Founder Notes

The part of open sourcing I'd defend hardest

A founder's note alongside the open-source announcement: why the moat argument is the one that sounds like weakness, and why saying it out loud beats pricing the code as if it were the hard part.

3 min read
The part of open sourcing I'd defend hardest
Founder Notes
Contents·3 sections

We open sourced our entire AI governance toolkit today. Apache 2.0, component by component over the coming months.

The company post lays out the full reasoning — why we're open sourcing everything. This is the part that's mine.

The argument that sounds like weakness

The claim I'd defend hardest is the one about the moat, because it's the one that sounds like weakness. A security company announcing free software reads as distress, and anyone mid-cycle with us will notice.

So, plainly: our gateway is good engineering, but it isn't secret engineering. A competent team that set out to rebuild it could, in a quarter.

What nobody rebuilds in a quarter:

  • The policy library. It came out of running this in regulated environments, against real findings, not out of a design doc.
  • Compliance evidence an auditor will actually accept. Which is a different artefact from logs, and the difference takes years to learn.
  • Someone to call when it breaks at 3am. No licence grants you that.

I'd rather say that out loud than price the code as though it were the hard part.

What's actually in the box

The other thing I keep coming back to is the size of what we're asking for. We want security teams to put our software between their staff and their models — in the path of the traffic that matters most.

I've sat in the reviews where a CISO asks what's actually in the box. “Trust us” was never a good answer. It's a worse one every year, and it should be. The people pushing back hardest on this are the ones doing their job properly.

Now the answer is: read it.

What I want back

Not stars. Someone getting past the gateway and telling us how. We'd rather learn it from you than from an incident report — and if you build something on top of it, that's the part we can't do alone.

Which of your vendors could you actually read, if you asked?

Filed under

Open SourceFounder NotesAI GovernanceStrategy
Get started

Read next

How to Discover Shadow AI: Detection Methods, Blind Spots, and a Gateway-First Approach

A practical guide to shadow AI discovery — the detection methods that actually work, where each one goes blind, and how Prompt Shields surfaces every AI tool, integration, and vendor touching your data.