few teams at a time, and hosting is set up per organisation. Write and say what you would use it for.