v10.17 Β· Harness engineering + governance + evidence Β· 100% aligned
πŸ”’ Proprietary Β· Source-available

Harness engineering + governance + evidence.

Hashimoto coined the term in Feb 2026. OpenAI institutionalized it. Fowler formalized it. We ship it to production with the 3 layers the pure pattern omits: 10-category DLP scrubber, dual-rail audit trail, and output guards across 9 compliance frameworks.

Baseline is the multi-runtime harness (14+ runtimes). GlassPlane is the control plane (18 live compliance dimensions). We use it for our own factory. We license it so you can use it too.

● Feb 5 2026 β€” Hashimoto coins the term ● Feb 11 2026 β€” OpenAI institutionalizes ● Mar 17 2026 β€” OSSFIA v4.0 ships ● Apr 2 2026 β€” Fowler formalizes ● May 9 2026 β€” OSSFIA v10.17 strategic decisions sprint
NIST CSF 2.0 NIST AI RMF EU AI Act NIS2 (EU) ISO 42001 SOC 2 Law 1581 (Colombia) + LATAM
14+
Supported runtimes
9
Compliance packs
18
GlassPlane dimensions
131
Linter checks
100%
Aligned vs state-of-art
The problem

The market has tools to generate code with AI.

Nobody has a system to govern it.

1.7Γ—
more defects in AI-generated code vs human-written code (CodeRabbit, 8.1M PRs analyzed in 2026)
91%
increase in code review time since AI adoption (LinearB Benchmarks 2026)
€35M
maximum EU AI Act penalty, in force August 2026. Only 6% of organizations have a formal AI governance strategy (Gartner)

Traditional dev shops don't know how to build with autonomous agents.
AI governance vendors (Credo AI, Holistic AI, Fiddler) charge enterprise pricing for the dashboard alone β€” and you still need someone to actually build the software.

We do both.

Harness engineering Β· State-of-art

3 standard pillars + 3 layers only OSSFIA brings

Hashimoto, OpenAI, and Fowler defined harness engineering as the tooling that steers AI agents toward specific objectives via infrastructure. But the pure pattern is productivity-only β€” it omits governance, DLP, and compliance. OSSFIA ships it with the 3 layers regulated industries actually need.

The 3 standard pillars
🧠

Pillar 1 β€” Context engineering

CLAUDE.md + AGENTS.md + skills + rules + progressive disclosure. What the agent can't see, doesn't exist.

OSSFIA: 19 always-on rules + 50 skills + 14+ runtimes via AGENTS.md universal LCD
πŸ”§

Pillar 2 β€” Architectural constraints

Linters, hooks, dependency layers mechanically enforced. Unidirectional layers (Types β†’ Config β†’ Repo β†’ Service β†’ Runtime β†’ UI).

OSSFIA: 98 linter checks + 8 hooks + dep-graph-check.py ArchUnit-style + spec-first .openspec/
♻️

Pillar 3 β€” Entropy management

Periodic agents validate docs vs code, remove dead code, detect drift. The repository = single source of truth.

OSSFIA: daily-drift-check.yml + canonical-check + KNOWLEDGE-01 detects Confluence/Notion/Slack URLs
The OSSFIA moat β€” 3 layers pure harness eng omits

What DIY cannot replicate in under 12 months

The nxcode 'Harness Engineering Complete Guide 2026' article is excellent "Harness Engineering 101". OSSFIA is the full graduate program for regulated industries.

πŸ›‘οΈ
Layer 1 β€” DLP scrubber

10 formal categories with absolute BLOCK (CDI / JDI / SEC / BIO) + automatic REDACT (PII / PHI / PFI / HRI) + auditable WARN (AUD / IPR). Applied at runtime BEFORE any external model.

DIY estimate: 6-12 months for taxonomy + scrubber + tests + integration
πŸ“œ
Layer 2 β€” Dual-rail audit trail

Canonical schema work_agent_executions.sql + actor_origen + actor_id columns on operational tables. GlassPlane dim 17 work_automation_ratio.

DIY estimate: 3-6 months schema + dual-rail DB + dashboards
βš–οΈ
Layer 3 β€” Multi-framework output guards

AURA 4 levels + scoring against 9 simultaneous frameworks: NIST CSF 2.0 (93%), AI RMF (93%), SSDF (95%), GenAI (80%), EU AI Act, NIS2, ISO 42001, SOC 2 + LATAM packs.

