@Signetry

Signetry

Seal every agent's PR with proof — a change-control plane for coding agents. Earned authority, sealed in a signed receipt.

Signetry

Signetry

Seal every agent's PR with proof — earned authority in a signed receipt.


Signetry is a change-control plane for coding agents. Any agent (Claude Code, Codex, Cursor, Copilot, Devin — or a human) may propose a change; only Signetry decides how much authority that change earned, and seals the verdict in an Ed25519-signed receipt.

For every change it runs one deterministic pipeline:

executable contract → untrusted-text quarantine → required checks →
independent verifier → earned authority (0/1/2) → Ed25519-signed receipt

A coding agent cannot approve its own authority to make a change. The patch-writer is never the patch-approver. auto_merge is always false — a human merges.

Start here

RepoWhat it is
signetryThe overview / front door — architecture, integrations, compatibility
coreThe governance kernel (signetry-core, the signetry CLI)
actionSignetry Admission — govern every PR on the GitHub Marketplace
reviewerAdvisory PR reviewer with a deterministic merge-safety gate
evalPublic adversarial benchmark (attack-success-rate + utility)
plugins · claude-code · codex · cursor · precommitEditor / agent / hook integrations

Install

# open core: integrations Apache-2.0, engine BUSL-1.1; installed from source, not PyPI
pip install "signetry-core @ git+https://github.com/Signetry/core@v0.7.0"

Licensing — open core

Every surface you integrate with is Apache-2.0:action, plugins, claude-code, codex, cursor, precommit, reviewer, eval, the github-app, and the signetry overview. Fork them, vendor them, ship them in a product.

The governance kernel (core) is source-available under BUSL-1.1 and converts to Apache-2.0 on 2030-08-31. Read it, run it in production on your own repositories, fork it, patch it. The one prohibition is reselling it as a competing hosted governance service. Every release carries its own four-year clock.

Full table: LICENSING.md. If a public repository here has no LICENSE file, that is a bug — open an issue.

Contributing

Start with the Agent Governance Leaderboard if you want the shortest path to something visible: it takes submissions from any governance system, including ones that beat Signetry. A leaderboard only its author can win is marketing, and everyone can tell. See SUBMITTING.md.

Otherwise: eval wants adversarial cases that get past the kernel, core wants detection rules and receipt-verification hardening, and the integration repos want whatever breaks in your editor. Each repo has its own CONTRIBUTING.md.

Contributions are accepted under a Contributor License Agreement — because code legitimately moves across the open-core licence line, and the CLA is what lets it move without tracking down every past contributor. It takes nothing from you: you keep the same Apache-2.0 rights as every other user, you keep the right to use your own work elsewhere, and you are credited in CONTRIBUTORS.md, the Git history, and release notes.

Pinned Loading

  1. corecorePublic

    Agent-agnostic change-control plane for coding agents. Govern Claude Code, Codex, Cursor, or any agent behind one admission pipeline — prove every change with a signed receipt.

    Python 1 4

  2. signetrysignetryPublic

    The umbrella overview for the Signetry platform — architecture, integration catalog, compatibility matrix, and release train. Governance code lives in signetry-core.

  3. evalevalPublic

    The public adversarial evaluation suite for Signetry: measures attack success rate (ASR) and utility-under-defense for coding-agent prompt injection, skill/MCP poisoning, and memory-injection threa…

    Python

Repositories

Showing 10 of 15 repositories

Top languages

Loading…

Most used topics

Loading…

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all \u003cpre\u003e\u003ccode\u003e blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks"); } } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); } })(); (function(){ try { var __m = "github.com"; var __re = new RegExp('^' + "github\\.com" + '
Skip to content
@Signetry

Signetry

Seal every agent's PR with proof — a change-control plane for coding agents. Earned authority, sealed in a signed receipt.

Signetry

Signetry

Seal every agent's PR with proof — earned authority in a signed receipt.


