AI-Assisted Engineering
Runtime Governance.
Employees, contractors, and autonomous agents now run Claude, Cursor, shell, GitHub, cloud tools, and MCP servers against real repos and production infrastructure. The open question is “what did every AI-assisted action do, and who authorized it?” OpenSyber answers it — isolate the workspace, govern the tool call, and explain the audit chain.
Pre-revenue · bootstrapped · seeking 3–5 design partners and pre-seed conversations.
An AI cleanup agent deleted a production database — and every backup — in 9 seconds. An over-permissioned token and no gate on irreversible actions.
Shai-Hulud (TeamPCP): a worm that hijacks AI-dev-tool config, plants an auto-run hook, and steals GitHub/npm tokens. Source is public.
Staged MCP rug-pulls swap a hidden instruction after N clean calls — invisible to every single-session scanner.
Architecture problems, not model failures. The threat model already shifted.
Agentic AI security, 2026 → $13.52B by 2032 (42.0% CAGR)
MarketsandMarkets
AI-TRiSM, 2026 → $21.06B by 2035 (~21.7% CAGR)
Precedence
AI agents per Fortune 500 by 2028 — agent sprawl
Gartner
Published standalone MCP-security TAM — open whitespace
verified by absence
The relevant band is $1.65B–$3.59B “security-for-AI,” not the ~$51B headline. Cross-session MCP drift is the least-crowded whitespace.
Isolate
Browser-isolated governed workspaces replace unmanaged execution paths for AI-assisted development.
Govern
MCP, shell, GitHub, and cloud actions are checked before execution with allow, step-up, or deny decisions.
Explain
Prompt → tool → repo → infra linking shows who did what, when, why, and which policy decided it.
Export
Evidence packs turn audit-chain events into review-ready SOC 2 / ISO 27001 / ISO 42001 artifacts.
Cross-session MCP drift
Most AI security checks a tool once per session. We fingerprint across days and catch the swap on call N.
MCP policy chokepoint
We intercept the call — allow / step-up / deny — instead of detecting damage after the fact.
GitHub policy bridge
Prod-touching commits are gated by AI-session identity with step-up auth.
Device-bound sessions
TokenForge ECDSA P-256 keys are non-extractable and survive cookie theft.
Verified marketplace
SBOM-attested, ECDSA-signed, OSV.dev CVE-scanned skills and MCP servers.
apps + 26 packages shipped
tests passing across measured suites
D1 tables · 71 migrations · 195 API routes
marketplace skills (6 AI + 13 utility)
Pre-revenue, pre-design-partner. LemonSqueezy billing live. Product Hunt launch planned Q2 2026.
Three design partners. One quarter. One proven catch each.
We commit to surfacing at least one finding your current stack missed — an over-permissioned agent token, an unaudited MCP call, or a drifted tool definition. Investors and operators in AI-assisted engineering governance: let’s talk.