DIY estimate: 12-18 months PER FRAMEWORK. 108-162 months for all 9.

OSSFIA total: additive brownfield in ~1 day with everything included. Saves 12-24 months of engineering plus the cost of not having it when EU AI Act enforcement hits (Aug 2 2026).

Scope-based quote β€” book a 30-min diagnostic call and we'll review your project.

Side-by-side Β· Pure Harness Engineering vs OSSFIA
Capability Pure Harness Engineering (DIY) OSSFIA
Time to ship governance harness6-12 dedicated months~1 day brownfield
Multi-runtime supportLock-in14+ runtimes
DLP scrubberDIY10 categories + 20 tests/cat
Dual-rail audit trailDIYwork_agent_executions schema
Compliance frameworks0-19 cross-mapped
CVE freshnesshardcodedOSV.dev 24h refresh
LATAM regulatoryinvisibleLaw 1581, RIPS, SFC, SNIES, LGPD
Time-to-value vs cost12-24 engineering months~1 day brownfield + retainer

Full battlecard with 14 capabilities + 6 objections + 5 closing tactics: framework/reference/marketing/battlecards/BATTLECARD_vs_Pure_Harness_Engineering.md in the public repo.

Our method

ADLC β€” Agentic Development Life Cycle

10 phases, 3 macro-stages, formal gates with automated enforcement. Replaces the traditional SDLC for development with autonomous agents.

Macro 1

🧠 Think

Strategy, domain, knowledge, architecture. Decide what to build and under what regulatory constraints.

F01 Strategy F02 Domain F03 Knowledge F04 Architecture
Gates: A B C
Macro 2

πŸ”¨ Build

Contracts, AI-assisted build, TEVV (test + eval + verify + validate), security & compliance.

F05 Contracts F06 AI Build F07 TEVV F08 Security
Gates: D E
Macro 3

πŸš€ Operate

Deploy, continuous operation with GenOps, metrics, and evolution based on real telemetry.

F09 Deploy & Ops F10 Evolve
Gate: F

What makes OSSFIA different

βœ“
Complete lifecycle β€” 10 phases vs 3 in Kiro/AWS, 0 in Cursor/Devin
βœ“
6 formal gates with 60 Python enforcement scripts
βœ“
Multi-regulatory compliance β€” 10+ frameworks simultaneously (EU AI Act, NIS2, ISO 42001, NIST CSF 2.0, NIST AI RMF, OWASP, SOC 2, Colombia Law 1581 + LATAM)
βœ“
19 Invisible Intelligence modules evaluable against every business domain
βœ“
10 DLP categories with automatic BLOCK/REDACT/WARN (PII, PHI, CDI, JDI, SEC, BIO...)
βœ“
Kill switch with verified drills β€” auditable emergency stop
βœ“
Brownfield adoption (Strangler Fig AI) β€” adoptable on existing code
βœ“
Native LATAM regulatory coverage β€” the only AI governance framework written from Colombia
How we work with you

Two engagement models, one harness

You choose the autonomy level. We give you the same Baseline + GlassPlane underneath. No tier or feature gating on compliance β€” the regulatory evidence is the same regardless of how you contract us.

🀝
Model A

Co-creation / Adoption

Your team builds; we are the harness and sparring partner. We install Baseline in your repo, configure GlassPlane for your portfolio, train your devs with our 17 specialized subagents, and gradually remove the scaffolding as your team matures.

βœ“
Additive brownfield adoption β€” we install baseline/ as a subtree without touching your existing code
βœ“
17 subagents + 50 skills + 19 always-on rules auto-invoked by ADLC phase
βœ“
Multi-runtime β€” works with the tooling you already use (Claude Code, Cursor, Copilot, Junie, Codex...)
βœ“
Pair programming with OSSFIA architects β€” weekly sessions to review ADRs, gates, and the compliance scorecard
βœ“
Daily auto-sync β€” your repo gets baseline updates automatically via GitHub Action
βœ“
Clear exit ramp β€” the harness is yours. You can continue solo whenever you want
Ideal for
CTOs with their own team who need governance, not extra developers. Companies with internal CISOs who want auditable evidence without rewriting their SDLC.
Discuss adoption β†’
Most common
🏭
Model B

Turnkey Software Factory

We build; you receive product + evidence. You hand off an intent (business problem + constraints), our FABs (FullStack Agent Builders) execute the ADLC F01-F10 autonomously, and we deliver release + GlassPlane scorecard + signed AIBOM/SBOM every month.