Signetry is a change-control plane for coding agents. Any agent (Claude Code, Codex, Cursor, Copilot, Devin — or a human) may propose a change; only Signetry decides how much authority that change earned, and seals the verdict in an Ed25519-signed receipt.

For every change it runs one deterministic pipeline:

executable contract → untrusted-text quarantine → required checks →
independent verifier → earned authority (0/1/2) → Ed25519-signed receipt

A coding agent cannot approve its own authority to make a change. The patch-writer is never the patch-approver. auto_merge is always false — a human merges.

Start here

RepoWhat it is
signetryThe overview / front door — architecture, integrations, compatibility
coreThe governance kernel (signetry-core, the signetry CLI)
actionSignetry Admission — govern every PR on the GitHub Marketplace
reviewerAdvisory PR reviewer with a deterministic merge-safety gate
evalPublic adversarial benchmark (attack-success-rate + utility)
plugins · claude-code · codex · cursor · precommitEditor / agent / hook integrations

Install

# open core: integrations Apache-2.0, engine BUSL-1.1; installed from source, not PyPI
pip install "signetry-core @ git+https://github.com/Signetry/core@v0.7.0"

Licensing — open core

Every surface you integrate with is Apache-2.0:action, plugins, claude-code, codex, cursor, precommit, reviewer, eval, the github-app, and the signetry overview. Fork them, vendor them, ship them in a product.

The governance kernel (core) is source-available under BUSL-1.1 and converts to Apache-2.0 on 2030-08-31. Read it, run it in production on your own repositories, fork it, patch it. The one prohibition is reselling it as a competing hosted governance service. Every release carries its own four-year clock.

Full table: LICENSING.md. If a public repository here has no LICENSE file, that is a bug — open an issue.

Contributing

Start with the Agent Governance Leaderboard if you want the shortest path to something visible: it takes submissions from any governance system, including ones that beat Signetry. A leaderboard only its author can win is marketing, and everyone can tell. See SUBMITTING.md.

Otherwise: eval wants adversarial cases that get past the kernel, core wants detection rules and receipt-verification hardening, and the integration repos want whatever breaks in your editor. Each repo has its own CONTRIBUTING.md.

Contributions are accepted under a Contributor License Agreement — because code legitimately moves across the open-core licence line, and the CLA is what lets it move without tracking down every past contributor. It takes nothing from you: you keep the same Apache-2.0 rights as every other user, you keep the right to use your own work elsewhere, and you are credited in CONTRIBUTORS.md, the Git history, and release notes.

Pinned Loading

  1. corecorePublic

    Agent-agnostic change-control plane for coding agents. Govern Claude Code, Codex, Cursor, or any agent behind one admission pipeline — prove every change with a signed receipt.

    Python 1 4

  2. signetrysignetryPublic

    The umbrella overview for the Signetry platform — architecture, integration catalog, compatibility matrix, and release train. Governance code lives in signetry-core.

  3. evalevalPublic

    The public adversarial evaluation suite for Signetry: measures attack success rate (ASR) and utility-under-defense for coding-agent prompt injection, skill/MCP poisoning, and memory-injection threa…

    Python

Repositories

Showing 10 of 15 repositories

Top languages

Loading…

Most used topics

Loading…

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
@Signetry

Signetry

Seal every agent's PR with proof — a change-control plane for coding agents. Earned authority, sealed in a signed receipt.

Signetry

Signetry

Seal every agent's PR with proof — earned authority in a signed receipt.


Signetry is a change-control plane for coding agents. Any agent (Claude Code, Codex, Cursor, Copilot, Devin — or a human) may propose a change; only Signetry decides how much authority that change earned, and seals the verdict in an Ed25519-signed receipt.

For every change it runs one deterministic pipeline:

executable contract → untrusted-text quarantine → required checks →
independent verifier → earned authority (0/1/2) → Ed25519-signed receipt

A coding agent cannot approve its own authority to make a change. The patch-writer is never the patch-approver. auto_merge is always false — a human merges.

