Trust infrastructure for the agent internet.
The internet is filling up with machine actors. OSL builds the observatory and evidence layer so those interactions can be inspected, attributed, and defended.
Glimmer is the first product: a commercial threat-intelligence publisher for MCP and x402. We run the Decoys. Customers receive signed Feeds and lookup APIs, not raw telemetry. Glimmer is pre-launch — architecture confirmed, public access gated on legal and hosting-provider clearance.
This org also hosts open-source product-security tools. They are not Glimmer.
- deterministic-deps — GitHub Action that flags non-deterministic dependency declarations across 9 ecosystems.
- AuthMap — authorization coverage mapping across routes, handlers, and data mutations.
- SessionScope — session, cookie, JWT, and token lifecycle auditor.
- PkgWarden — package-manager hardening advisor for dependency-ingestion controls.
- rulepath — deterministic analysis of business-logic flaws and invariant enforcement.
Owned, trimmed osl- forks of external dependencies live in this org. Policy, runbook, and the current index:
If you found this org through a CVE advisory, the fork's CHANGELOG-OZARK.md is the per-dep history.