We open sourced our entire AI governance toolkit today. Apache 2.0, component by component over the coming months.
The company post lays out the full reasoning — why we're open sourcing everything. This is the part that's mine.
The argument that sounds like weakness
The claim I'd defend hardest is the one about the moat, because it's the one that sounds like weakness. A security company announcing free software reads as distress, and anyone mid-cycle with us will notice.
So, plainly: our gateway is good engineering, but it isn't secret engineering. A competent team that set out to rebuild it could, in a quarter.
What nobody rebuilds in a quarter:
- The policy library. It came out of running this in regulated environments, against real findings, not out of a design doc.
- Compliance evidence an auditor will actually accept. Which is a different artefact from logs, and the difference takes years to learn.
- Someone to call when it breaks at 3am. No licence grants you that.
I'd rather say that out loud than price the code as though it were the hard part.
What's actually in the box
The other thing I keep coming back to is the size of what we're asking for. We want security teams to put our software between their staff and their models — in the path of the traffic that matters most.
I've sat in the reviews where a CISO asks what's actually in the box. “Trust us” was never a good answer. It's a worse one every year, and it should be. The people pushing back hardest on this are the ones doing their job properly.
Now the answer is: read it.
What I want back
Not stars. Someone getting past the gateway and telling us how. We'd rather learn it from you than from an incident report — and if you build something on top of it, that's the part we can't do alone.
Which of your vendors could you actually read, if you asked?