Start here

RepoWhat it is
signetryThe overview / front door — architecture, integrations, compatibility
coreThe governance kernel (signetry-core, the signetry CLI)
actionSignetry Admission — govern every PR on the GitHub Marketplace
reviewerAdvisory PR reviewer with a deterministic merge-safety gate
evalPublic adversarial benchmark (attack-success-rate + utility)
plugins · claude-code · codex · cursor · precommitEditor / agent / hook integrations

Install

# open core: integrations Apache-2.0, engine BUSL-1.1; installed from source, not PyPI
pip install "signetry-core @ git+https://github.com/Signetry/core@v0.7.0"

Licensing — open core

Every surface you integrate with is Apache-2.0:action, plugins, claude-code, codex, cursor, precommit, reviewer, eval, the github-app, and the signetry overview. Fork them, vendor them, ship them in a product.

The governance kernel (core) is source-available under BUSL-1.1 and converts to Apache-2.0 on 2030-08-31. Read it, run it in production on your own repositories, fork it, patch it. The one prohibition is reselling it as a competing hosted governance service. Every release carries its own four-year clock.

Full table: LICENSING.md. If a public repository here has no LICENSE file, that is a bug — open an issue.

Contributing

Start with the Agent Governance Leaderboard if you want the shortest path to something visible: it takes submissions from any governance system, including ones that beat Signetry. A leaderboard only its author can win is marketing, and everyone can tell. See SUBMITTING.md.

Otherwise: eval wants adversarial cases that get past the kernel, core wants detection rules and receipt-verification hardening, and the integration repos want whatever breaks in your editor. Each repo has its own CONTRIBUTING.md.

Contributions are accepted under a Contributor License Agreement — because code legitimately moves across the open-core licence line, and the CLA is what lets it move without tracking down every past contributor. It takes nothing from you: you keep the same Apache-2.0 rights as every other user, you keep the right to use your own work elsewhere, and you are credited in CONTRIBUTORS.md, the Git history, and release notes.

Pinned Loading

  1. corecorePublic

    Agent-agnostic change-control plane for coding agents. Govern Claude Code, Codex, Cursor, or any agent behind one admission pipeline — prove every change with a signed receipt.

    Python 1 4

  2. signetrysignetryPublic

    The umbrella overview for the Signetry platform — architecture, integration catalog, compatibility matrix, and release train. Governance code lives in signetry-core.

  3. evalevalPublic

    The public adversarial evaluation suite for Signetry: measures attack success rate (ASR) and utility-under-defense for coding-agent prompt injection, skill/MCP poisoning, and memory-injection threa…

    Python

Repositories

Showing 10 of 15 repositories

Top languages

Loading…

Most used topics

Loading…

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length \u003e 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
@Signetry

Signetry

Seal every agent's PR with proof — a change-control plane for coding agents. Earned authority, sealed in a signed receipt.

Signetry

Signetry

Seal every agent's PR with proof — earned authority in a signed receipt.


Signetry is a change-control plane for coding agents. Any agent (Claude Code, Codex, Cursor, Copilot, Devin — or a human) may propose a change; only Signetry decides how much authority that change earned, and seals the verdict in an Ed25519-signed receipt.

For every change it runs one deterministic pipeline:

executable contract → untrusted-text quarantine → required checks →
independent verifier → earned authority (0/1/2) → Ed25519-signed receipt

A coding agent cannot approve its own authority to make a change. The patch-writer is never the patch-approver. auto_merge is always false — a human merges.

Start here

RepoWhat it is
signetryThe overview / front door — architecture, integrations, compatibility
coreThe governance kernel (signetry-core, the signetry CLI)
actionSignetry Admission — govern every PR on the GitHub Marketplace
reviewerAdvisory PR reviewer with a deterministic merge-safety gate
evalPublic adversarial benchmark (attack-success-rate + utility)
plugins · claude-code · codex · cursor · precommitEditor / agent / hook integrations

Install

# open core: integrations Apache-2.0, engine BUSL-1.1; installed from source, not PyPI
pip install "signetry-core @ git+https://github.com/Signetry/core@v0.7.0"

Licensing — open core

Every surface you integrate with is Apache-2.0:action, plugins, claude-code, codex, cursor, precommit, reviewer, eval, the github-app, and the signetry overview. Fork them, vendor them, ship them in a product.

