Cadence: the resource-oriented smart contract programming language of the Flow network. Capability-based security, type safety, and move semantics
-
Updated
Sep 2, 2026 - Go
Cadence: the resource-oriented smart contract programming language of the Flow network. Capability-based security, type safety, and move semantics
A real operating system written from scratch in Embedded Swift for 64-bit ARM: MMU-isolated processes, capability-based security, an in-kernel pure-Swift TCP/IP stack — and it runs nginx, Node.js and SQLite on bare metal.
Open authorization and accountability infrastructure for physical AI: short-lived capabilities, local action gates, replay protection, signed receipts, post-quantum ML-DSA-65, fleet policy/revocation distribution, and a zero-dependency offline browser verifier.
Sandboxed plugin VM with typed capabilities, deterministic replay, and time-travel debugging — written in Rust.
InferNode is a security-focused 64-bit Inferno® OS (ARM64/AMD64) for embedded systems, servers, and AI agents. GPL-free, headless-capable, with 280+ utilities and 9P filesystem protocol. Providing a namespace-based alternative to MCP servers. Namespace-bounded containment of AI agents.
Decentralized OS for multi-tool agent swarms.
AI agent sandbox prison runtime with a local-first desktop app + CLI. Chat with any model (Claude, OpenAI, Groq, Ollama, LM Studio); every action passes Intent → Proposal → Commit through signed capability writs, risk-gated approvals, and a replayable hash-chained ledger. Watch it think in the Mind graph. Cognition proposes; the runtime governs.
Three packages: @kernel.chat/agent-os (POSIX for AI agents — capabilities, namespaces, quotas, taint, audit, vault, outcomes), @kernel.chat/kbot (terminal AI agent, MCP-native, BYOK), @kernel.chat/kbot-finance (audit-grade AI for regulated industries). Provenance-engineering substrate.
Compile-time capability-based security for Rust
The home of the Cadence website
Zero-trust, capability-based Rust microkernel targeting formal verification. Tri-arch (x86_64 / AArch64 / RISC-V). Sovereign and generative: no telemetry, user owns keys and data. Early-stage — see STATUS.md. Inspired by seL4, Hubris, and Redox.
A constraint-native programming language — capability-typed effects, 0.2 research preview
The Deed programming language. Built for code that agents write and humans review.
Self-hosted systems programming langauge with an effect system and compile-time capability enforcement
WasmVault is a security-first package manager and runtime sandbox in Rust that enforces zero-trust, capability-based security and real-time syscall interception for untrusted WebAssembly (WASI) plugins — starting in under 5ms with less than 16MB of overhead.
A language for safe, universal spatiotemporal composability (Cordis paradigm) and orchestration.
A quantum-aware microkernel OS — capability-based IPC, real QPU entropy at boot, holographic kernel memory. Boots in your browser.
An open source RISC-V operating system in Rust — capability-based microkernel, userspace services, and a graphical desktop in QEMU.
Aster RPC -- peer-to-peer RPC framework with identity in the connection. Machines authenticate to machines, on behalf of users. Built on iroh QUIC + Apache Fory + capability-based credentials.
An embeddable, sandbox-first symbolic term-rewriting language and runtime in Rust — exact rational arithmetic and a capability sandbox for safely evaluating untrusted scripts.
To associate your repository with the capability-based-security topic, visit your repo's landing page and select "manage topics."