βœ“
Intent β†’ Release in a closed loop. You don't manage tickets, you manage outcomes
βœ“
Autonomous FABs with kill switch β€” cost guard, circuit breakers, verified quarterly drills
βœ“
Continuous Conformity Monitoring β€” your production system runs every 6h with auditable session recordings
βœ“
Monthly regulatory evidence β€” EU AI Act, NIS2, ISO 42001, NIST CSF 2.0 + AI RMF, SOC 2 ready for your auditor
βœ“
DORA + SPACE + DX-AI metrics β€” we know how much code AI contributes vs human and how it benchmarks
βœ“
Branded reports for your board, your regulator, your cyber insurance carrier
Ideal for
Companies that want to launch a product without hiring 15 engineers. Regulated sectors (healthcare, fintech, government, public education) where compliance is a licensing condition.
Start factory β†’
In both models

Same Baseline harness. Same GlassPlane. Same 18 compliance dimensions. Same regulatory evidence. The difference is who writes the code β€” your team or ours β€” not how rigorous the governance is.

NEW v10.17 Β· Bet 1 B2B2B

For cyber insurance carriers

Underwriting platform that continuously measures the NIST AI RMF + MITRE ATLAS posture of your insureds, via API, with 30-day refresh. You keep the underwriting; we give you the objective evidence underneath.

βœ—
Today: annual PDF questionnaire
Self-reported, static, stale within 3 months
βœ“
With OSSFIA: live API scorecard
30-day refresh + webhook alerts on score drops
βœ—
Today: blind AI-specific exclusions
No objective evidence β†’ blanket premium hikes
βœ“
With OSSFIA: differentiated pricing
Score β‰₯90 = preferred premium Β· <60 = denial/uplift
βœ—
Today: manual NAIC compliance
Underwriter ad-hoc per insured, not scalable
βœ“
With OSSFIA: NAIC-defensible automated
Immutable dual-rail audit log + signed AIBOM/SBOM
βœ—
Today: post-incident "I can't find the logs"
Forensic blind for claim defense
βœ“
With OSSFIA: complete chain of custody
work_agent_executions + cosign signatures + provenance

6 underwriting coverage areas

AI Governance 25%
Policies + RACI + risk register + incident plan
Data Protection 20%
data_classification + 10-cat DLP scrubber + provenance
Adversarial (MITRE ATLAS) 20%
threat_model + adversarial eval + OWASP ASI
Audit Trail 15%
work_agent_executions + AIBOM + SBOM + monitoring
Incident Response 15%
incident_plan + recovery + kill switch + post-mortem
Human Oversight (EU AI Act 14) 5%
WA registry + dual-rail + escalation config
Underwriting score tiers
β‰₯90
Excellent Β· Preferred premium Β· No AI exclusions
75-89
Good Β· Standard premium Β· Light AI exclusions
60-74
Acceptable Β· 10-30% uplift Β· Moderate exclusions
<60
Poor Β· Denial OR aggressive AI exclusions

1 implementation, 2 GTM motions

Your insured implements OSSFIA on their side (Bet 2). You access the scorecard via API with OAuth consent (Bet 1). Same baseline + GlassPlane underneath. Validated B2B2B chain.

🀝
1. Insured implements
Additive brownfield in 1 day. LATAM pack or sector-specific.
πŸ“Š
2. GlassPlane scores
18 live dim + 6 coverage areas + continuous 0-100 score.
πŸ›οΈ
3. Carrier consumes API
OAuth grant from the insured. Underwriter uses score in pricing engine.
Pilot program for carriers β†’

Targets: LATAM Q3 2026 Β· 3-phase pilot setup β†’ operational β†’ scale Β· scope-based quote per carrier engagement

Living proof

Every delivery comes with measurable evidence

GlassPlane is the private dashboard we give every customer. It scans your project against 16 compliance dimensions in real time. Your team sees the score; your auditors see the evidence.

