AI that works.Security that comes with it.
An open-source software company with remote consulting behind it. We build AI and security products in the open — and help your company put them in production, without vendor lock-in.
Open-source software and secure AI consulting for SMBs
SMBs don't need fancy AI. They need AI that works, doesn't leak data and doesn't burn the budget.
That's why we build open-source software — a coding agent, a multi-agent mission control and an AppSec maturity tool, all in the open — backed by 20+ years in technology and 10+ in applied cybersecurity. Compliance turned into code, not slides.
Consulting is remote and objective — diagnosis, rollout and hand-off, with our products doing the heavy lifting.
Remote consulting on AI, AppSec and compliance
Consulting
Technical and strategic diagnosis on AI, AppSec and DevSecOps. From architecture to roadmap.
→ Learn moreMulti-LLM Gateway
One API, many models. Routing by cost, latency and data policy — no vendor lock-in.
→ Learn moreCompliance
Controls as code and automated evidence for LGPD, GDPR, ISO 27001 and the EU AI Act.
→ Learn moreDevelopment
Remote delivery of products with embedded AI, secure infra and agents accelerating the cycle.
→ Learn moreThe products behind the consulting
Okami Agent
Sovereign AI coding agent: capability parity across LLMs, self-improvement (skills, persona, memory) and mandatory design-system adherence. In the terminal, on Telegram, wherever you want.
→ See details · Website ↗ · Source code ↗Okami Monitor
Mission control for multi-agent environments: usage and cost per period, sessions, Kanban, logs, API keys and external runtime connections — in one cockpit.
→ See details · Website ↗ · Source code ↗OkamiCode
Local-first desktop cockpit for AI coding CLIs: folder-bound projects, native sessions per provider, chat, email, Kanban, usage/cost analytics and durable memory — without paying a second API bill.
→ See details · Website ↗ · Source code ↗Okami Maturity
OWASP SAMM v2 maturity assessment: 5 functions, 15 practices, 90 questions — with scorecard, radar, prioritized roadmap and a board-ready PDF report.
→ See details · Website ↗ · Source code ↗Okami Tally
An iPhone panel for your AI subscription quotas — Claude, Codex, Grok, Cursor, Minimax, MiMo and any service with a JSON endpoint. In the app, in widgets, on the Lock Screen and in the Dynamic Island. No backend, no telemetry.
→ See details · Website ↗Okami Deal
The Okami suite CRM, under construction — pipeline, contacts and follow-up with AI built in. Soon to be open like the others.
Why choose OkamiOps for secure AI
Multi-LLM gateway, no vendor lock-in
Your app speaks one API. We swap the model underneath based on cost, latency and data policy — without rebuilding pipelines.
Security as prerequisite, not checklist
Every integration starts with threat model, tenant isolation and auditable logs. Compliance is a result, not extra effort.
Bank-grade depth, SMB pricing
We bring SMBs the same technical standard we apply to large banks and fintechs — without the corporate overhead.
Open-source when it fits
Self-hosted, commercial, hybrid — we combine whatever solves the problem best, not what pays the highest commission.
AppSec consulting led by senior engineering

Twenty years building software, ten of them doing it with security embedded. Specialist in AppSec and DevSecOps, with security tooling deployments in 1,000+ employee companies, large banks and payment processors.
Career spanning Brazil and Germany — through OpenMind Tech, IGEL, Greenbone (maintainer of OpenVAS, one of the world's leading infrastructure compliance scanners), Nova8 CyberSecurity and BRScan Segurança.
The technical depth usually reserved for the big players — now delivered in a consumable format for everyone building.
Technical compliance for LGPD, GDPR and ISO 27001
Corporate AI, AppSec and observability stack
Models
- Anthropic Claude
- OpenAI GPT
- Google Gemini
- Mistral · self-host
- Llama · self-host
- Cohere · embeddings
Infrastructure
- AWS / GCP / Azure
- Kubernetes · EKS/GKE
- Terraform + Atlantis
- Cloudflare · edge
- OpenTelemetry
- Vault · KMS
AppSec & DevSecOps
- OpenVAS · scanner
- Trivy + Grype
- Semgrep · SAST
- OWASP ZAP · DAST
- Sigstore · supply chain
- Falco · runtime
Engineering
- Python · Go · TypeScript
- FastAPI · Fastify
- Postgres · pgvector
- Redis · queues
- Temporal · workflows
- GitHub Actions
Remote consulting plans and open-source products
Diagnosis
A closed scope to map risk, architecture and feasibility before investing in execution.
- Remote technical diagnosis
- AppSec maturity with Okami Maturity
- Initial threat model
- Roadmap 90 / 180 / 360 days
- Executive presentation
Project
Delivery with a beginning, an end and a hand-off: multi-LLM gateway, compliance or an AI product.
- Senior engineering + AI agents
- Multi-LLM gateway in production
- Compliance controls as code
- AppSec in the pipeline from commit one
- Documented hand-off — code is yours
Ongoing retainer
Monthly remote evolution: products operated, policies tuned and maturity rising every cycle.
- Async remote follow-up
- Okami product deploys and updates
- Continuous gateway policy tuning
- Compliance evidence maintained
- Monthly executive report
Insights on AI, AppSec, OWASP SAMM and AI Act
Policy-based routing: how to cut 60% of LLM cost without losing quality
A practical framework to decide which model serves which request, with automatic fallback.
Read article →Threat modeling AI integrations: 7 shortcuts learned from banks
What changes when the input of your system is a user prompt and the output becomes action.
Read article →AI Act, LGPD and SOC 2 in one pipeline — without three separate projects
How to instrument evidence once and satisfy multiple regulatory frameworks.
Read article →