Okami publishes practical tools and delivers on-premise systems for teams building with AI. The work sits where product ideas start meeting operational reality: model choice, security boundaries, delivery gates, cost, observability and ownership.
Some projects are open source; others are public work with their own licensing terms. Run what fits your environment, inspect the code and adapt it to the way your team actually works.
Useful AI. Security built into the architecture. Provider freedom. Evidence before scale.
|
Local-first tooling, model-aware workflows, usage visibility and explicit operating boundaries. |
AppSec maturity, CI/CD security checks, scan workbenches and artifacts people can inspect later. |
- Okami Agent — A sovereign AI coding agent with provider-aware execution, persistent capabilities and terminal or Telegram operation. Source
- OkamiCode — A local-first desktop cockpit for native AI coding CLIs, communication, planning, usage intelligence and memory. Source
- Okami Sentinel — A local-first workbench for running, comparing, reporting and gating OpenAI Codex Security scans. Source
- Okami Maturity — An OWASP SAMM v2 assessment workspace with scorecard, radar, prioritized roadmap and board-ready PDF report. Source
- SecOps Baseline — A practical CI/CD baseline for SCA, secrets, containers, IaC and auditable evidence. Source
- Okami Monitor — Mission control for multi-agent AI environments: usage, cost, sessions, logs and external runtimes in one cockpit. Source
- OkTally — A macOS menu-bar tool for tracking AI coding subscription quotas before they become a surprise. Source
Each repository has its own license, deployment notes and maturity level. Browse the full public portfolio.
A useful proof of concept uses real inputs and produces numbers: quality, cost, latency, failure cases and a decision to proceed, change shape or stop. Production work adds boundaries, monitoring, rollback and clear ownership.
What “provider freedom” means here
We design for explicit model routing, fallback behavior and evaluation across commercial APIs, open-source models and self-hosted deployments. The point is not to promise zero lock-in; it is to keep the decision visible and reversible.
okami:
architecture: "multi-LLM, provider-aware"
delivery: "risk map → controlled PoC → production gates"
security: "AppSec + DevSecOps"
evidence: "logs, tests, evals, runbooks, rollback"
regions: ["São Paulo", "Munich"]
LGPD
GDPR
ISO 27001
OWASP SAMM
OWASP ASVS
NIST
PCI-DSS
- Useful technology beats hype. If it does not survive real inputs, it is decoration.
- Security belongs in the architecture. It is not a panic meeting two days before launch.
- Compliance should produce evidence. A control that nobody can inspect does not help much.
- Cost must be visible before scale. AI without cost visibility turns into a billing surprise.
- The system must remain understandable. Teams should know how it works after the first launch.