GP
GlassPlane
Customer portfolio
Repos monitored
5
Average score
79
Silver β†’ Gold
Need attention
0
3 healthy
Weakest area
Gates
Avg: 48
Averages by dimension
EU AI Act
96
Specs
94
FinOps
94
DORA+DX
90
NIST Agent
87
Task-Flow
81
AI Gov
77
Data
75
Security
73
Framework
71
SAST/SCA
66
OWASP
55
Gates
48
* Illustrative data from a real customer portfolio, anonymized.

You're free to see even our weaknesses. This portfolio shows real scores β€” EU AI Act 96, but Gates 48. That's how we work: no black boxes. Your auditors can validate the evidence directly.

New β€” Cloudflare Browser Run GA April 2026

Continuous Conformity Monitoring

We don't just measure your software. We execute it every 6 hours with AI agents that walk through critical flows like real users, and we archive the recordings as auditable evidence for your regulators.

Growth tier projection
840
monitored executions per month
7 critical flows Γ— every 6h Γ— 30 days Β· full DOM replay available for your auditor
🎬

Auditable session recordings

DOM + mouse + keyboard + network for every execution, encrypted in R2 with 365-day retention. Meets ISO 42001 Annex B and EU AI Act Art. 72.

🧠

Semantic LLM evaluation

We validate that your AI chat (AURA or others) responds correctly against golden datasets β€” by meaning, not by string match.

πŸ‘₯

Persona-Based Usability

We simulate doctor_senior, patient_65+, admin_compliance, accountant β€” and report real friction by persona.

⚑

30-minute alert SLA

Critical flows that fail alert your team's webhook within 30 min max. Automatic 3-level escalation if there's no ack.

Why this is the only defensible moat in LATAM

Credo AI / Holistic AI / Fiddler

Static compliance dashboards. They measure artifacts, not live behavior. Enterprise pricing.

Traditional dev shops

They build software, but without auditable regulatory evidence. When the regulator shows up, you're the one assembling the report.

OSSFIA (us)

Both β€” we build + monitor + give you signed evidence every month. Included in retainer.

Implemented on Cloudflare Browser Run (GA 2026-04-15). Available automatically for Growth and Enterprise tier customers. No additional charge on top of the monthly retainer.

Multi-framework compliance

10 regulatory frameworks. One delivery.

When we deliver a sprint, it ships with scoring against all 10 frameworks at once: NIST CSF 2.0, NIST AI RMF, EU AI Act, NIS2, ISO 42001, SOC 2, and the native LATAM packs. No separate "compliance consulting" services, no rework, no surprises for your auditor.

NIST stack coverage Β· v10.17

Auditable against CSF 2.0 (CSWP 29, Feb 2024), AI RMF 1.0 (AI 100-1), GenAI Profile (AI 600-1), SSDF v1.1 (SP 800-218 + 218A), SP 800-53r5

6 NIST publications
NIST CSF 2.0
93%
6 functions Β· GV/ID/PR/DE/RS/RC
AI RMF 1.0
93%
GV / MAP / MEASURE / MANAGE
SSDF v1.1
95%
SP 800-218 + 218A AI augmentations
GenAI Profile
80%
AI 600-1 Β· 12 risk categories
SP 800-53r5
75%
Federal controls
OSCAL emit
30%
Phase 2 scaffolding
Roadmap to 99%
v11.5
12-18 months Β· public on GitHub

Global + native LATAM packs

Same Baseline, same GlassPlane, same sprint β€” scoring against all of them simultaneously

Global
πŸ‡ͺπŸ‡Ί
EU AI Act
In force Aug 2 2026

Article 14 (human oversight), Annex IV technical doc, conformity assessment. Pack + battlecard.

πŸ”’
NIS2 Directive EU
NEW
In force Oct 17 2024

Article 21 β€” 10 cyber risk measures. 18 EU critical sectors. ~90% mapping with NIST CSF 2.0. Up to €10M / 2% revenue.

πŸ“‹
ISO/IEC 42001
AIMS certification ready

Annex A controls, automatic evidence collector script, mapping to SOC 2 CC + assisted audit.

πŸ›‘οΈ
SOC 2 Type II
v10.16 productized pack

Trust Service Criteria CC1-CC9, existing evidence collector, cross-mapping with ISO 42001.

