Policies your team can inspect
Define rules, AI instructions, and capability contracts as versioned repository files.
Policies and profiles
Open-source SDLC governance
AI power to build.
NAOS-Governance for trust.
Bring policies, deterministic checks, and traceability into your repository. Give your team a clearer path from AI-assisted code to human-reviewed delivery.
Between generation and delivery
AI can help write the code. Your team still needs to know which requirements it serves, which checks ran, and what needs review.
NAOS turns your development method into versioned policies, checks, and records that live alongside the work.
Meet the governance kitInside the kit
Start with the controls your project needs.
Extend them through explicit profiles and configuration.
Define rules, AI instructions, and capability contracts as versioned repository files.
Policies and profilesInspect instruction structure, certain duplicate Python functions, obvious secret patterns, and test hygiene.
Explore capability contractsCheck declared links between requirements, tasks, source, tests, and evidence. Make gaps visible.
Traceability checksUse profile-available prompts, task context, and lifecycle records to keep daily work connected.
Workflow catalogueCollect reports, gate status, exceptions, and known gaps in a repository-local evidence pack.
Evidence pack contractGive reviewers structured inputs for remediation, waivers, and delivery decisions.
Scope and boundariesHow it works
NAOS works through files, commands, and configured checks. Your team chooses the tools and retains authority.
Requirements, method,
and profile policy.
Developers and AI tools
work in the repository.
Validators and gates
surface findings.
Reports, exceptions,
and evidence packs.
People review the evidence
and own the next step.
Core deterministic checks require no external AI service.
Inspect the control planeOne foundation. Shared understanding.
Engineering & IT leadership
Bring structure to AI-assisted development without losing the context of your repository.
Security & GRC
Use declared controls, structured findings, and evidence mappings to support your organisation's own control reviews.
Review scopeAudit & review
Navigate local reports, evidence packs, declared review records, and known gaps in an inspectable handoff.
Open the audit playbookNAOS supports governance and review. It does not certify compliance, guarantee secure code, or prove runtime safety.
Start with your repository
Quickstart is the evaluation path. Standard is the recommended starting point for a broader team workflow.
Open the installation guidePython 3.11+ required. Managed activation currently supports Apple Silicon macOS with CPython 3.11–3.13. Linux preview is documented separately in the installation guide.
Enterprise direction
Broader language coverage. More AI platforms and IDEs. Governed external connectors.
Help shape the next chapter around your organisation's needs.
Discuss enterprise needsNAOS-Governance
Open source under Apache-2.0, for personal and commercial use.