The governance kernel (core) is source-available under BUSL-1.1 and converts to Apache-2.0 on 2030-08-31. Read it, run it in production on your own repositories, fork it, patch it. The one prohibition is reselling it as a competing hosted governance service. Every release carries its own four-year clock.

Full table: LICENSING.md. If a public repository here has no LICENSE file, that is a bug — open an issue.

Contributing

Start with the Agent Governance Leaderboard if you want the shortest path to something visible: it takes submissions from any governance system, including ones that beat Signetry. A leaderboard only its author can win is marketing, and everyone can tell. See SUBMITTING.md.

Otherwise: eval wants adversarial cases that get past the kernel, core wants detection rules and receipt-verification hardening, and the integration repos want whatever breaks in your editor. Each repo has its own CONTRIBUTING.md.

Contributions are accepted under a Contributor License Agreement — because code legitimately moves across the open-core licence line, and the CLA is what lets it move without tracking down every past contributor. It takes nothing from you: you keep the same Apache-2.0 rights as every other user, you keep the right to use your own work elsewhere, and you are credited in CONTRIBUTORS.md, the Git history, and release notes.

Pinned Loading

  1. corecorePublic

    Agent-agnostic change-control plane for coding agents. Govern Claude Code, Codex, Cursor, or any agent behind one admission pipeline — prove every change with a signed receipt.

    Python 1 4

  2. signetrysignetryPublic

    The umbrella overview for the Signetry platform — architecture, integration catalog, compatibility matrix, and release train. Governance code lives in signetry-core.

  3. evalevalPublic

    The public adversarial evaluation suite for Signetry: measures attack success rate (ASR) and utility-under-defense for coding-agent prompt injection, skill/MCP poisoning, and memory-injection threa…

    Python

Repositories

Showing 10 of 15 repositories

Top languages

Loading…

Most used topics

Loading…

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
@Signetry

Signetry

Seal every agent's PR with proof — a change-control plane for coding agents. Earned authority, sealed in a signed receipt.

Signetry

Signetry

Seal every agent's PR with proof — earned authority in a signed receipt.


Signetry is a change-control plane for coding agents. Any agent (Claude Code, Codex, Cursor, Copilot, Devin — or a human) may propose a change; only Signetry decides how much authority that change earned, and seals the verdict in an Ed25519-signed receipt.

For every change it runs one deterministic pipeline:

executable contract → untrusted-text quarantine → required checks →
independent verifier → earned authority (0/1/2) → Ed25519-signed receipt

A coding agent cannot approve its own authority to make a change. The patch-writer is never the patch-approver. auto_merge is always false — a human merges.

Start here

RepoWhat it is
signetryThe overview / front door — architecture, integrations, compatibility
coreThe governance kernel (signetry-core, the signetry CLI)
actionSignetry Admission — govern every PR on the GitHub Marketplace
reviewerAdvisory PR reviewer with a deterministic merge-safety gate
evalPublic adversarial benchmark (attack-success-rate + utility)
plugins · claude-code · codex · cursor · precommitEditor / agent / hook integrations

Install

# open core: integrations Apache-2.0, engine BUSL-1.1; installed from source, not PyPI
pip install "signetry-core @ git+https://github.com/Signetry/core@v0.7.0"

Licensing — open core

Every surface you integrate with is Apache-2.0:action, plugins, claude-code, codex, cursor, precommit, reviewer, eval, the github-app, and the signetry overview. Fork them, vendor them, ship them in a product.

The governance kernel (core) is source-available under BUSL-1.1 and converts to Apache-2.0 on 2030-08-31. Read it, run it in production on your own repositories, fork it, patch it. The one prohibition is reselling it as a competing hosted governance service. Every release carries its own four-year clock.

