I build black boxes for systems nobody can fully trust — right now, that means AI agents.
The exploit lives in the gap between what your AI reads and what it's allowed to do. The cover-up lives in the gap between what it did and what its logs say. I build for the second gap.
An agent does something it shouldn't. Three weeks later, someone asks "what exactly did it do?" — and the only witness is a log written by the suspect.
NoireBox fixes that: a hash-chained, Ed25519-signed journal of agent decisions and outputs, anchored by third-party RFC 3161 timestamping, exported as attestations anyone can verify. Tamper with the journal and verification explodes. On purpose.
┌─ ⬛ FLIGHT DATA RECORDER — STATUS ────────────────────
│ journal hash-chained · Ed25519-signed
│ anchoring RFC 3161 · third-party TSA
│ exports signed attestations · MIT
│ interfaces MCP server · Plugins · API · dashboard
│ pilot solo, from the Vosges mountains 🇫🇷
└────────────────────────────────────────────────────────
PyPI · Docker · Verify in CI · Docs
Tamper-evidence is not truth-at-write: NoireBox proves records weren't altered — it can't vouch that a record was accurate when it was sealed. That boundary is written down in the threat model, on purpose. Trust a product that tells you what it can't do.
- zerojour — security-advisories agent built for the DEV × Sanity Challenge: head-to-head model duels on structured content, scored eval runs. Every demo frame is a real capture.
- pluginforge — quality-first factory for e-commerce payment plugins: one spec, one conformance suite, AI-agent generation under strict gates.
- mineral-starter-kit — batteries-included starter for the Mineral Dart framework.
Python · TypeScript · Dart · a long PHP past (Laravel, Symfony — I don't flinch at legacy anymore).
slabb.dev · X · ☕ buymeacoffee.com/samlabbe
Every claim on this page ships with receipts.




