Home / Investors

For angel investors · published in the open

sgit.ai, for investors

Everything the founder's companies publish for investors, they publish in the open — the pitch, the model, the numbers — and this page follows that rule. What is here can be checked against the site it sits on. What is not here yet is marked as not here yet, rather than filled in.

The problem, in one sentence

AI agents are producing an enormous amount of work, and there is no good unit to hand it over in. A report, a dataset, an application, a talk — today each needs hosting, an account, a deploy, and a trust relationship with whoever runs the server. Meanwhile the state agents need to share with each other and with people is versioned by nobody and readable by the host. The tools that exist were built for source code (git) or for storage (cloud drives). Neither was built for a unit of work that carries its own app, history and sources and can be handed to a stranger with one string.

What sgit is

Git for encrypted vaults. A vault is a folder that is versioned like git — clone, commit, branch, merge, history — encrypted on the client before anything leaves the machine, and openable by anyone who holds the read key: no account, no install, nothing hosted by the reader. A vault can carry its own application, sandboxed, with the permissions it asks for declared in a file. The server stores ciphertext and hashes and cannot read what it stores.

LayerWhat it isWho runs itLicence
sgitThe CLI — pip install sgit-ai. Pure Python, two runtime dependencies.AnyoneApache-2.0
SG/VaultThe web app: browse, edit and run vault apps in the browser. An independent implementation of the same wire format.sgraph.ai, or self-hostedApache-2.0
SG/SendThe zero-knowledge storage API both clients speak to.sgraph.ai (hosted), or self-hosted — the guidance is publishedApache-2.0

The proof is not this page. It is the published vaults: real artefacts — a penetration test report with a retest script per finding, a compliance standard rebuilt as a citable graph, a Black Hat keynote with its cited papers, a game that reports anonymous telemetry through a write-only channel — each opened by one string, each audited before its key went public. Open one before reading further.

Strategic architecture: open source, zero knowledge, zero lock-in

Traction — computed from this site, not typed onto it

These numbers are generated at build time from the site's own data. If one is wrong, the site is wrong somewhere else too.

92site releases since 14 August
each verified live before it was called done
26vaults published with a public read key
every one audited first; findings on the page
19sibling sites on *.sgit.ai
one question each, own repo, own history
36articles and release notes
all with a markdown twin and an RSS feed
10cross-team briefs, in the open
two of them corrected this site
~4,000tests in the CLI, mutation-tested in CI
against a real server, no mocks

Behind the numbers: the site and every vault on it are built by one person and a team of AI agents, and the agents build for each other — a brief published here was turned into a working vault by another agent the same day, reviewed by the team that owns the API, and the review's corrections are published above the original. That loop is the product being used to build the product, and it is documented as a method.

Business model

The code is free. What is sold is the running service, and the trust that comes with running it well.

open-source.sgit.ai · Business & publishingThe position — open source is a strategy, not a charity ↗Technology is not the moat; lock-in relocates to quality, certification and maintainability; the moat is a rate, not a wall. The full argument, with its counter-cases named.“Open source is a strategy. It is not a charity.”part of the sgit.ai network

Market: the beachhead, and what it opens

Beachhead: teams that already run AI agents and need the output to be auditable, encrypted and handed over. Security and compliance work is where this bites first — a pentest report, a conformance assessment, a risk register — because the deliverable must carry its evidence and the recipient cannot be asked to trust a portal. Every published vault in that category was built by an agent and handed over with one string.

Expansion: any team whose agents produce work for other people. The same unit — data, app, history, sources — is a pitch deck, a research pack, a talk, a health record, a game. The vaults table is already spread across eight categories, none of which is "encryption".

The ask

Not filled in — and not invented

Round size, instrument and use of funds are the founder's to state, and they are not on this page yet. Following the rule that nothing here is a number the author has not supplied, this box stays open until it is filled, and the gap is tracked in the open on the board as N1. When it is filled, it will follow the same shape as the founder's other open pitches: the amount, what it buys in the next eighteen months, and the split.

What this is not, and what could go wrong

Investor materials, in the open

MaterialWhereState
This page, as a printable one-pagerPrint it — the site has a print stylesheetlive
The security model and threat model/security/live
When not to use it/docs/limitationslive
Every release, with what went wrong/admin/versionslive
The published vaults — the product, in use/demos/vaults/live
How the company is built: one human, a team of agents/team/live
The founder's record and interests declaredopen-source.sgit.ai/about ↗live
The ask, use of funds, the deckthis page, N1 and N2waiting on the founder

The founder's other companies publish their investor relations in public repositories (MyFeeds.ai ↗, The Cyber Boardroom ↗). sgit.ai's will follow the same practice: this page is the first file in it.

Contact: through LinkedIn ↗, or the repository. If anything on this page is wrong, say so and it will be corrected above the mistake — that is how this site works.