LATAM native Β· Production validated
Bet 2 Β· v10.17
πŸ₯
Healthcare IPS (Colombia)
Production
Res 1995 Β· 1438 Β· 1888 Β· 839
  • β€’ RIPS JSON 2025 + CUPS + ICD-10
  • β€’ FHIR-ready HL7 interoperability
  • β€’ Sectoral authorization Res 1438
  • β€’ DLP-PHI + DLP-CDI (minors) BLOCK
  • β€’ SIVIGILA auto notification
Reference deployment Β· Hospital ERP + longitudinal EHR Β· 1,070 automated tests
πŸ’°
Fintech Coop SFC (Colombia)
37 Executors
Circulars 007 Β· 008 SFC
  • β€’ Superfinanciera operational + cyber
  • β€’ IT risk Circular 008
  • β€’ Cooperatives vs traditional banking
  • β€’ DLP-PFI + AML/KYC + UIAF reporting
  • β€’ Financial Habeas Data (Law 1581)
Reference deployment Β· Cooperative credit platform Β· 37 dual-rail Work Agents
πŸŽ“
Public Higher-Ed (Colombia)
7+ Executors
SNIES Β· SPADIES Β· SACES
  • β€’ Automated MinEdu academic reports
  • β€’ Qualified registry + accreditation
  • β€’ PILA + DIAN university payroll
  • β€’ Faculty rank + salary points
  • β€’ Habeas Data art. 24 (education)
Reference deployment Β· University payroll + faculty rank Β· 7+ Work Agents
Bet 2 Β· LATAM mid-market

3 production-validated packs. Compatible with any regulated LATAM sector.

If you're an IPS in Colombia, an SFC-regulated cooperative, a public higher-ed institution, or an equivalent regulated sector (critical manufacturing, telco, energy LATAM), we start in ~1 day with additive brownfield. If your sector ISN'T covered but has similar regulation, we build a tailored pack in 4-8 weeks and it stays as reference.

Cross-mapping NIS2 ↔ NIST CSF 2.0

One sprint, two frameworks covered

NIS2 Article 21 (10 cyber risk management measures) has ~90% overlap with NIST CSF 2.0. We build it once, report in both formats.

NIS2 Article 21 β€” measure NIST CSF 2.0 β€” function OSSFIA
a) Risk analysis & info system security policiesGOVERN (GV.RM, GV.PO)βœ“
b) Incident handlingRESPOND + RECOVERβœ“
c) Business continuity & backup mgmtRECOVER (RC.RP, RC.CO)βœ“
d) Supply chain securityIDENTIFY (ID.SC) + AIBOM/SBOMβœ“
e) Vulnerability handling & disclosurePROTECT (PR.IP) + SECURITY.mdβœ“
f) Cybersecurity assessment policiesDETECT (DE.CM) + auditsβœ“
g) Cyber hygiene + trainingPROTECT (PR.AT)βœ“
h) Cryptography + encryptionPROTECT (PR.DS)βœ“
i) Human resources security & accessGOVERN (GV.RR-04) + IDENTIFYβœ“
j) MFA, secure comms, emergency commsPROTECT (PR.AA, PR.PS)βœ“

Applicable to essential entities (energy, healthcare, transport, banking, digital infra, government) and important entities (critical manufacturing, food, waste, postal). Penalties up to €10M or 2% global revenue.

10 DLP categories β€” runtime enforcement

Every prompt to an external LLM is filtered against these 10 categories. Absolute BLOCK, automatic REDACT, auditable WARN.

CDI
Minors
BLOCK
JDI
Judicial
BLOCK
SEC
Secrets
BLOCK
BIO
Biometric
BLOCK
PII
Personal
REDACT
PHI
Health
REDACT
PFI
Financial
REDACT
HRI
HR
REDACT
AUD
Audit
WARN
IPR
IP source
WARN

Native Habeas Data (Colombia Law 1581) Β· GDPR Art. 9 Β· HIPAA Safe Harbor Β· ADR-FRAMEWORK-010 dogfooded

Engagement

Sized to your project's real scope

OSSFIA is XCloud Solutions' proprietary methodology. We use it to build our own software, on third-party engagements, and for co-creation with clients (always under contract). Every engagement is scoped individually β€” we don't publish rates because every case is different.

🀝

Co-creation

Your team and ours build together. You pay for the harness + sparring; the code and the harness stay in your repo.