Full table: LICENSING.md. If a public repository here has no LICENSE file, that is a bug — open an issue.

Contributing

Start with the Agent Governance Leaderboard if you want the shortest path to something visible: it takes submissions from any governance system, including ones that beat Signetry. A leaderboard only its author can win is marketing, and everyone can tell. See SUBMITTING.md.

Otherwise: eval wants adversarial cases that get past the kernel, core wants detection rules and receipt-verification hardening, and the integration repos want whatever breaks in your editor. Each repo has its own CONTRIBUTING.md.

Contributions are accepted under a Contributor License Agreement — because code legitimately moves across the open-core licence line, and the CLA is what lets it move without tracking down every past contributor. It takes nothing from you: you keep the same Apache-2.0 rights as every other user, you keep the right to use your own work elsewhere, and you are credited in CONTRIBUTORS.md, the Git history, and release notes.

Pinned Loading

  1. corecorePublic

    Agent-agnostic change-control plane for coding agents. Govern Claude Code, Codex, Cursor, or any agent behind one admission pipeline — prove every change with a signed receipt.

    Python 1 4

  2. signetrysignetryPublic

    The umbrella overview for the Signetry platform — architecture, integration catalog, compatibility matrix, and release train. Governance code lives in signetry-core.

  3. evalevalPublic

    The public adversarial evaluation suite for Signetry: measures attack success rate (ASR) and utility-under-defense for coding-agent prompt injection, skill/MCP poisoning, and memory-injection threa…

    Python

Repositories

Showing 10 of 15 repositories

Top languages

Loading…

Most used topics

Loading…

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
@Signetry

Signetry

Seal every agent's PR with proof — a change-control plane for coding agents. Earned authority, sealed in a signed receipt.

Signetry

Signetry

Seal every agent's PR with proof — earned authority in a signed receipt.


Signetry is a change-control plane for coding agents. Any agent (Claude Code, Codex, Cursor, Copilot, Devin — or a human) may propose a change; only Signetry decides how much authority that change earned, and seals the verdict in an Ed25519-signed receipt.

For every change it runs one deterministic pipeline:

executable contract → untrusted-text quarantine → required checks →
independent verifier → earned authority (0/1/2) → Ed25519-signed receipt

A coding agent cannot approve its own authority to make a change. The patch-writer is never the patch-approver. auto_merge is always false — a human merges.

Start here

RepoWhat it is
signetryThe overview / front door — architecture, integrations, compatibility
coreThe governance kernel (signetry-core, the signetry CLI)
actionSignetry Admission — govern every PR on the GitHub Marketplace
reviewerAdvisory PR reviewer with a deterministic merge-safety gate
evalPublic adversarial benchmark (attack-success-rate + utility)
plugins · claude-code · codex · cursor · precommitEditor / agent / hook integrations

Install

# open core: integrations Apache-2.0, engine BUSL-1.1; installed from source, not PyPI
pip install "signetry-core @ git+https://github.com/Signetry/core@v0.7.0"

Licensing — open core

Every surface you integrate with is Apache-2.0:action, plugins, claude-code, codex, cursor, precommit, reviewer, eval, the github-app, and the signetry overview. Fork them, vendor them, ship them in a product.

The governance kernel (core) is source-available under BUSL-1.1 and converts to Apache-2.0 on 2030-08-31. Read it, run it in production on your own repositories, fork it, patch it. The one prohibition is reselling it as a competing hosted governance service. Every release carries its own four-year clock.

Full table: LICENSING.md. If a public repository here has no LICENSE file, that is a bug — open an issue.

Contributing

Start with the Agent Governance Leaderboard if you want the shortest path to something visible: it takes submissions from any governance system, including ones that beat Signetry. A leaderboard only its author can win is marketing, and everyone can tell. See SUBMITTING.md.

Otherwise: eval wants adversarial cases that get past the kernel, core wants detection rules and receipt-verification hardening, and the integration repos want whatever breaks in your editor. Each repo has its own CONTRIBUTING.md.

