Project Status

What exists, what is proven, and what still needs validation

SMERC is ready for technical review and shadow-mode pilot discussion as a recoverability-aware runtime permission layer for AI agents, MCP tool calls, GitHub Actions, and high-impact automation. It should not be represented as a production-certified security platform.

Public review Submission kit CISO review Live demo

Current Artifact

Working pilot-grade infrastructure

The public repository contains a recoverability engine, Runtime Evidence Trust Gate, REST API, audit/replay path, pilot review metrics, GitHub PR Guardian, MCP tool governance, GitHub Actions pilot materials, action-bound permits, signed control evidence, Decision Lifecycle Ledger intelligence, Self-Governance Sandbox, scoped workload identity, GitHub OIDC support, configurable domain profiles, SDKs, Docker support, and automated tests.