Under MSA + SOW per engagement
🏭

Turnkey software factory

We build, you receive product + monthly regulatory evidence. Outcome-based model + GlassPlane score gates in the contract.

Monthly retainer + signed deliverables
πŸ›‘οΈ

Cyber insurance underwriting

For carriers that need to measure NIST AI RMF / MITRE ATLAS compliance of their insureds (B2B2B).

Platform + API integration + carrier retainer

How we quote

πŸ“‹
1. Diagnostic call
30 min, no cost. We review your project + regulatory sector.
πŸ“Š
2. GlassPlane scorecard
What score you'd have today across the 18 dimensions. No commitment.
πŸ“„
3. SOW + quote
Scope, milestones, gates, monthly retainer sized to fit.
Book diagnostic call (30 min) β†’

OSSFIA is proprietary. Available only under contract. It is not open source and is not licensed individually β€” it is the methodology we use to build.

vs alternatives β€” including "build your own harness"

Tools generate.
OSSFIA governs with compliance.

We don't compete with Cursor / Copilot / Codex (we use them as runtimes). Nor with DIY harness engineering (we applaud it but add the 3 layers). 16-capability table, 6 columns β€” including the "Pure Harness Engineering" route that sells 6-12 months of engineer time.

Capability Cursor GitHub Copilot MS AI Toolkit Devin / Factory Pure HE (DIY) OSSFIA
Code generation βœ“ βœ“ βœ“ βœ“ βœ“ βœ“ via 14+ runtimes
Multi-runtime governance βœ— βœ— partial βœ— lock-in DIY βœ“ 14+ runtimes
ADLC / 10-phase lifecycle βœ— βœ— βœ— 3 phases βœ— βœ“ F00-F10
EU AI Act evidence auto βœ— βœ— templates βœ— βœ— βœ“ Art 14 + Annex IV
NIS2 Directive EU (Art 21) βœ— βœ— βœ— βœ— βœ— βœ“ 10 risk measures
NIST CSF 2.0 + AI RMF βœ— βœ— ~40% βœ— βœ— 93% / 93%
10-category DLP scrubber βœ— basic PII basic PII βœ— βœ— DIY 6-12m βœ“ CDI/JDI/PHI/PFI/BIO+
Dual-rail audit trail βœ— βœ— βœ— βœ— βœ— DIY 3-6m βœ“ work_agent_executions
Native LATAM regulatory βœ— βœ— βœ— βœ— βœ— invisible βœ“ 1581/1995/SFC/SNIES
Live compliance dashboard βœ— βœ— excel exports βœ— DIY dashboards βœ“ GlassPlane 18-dim
Continuous Conformity (6h) βœ— βœ— βœ— βœ— βœ— βœ“ unique in LATAM
Loop detection + drift βœ— βœ— βœ— βœ— DIY hooks βœ“ pre_tool_use + daily-drift
Signed AIBOM + SBOM βœ— βœ— SBOM only βœ— βœ— βœ“ cosign + SLSA
CVE freshness (MCP packages) βœ— βœ— manual βœ— hardcoded βœ“ OSV.dev 24h refresh
Time to ship governance N/A (tool) N/A (tool) 2-4 weeks M365 N/A 6-12 months DIY ~1 day brownfield
Sovereign on-prem βœ— SaaS βœ— SaaS Azure only βœ— SaaS βœ“ DIY βœ“ deploy anywhere
Commercial model per developer per developer M365 license per developer 3-5 internal engineers scope-based retainer
πŸ› οΈ

Cursor / Copilot / Codex

Excellent code generators. Your team will keep using them under OSSFIA β€” we are the harness, not the competitor.

πŸ“Š

Credo / Holistic / Fiddler

Static governance dashboards. They only measure artifacts; they don't build software or integrate with your pipeline. High enterprise pricing.

πŸ”¨

Pure Harness Engineering (DIY)

3 pillars from Hashimoto/OpenAI/Fowler. Excellent theory. 6-12 months of 3-5 engineers to implement. And you still need the 3 regulatory layers.

⚑

OSSFIA Baseline + GlassPlane

3 pillars + 3 integrated layers. Additive brownfield in ~1 day. A single source of truth for your CISO and your CTO. Scope-based quote.

Cases in production

Real software with auditable evidence

GlassPlane is our own control plane β€” we built it for ourselves before licensing it. If we didn't apply it to Baseline, we couldn't sell it.