Contributions are accepted under a Contributor License Agreement — because code legitimately moves across the open-core licence line, and the CLA is what lets it move without tracking down every past contributor. It takes nothing from you: you keep the same Apache-2.0 rights as every other user, you keep the right to use your own work elsewhere, and you are credited in CONTRIBUTORS.md, the Git history, and release notes.

Pinned Loading

  1. corecorePublic

    Agent-agnostic change-control plane for coding agents. Govern Claude Code, Codex, Cursor, or any agent behind one admission pipeline — prove every change with a signed receipt.

    Python 1 4

  2. signetrysignetryPublic

    The umbrella overview for the Signetry platform — architecture, integration catalog, compatibility matrix, and release train. Governance code lives in signetry-core.

  3. evalevalPublic

    The public adversarial evaluation suite for Signetry: measures attack success rate (ASR) and utility-under-defense for coding-agent prompt injection, skill/MCP poisoning, and memory-injection threa…

    Python

Repositories

Showing 10 of 15 repositories

Top languages

Loading…

Most used topics

Loading…

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
@Signetry

Signetry

Seal every agent's PR with proof — a change-control plane for coding agents. Earned authority, sealed in a signed receipt.

Signetry

Signetry

Seal every agent's PR with proof — earned authority in a signed receipt.


Signetry is a change-control plane for coding agents. Any agent (Claude Code, Codex, Cursor, Copilot, Devin — or a human) may propose a change; only Signetry decides how much authority that change earned, and seals the verdict in an Ed25519-signed receipt.

For every change it runs one deterministic pipeline:

executable contract → untrusted-text quarantine → required checks →
independent verifier → earned authority (0/1/2) → Ed25519-signed receipt

A coding agent cannot approve its own authority to make a change. The patch-writer is never the patch-approver. auto_merge is always false — a human merges.

Start here

RepoWhat it is
signetryThe overview / front door — architecture, integrations, compatibility
coreThe governance kernel (signetry-core, the signetry CLI)
actionSignetry Admission — govern every PR on the GitHub Marketplace
reviewerAdvisory PR reviewer with a deterministic merge-safety gate
evalPublic adversarial benchmark (attack-success-rate + utility)
plugins · claude-code · codex · cursor · precommitEditor / agent / hook integrations

Install

# open core: integrations Apache-2.0, engine BUSL-1.1; installed from source, not PyPI
pip install "signetry-core @ git+https://github.com/Signetry/core@v0.7.0"

Licensing — open core

Every surface you integrate with is Apache-2.0:action, plugins, claude-code, codex, cursor, precommit, reviewer, eval, the github-app, and the signetry overview. Fork them, vendor them, ship them in a product.

The governance kernel (core) is source-available under BUSL-1.1 and converts to Apache-2.0 on 2030-08-31. Read it, run it in production on your own repositories, fork it, patch it. The one prohibition is reselling it as a competing hosted governance service. Every release carries its own four-year clock.

Full table: LICENSING.md. If a public repository here has no LICENSE file, that is a bug — open an issue.

Contributing

Start with the Agent Governance Leaderboard if you want the shortest path to something visible: it takes submissions from any governance system, including ones that beat Signetry. A leaderboard only its author can win is marketing, and everyone can tell. See SUBMITTING.md.

Otherwise: eval wants adversarial cases that get past the kernel, core wants detection rules and receipt-verification hardening, and the integration repos want whatever breaks in your editor. Each repo has its own CONTRIBUTING.md.

Contributions are accepted under a Contributor License Agreement — because code legitimately moves across the open-core licence line, and the CLA is what lets it move without tracking down every past contributor. It takes nothing from you: you keep the same Apache-2.0 rights as every other user, you keep the right to use your own work elsewhere, and you are credited in CONTRIBUTORS.md, the Git history, and release notes.

Pinned Loading

  1. corecorePublic

    Agent-agnostic change-control plane for coding agents. Govern Claude Code, Codex, Cursor, or any agent behind one admission pipeline — prove every change with a signed receipt.

