Skip to content
Investor Brief · June 2026

AI-Assisted Engineering
Runtime Governance.

Employees, contractors, and autonomous agents now run Claude, Cursor, shell, GitHub, cloud tools, and MCP servers against real repos and production infrastructure. The open question is “which governed actions occurred, and who authorized them?” OpenSyber answers it — isolate the workspace, govern the tool call, and explain the audit chain.

Pre-revenue · bootstrapped · seeking 3–5 design partners and pre-seed conversations.

Why now
01

An AI cleanup agent deleted a production database — and every backup — in 9 seconds. An over-permissioned token and no gate on irreversible actions.

02

Shai-Hulud (TeamPCP): a worm that hijacks AI-dev-tool config, plants an auto-run hook, and steals GitHub/npm tokens. Source is public.

03

Staged MCP rug-pulls swap a hidden instruction after N clean calls — a single-session scanner can miss the change.

Architecture problems, not model failures. The threat model already shifted.

Market
$1.65B

Agentic AI security, 2026 → $13.52B by 2032 (42.0% CAGR)

MarketsandMarkets

$3.59B

AI-TRiSM, 2026 → $21.06B by 2035 (~21.7% CAGR)

Precedence

150K+

AI agents per Fortune 500 by 2028 — agent sprawl

Gartner

$0

Published standalone MCP-security TAM — open whitespace

verified by absence

The relevant band is $1.65B–$3.59B “security-for-AI,” not the ~$51B headline. Cross-session MCP drift is the least-crowded whitespace.

The product
01

Isolate

Browser-isolated governed workspaces replace unmanaged execution paths for AI-assisted development.

02

Govern

MCP, shell, GitHub, and cloud actions are checked before execution with allow, step-up, or deny decisions.

03

Explain

Prompt → tool → repo → infra linking shows who did what, when, why, and which policy decided it.

04

Export

Scoped evidence packs map audit-chain events to selected SOC 2 / ISO 27001 / ISO 42001 controls for review; they are not certification.

Defensible moat

Cross-session MCP drift

Single-session checks can miss a tool definition that changes later. We fingerprint configured tools across days and surface drift for review.

MCP policy chokepoint

Configured MCP calls can be evaluated inline with allow / step-up / deny decisions instead of relying only on after-the-fact detection.

GitHub policy bridge

Prod-touching commits are gated by AI-session identity with step-up auth.

Device-bound sessions

TokenForge uses non-extractable ECDSA P-256 device keys to resist cookie-only replay in supported browser flows.

Verified marketplace

Published versions can expose SBOM, signature, and OSV.dev scan metadata for supported skills and MCP servers.

Where we are (honest)
11

apps + 26 packages shipped

Dated

local test artifacts across measured suites

~159

D1 tables · 71 migrations · 195 API routes

19

marketplace skills (6 AI + 13 utility)

Pre-revenue, pre-design-partner. LemonSqueezy billing live. Product Hunt launch timing is not committed.

The ask

Three design partners. One quarter. One proven catch each.

We commit to surfacing at least one finding your current stack missed — an over-permissioned agent token, an unaudited MCP call, or a drifted tool definition. Investors and operators in AI-assisted engineering governance: let’s talk.