GP
Featured case Β· Dogfooding

GlassPlane control plane

The same dashboard we deliver to customers, applied to our own Baseline repo (github.com/aforero22/baseline). 18 compliance dimensions, fingerprint dedup, 9 regulatory frameworks scored simultaneously.

βœ“18 live compliance dimensions
βœ“122/122 tests framework green
βœ“19/0/0 canonical-check
βœ“10 consumers daily auto-sync
βœ“v10.17 stable, 2026-05-09
βœ“~157K LOC auto-inventoried
Stack: Python 3.10 Β· Bash Β· Cloudflare Workers Β· Wrangler Β· MCP servers Β· GitHub Actions
GlassPlane score
87
Gold Β· Healthy
EU AI Act 96 Β· Specs 94 Β· FinOps 94 Β· DORA 90
NIST Agent 87 Β· Task-Flow 81 Β· Data 75
github.com/aforero22/baseline
Production customers Β· validated

Commercial names under NDA. Numbers and stacks are real. We sign MSA + SOW before sharing direct references and detailed architecture.

πŸ₯
Healthcare Β· IPS (Colombia)

Hospital ERP + longitudinal EHR

90
Gold
Production live
  • β€’ RIPS JSON Res 1888/2025 + CUPS + ICD-10
  • β€’ FHIR-ready Res 839 interoperability
  • β€’ DLP-PHI + DLP-CDI (minors) runtime enforcement
  • β€’ 104 tables Β· 360+ endpoints Β· 1,070 tests
  • β€’ AURA: 15 tools + 9 workflows
Pack: pack_salud_ips v1.0 productized
Stack: Hono JSX + Cloudflare D1 + R2 + Workers AI
πŸ’°
Fintech Β· SFC Cooperative (Colombia)

Cooperative credit platform

88
Gold
37 Executors live
  • β€’ SFC Circular 007 + 008 cybersecurity
  • β€’ Operational risk + AML/KYC + UIAF reporting
  • β€’ DLP-PFI scrubber + accounts + cards
  • β€’ Financial Law 1581 + Habeas Data
  • β€’ 37 Work Agents dual-rail in production
Pack: pack_fintech_coop v1.0 productized
Stack: Hono + Cloudflare Workers + D1 + Workers AI
πŸŽ“
Public Higher-Ed (Colombia)

University payroll + faculty rank

85
Gold
7+ Executors live
  • β€’ PILA 2000-char + DIAN e-payroll
  • β€’ SNIES + SPADIES + SACES MinEdu reporting
  • β€’ Faculty rank + salary points + research
  • β€’ Law 1581 art 24 (sensitive education data)
  • β€’ 7+ Work Agents Β· 85% AURA validation
Pack: pack_ies_publica v1.0 productized
Stack: Astro + Hono + Cloudflare D1 + Workers AI
Pre-validation

These 3 cases represent the 3 productized LATAM packs we offer. Each customer was an additive brownfield. Their regulators don't need a PDF to see compliance β€” they read the live GlassPlane scorecard.

We sign MSA + SOW before sharing commercial names, detailed architecture, or direct references. Book a diagnostic call so we can discuss your case.

Let's talk

Your use case, one conversation

30 minutes. No cost. No pitch deck. You walk away with a preliminary GlassPlane scorecard for your project.

🀝
CIO / CTO

I want to adopt OSSFIA

I have my own dev team. I need governance + compliance evidence without rewriting my SDLC.

Discuss adoption β†’
🏭
Company

I want you to build

I need product in production + regulatory evidence. I don't want to hire 15 engineers.

Start factory β†’
πŸ›‘οΈ
CISO / Compliance

I'm getting audited in X months

EU AI Act, ISO 42001, SOC 2 or a regulator audit is coming. I need auditable evidence, not spreadsheets.

Gap assessment β†’
πŸ›οΈ
Cyber insurance carrier

I'm a carrier or broker

B2B2B underwriting platform. Continuous NIST AI RMF + MITRE ATLAS scoring of your insureds, via API, with 30-day refresh.

Pilot program β†’
Direct email
[email protected]
WhatsApp
+57 316 565 0842
Operation
XCloud Solutions
Colombia β†’ LATAM
Hours
Mon-Fri 08:00–18:00
COT (UTC-5)