    Python 1 4

  2. signetrysignetryPublic

    The umbrella overview for the Signetry platform — architecture, integration catalog, compatibility matrix, and release train. Governance code lives in signetry-core.

  3. evalevalPublic

    The public adversarial evaluation suite for Signetry: measures attack success rate (ASR) and utility-under-defense for coding-agent prompt injection, skill/MCP poisoning, and memory-injection threa…

    Python

Repositories

Showing 10 of 15 repositories

Top languages

Loading…

Most used topics

Loading…

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
@Signetry

Signetry

Seal every agent's PR with proof — a change-control plane for coding agents. Earned authority, sealed in a signed receipt.

Signetry

Signetry

Seal every agent's PR with proof — earned authority in a signed receipt.


Signetry is a change-control plane for coding agents. Any agent (Claude Code, Codex, Cursor, Copilot, Devin — or a human) may propose a change; only Signetry decides how much authority that change earned, and seals the verdict in an Ed25519-signed receipt.

For every change it runs one deterministic pipeline:

executable contract → untrusted-text quarantine → required checks →
independent verifier → earned authority (0/1/2) → Ed25519-signed receipt

A coding agent cannot approve its own authority to make a change. The patch-writer is never the patch-approver. auto_merge is always false — a human merges.

Start here

RepoWhat it is
signetryThe overview / front door — architecture, integrations, compatibility
coreThe governance kernel (signetry-core, the signetry CLI)
actionSignetry Admission — govern every PR on the GitHub Marketplace
reviewerAdvisory PR reviewer with a deterministic merge-safety gate
evalPublic adversarial benchmark (attack-success-rate + utility)
plugins · claude-code · codex · cursor · precommitEditor / agent / hook integrations

Install

# open core: integrations Apache-2.0, engine BUSL-1.1; installed from source, not PyPI
pip install "signetry-core @ git+https://github.com/Signetry/core@v0.7.0"

Licensing — open core

Every surface you integrate with is Apache-2.0:action, plugins, claude-code, codex, cursor, precommit, reviewer, eval, the github-app, and the signetry overview. Fork them, vendor them, ship them in a product.

The governance kernel (core) is source-available under BUSL-1.1 and converts to Apache-2.0 on 2030-08-31. Read it, run it in production on your own repositories, fork it, patch it. The one prohibition is reselling it as a competing hosted governance service. Every release carries its own four-year clock.

Full table: LICENSING.md. If a public repository here has no LICENSE file, that is a bug — open an issue.

Contributing

Start with the Agent Governance Leaderboard if you want the shortest path to something visible: it takes submissions from any governance system, including ones that beat Signetry. A leaderboard only its author can win is marketing, and everyone can tell. See SUBMITTING.md.

Otherwise: eval wants adversarial cases that get past the kernel, core wants detection rules and receipt-verification hardening, and the integration repos want whatever breaks in your editor. Each repo has its own CONTRIBUTING.md.

Contributions are accepted under a Contributor License Agreement — because code legitimately moves across the open-core licence line, and the CLA is what lets it move without tracking down every past contributor. It takes nothing from you: you keep the same Apache-2.0 rights as every other user, you keep the right to use your own work elsewhere, and you are credited in CONTRIBUTORS.md, the Git history, and release notes.

Pinned Loading

  1. corecorePublic

    Agent-agnostic change-control plane for coding agents. Govern Claude Code, Codex, Cursor, or any agent behind one admission pipeline — prove every change with a signed receipt.

    Python 1 4

  2. signetrysignetryPublic

    The umbrella overview for the Signetry platform — architecture, integration catalog, compatibility matrix, and release train. Governance code lives in signetry-core.

  3. evalevalPublic

    The public adversarial evaluation suite for Signetry: measures attack success rate (ASR) and utility-under-defense for coding-agent prompt injection, skill/MCP poisoning, and memory-injection threa…

    Python

Repositories

Showing 10 of 15 repositories

Top languages

Loading…

Most used topics

Loading…