The NAOS brain, code, and network emblem in platinum, suspended inside nested orange governance cubes.

Open-source SDLC governance

Governance-as-code
for AI-assisted
software development.

AI power to build.
NAOS-Governance for trust.

Bring policies, deterministic checks, and traceability into your repository. Give your team a clearer path from AI-assisted code to human-reviewed delivery.

Lives in your repository Deterministic core checks People make the decisions Apache-2.0

Between generation and delivery

Good code is only
part of the story.

AI can help write the code. Your team still needs to know which requirements it serves, which checks ran, and what needs review.

NAOS turns your development method into versioned policies, checks, and records that live alongside the work.

Meet the governance kit

Inside the kit

A practical foundation.
From intent to review.

Start with the controls your project needs.
Extend them through explicit profiles and configuration.

01

Policies your team can inspect

Define rules, AI instructions, and capability contracts as versioned repository files.

Policies and profiles
02

Checks with a defined scope

Inspect instruction structure, certain duplicate Python functions, obvious secret patterns, and test hygiene.

Explore capability contracts
03

Traceability across the work

Check declared links between requirements, tasks, source, tests, and evidence. Make gaps visible.

Traceability checks
04

Context for the next task

Use profile-available prompts, task context, and lifecycle records to keep daily work connected.

Workflow catalogue
05

Evidence ready for inspection

Collect reports, gate status, exceptions, and known gaps in a repository-local evidence pack.

Evidence pack contract
06

Human-owned decisions

Give reviewers structured inputs for remediation, waivers, and delivery decisions.

Scope and boundaries

How it works

Your workflow.
A governed foundation.

NAOS works through files, commands, and configured checks. Your team chooses the tools and retains authority.

  1. 01

    Define

    Requirements, method,
    and profile policy.

  2. 02

    Build

    Developers and AI tools
    work in the repository.

  3. 03

    Check

    Validators and gates
    surface findings.

  4. 04

    Collect

    Reports, exceptions,
    and evidence packs.

  5. 05

    Decide

    People review the evidence
    and own the next step.

Core deterministic checks require no external AI service.

Inspect the control plane

One foundation. Shared understanding.

Built for engineering.
Useful across the organisation.

Engineering & IT leadership

Make the method
part of the work.

Bring structure to AI-assisted development without losing the context of your repository.

  • Repository-local rules and task context
  • Profile-aware checks and review inputs
  • Traceability from requirements to evidence
Explore adoption

Security & GRC

See what exists.
See what is missing.

Use declared controls, structured findings, and evidence mappings to support your organisation's own control reviews.

Review scope

Audit & review

Follow the work.
Inspect the decisions.

Navigate local reports, evidence packs, declared review records, and known gaps in an inspectable handoff.

Open the audit playbook

NAOS supports governance and review. It does not certify compliance, guarantee secure code, or prove runtime safety.

Start with your repository

Evaluate the kit.
Choose your level of governance.

Quickstart is the evaluation path. Standard is the recommended starting point for a broader team workflow.

Open the installation guide

Python 3.11+ required. Managed activation currently supports Apple Silicon macOS with CPython 3.11–3.13. Linux preview is documented separately in the installation guide.

Enterprise direction

Shaping what comes next.

Broader language coverage. More AI platforms and IDEs. Governed external connectors.

Planned capabilities

Help shape the next chapter around your organisation's needs.

Discuss enterprise needs

NAOS-Governance

AI power to build.
NAOS-Governance for trust.

Open source under Apache-2.0, for personal and commercial use.

Explore NAOS on GitHub