Everything you need to ship secure products — CRA compliance tools, platform documentation, and the builder community.
EU Cyber Resilience Act — automated SBOM monitoring, CISA KEV CVE tracking, VEX generation, and ENISA notification drafts.
CycloneDX 1.5 SBOM generation from Python packages. Dependency tree resolution, component hashing, and signature verification. MIT-licensed.
MITDaily CISA KEV catalog matching against your SBOM components. Alerting on actively exploited vulnerabilities with severity scoring.
URGENTVulnerability Exploitability eXchange documents. Declare affected/not-affected status with justification. CSAF 2.0 format.
CommercialAuto-drafted ENISA notification templates for Article 14 reporting. 24-hour actively-exploited vulnerability disclosure workflow.
COMPLIANCECryptographic audit chain from component to SBOM. Immutable verification trail for regulatory submissions and customer assurance.
CommercialRuntime behavioural anomaly detection. Baseline deviation alerts for IoT and embedded devices. Cross-Oracle request signing.
CommercialJoin builders shipping secure products. Get help with SBOMs, CRA compliance, and the kit. Zero sales pitch — just solving the same problem together.
Real-time help with SBOM generation, CISA KEV alerts, CRA interpretation. Weekly office hours. #sbom-help, #cve-tracking, #cra-interpretation.
Join Free 💻Open-source repository. MIT-licensed core modules. Good first issues tagged. Contributions welcome — SBOM improvements, CVE feed integrations, docs.
Open Source 🌐14 live APIs — weather, finance, news, nutrition, security scanning. Free tier, edge-deployed on Cloudflare, no credit card required.
APIsArchitecture overviews, security model, and Oracle reference.
Eight specialist Oracles — Sia, Pythia, Anansi, Nostradamus, Yhi, White Buffalo, Shi Gandang — convened by ICID, who routes every request to the right hand and synthesises a single answer.
CouncilSix immutable rules bind every Oracle: Safety, Privacy, Fairness, Transparency, Accountability, Human Dignity. Hardcoded in the kernel — no Oracle or external instruction can override them.
GovernanceThe governed execution engine. Every action is routed through consent tiers — AUTO, NOTIFY, CONFIRM, DENY — so nothing executes without authorisation.
KernelInjection detection, PII scanning, cross-Oracle signing, harmful-content filtering, behavioural anomaly detection — ten gates on every query, outbound scan on every response.
SecurityYour life data lives in an SQLite vault on your own hardware — HMAC-signed entries, cryptographic provenance, no cloud, no third party.
PrivacySelf-healing sentinels watch every service, proactive pipelines deliver briefings and reminders, and scheduled runs keep Starcaller working while you sleep.
AutonomyStarcaller in daily operation — use cases that demonstrate the system's breadth.
8 Oracles collaborate to produce a personalised daily briefing: weather, news, calendar, health, and security — synthesised by ICID in under 3 seconds.
Daily UseShi Gandang screens all IoT device communications. Physical action blacklist blocks dangerous commands at the kernel level regardless of which Oracle initiated them.
Home AutomationSia cross-references sources against citation networks while Nostradamus identifies trend trajectories. Cited, bias-audited research briefs delivered autonomously.
ResearchA simulated prompt injection via an IoT temperature sensor was blocked by the input sanitisation layer before it reached any Oracle. Audit record produced in 120ms.
SecurityEvery vault entry carries an HMAC-SHA256 source tag. An audit trace confirmed a recalled preference originated from direct user conversation, not a compromised device.
PrivacyYhi oracle, enhanced with financial capability, analyses spending patterns against energy-physics models. Physics-grounded recommendations, not generic advice.
Finance