Riposte

Security tools can be
powerful and legible.

Independent · Norway

Riposte is an independent, founder-led project designing an agentic command-line environment specifically for authorized cybersecurity work. It is not publicly released.

02 / THESIS

The chat should be simple.
The authority should not be.

General coding agents made a new kind of terminal interaction feel natural: state an objective, inspect the work, steer when needed. Cybersecurity needs that fluidity, but it also needs scope, policy, credentials, network effects, evidence, and uncertainty to remain explicit. Riposte starts from those constraints instead of adding them later.

Operator authority

The operator defines the objective and the allowed surface. The model proposes; it does not enlarge its own permission.

Inspectability

Plans, approvals, effects, evidence, failures, and unknown outcomes should remain understandable after the conversation has moved on.

Specific claims

Design intent, implemented behavior, tested guarantees, and independent assessment are different states. The project will label them as such.

Responsible use

Riposte is for work you are authorized to perform. The product is being designed to carry that boundary through planning and execution.

03 / SHAPE

What it is—and what it is not.

Riposte is being designed as a terminal application you enter by running riposte. The primary surface is a persistent TUI conversation, in the same broad interaction category as modern coding CLIs, but with a security-native execution and evidence model.

is
A chat-first working environment for bounded, authorized cybersecurity tasks.
is
A durable case record connecting intent, action, result, evidence, and finding.
is not
A browser dashboard pretending to be a terminal, or an unrestricted shell with an AI label.
is not
A guarantee that a target, tool, provider, model, or operator is safe.

04 / GOVERNANCE

Decisions should leave a trail.

The project is presently founder-led. Product and security decisions are recorded in versioned specifications and decision records. The founder-selected direction is for company-owned Riposte core material, source, and original documentation to be kept closed-source and proprietary. It does not create or offer a new public core-source license or contribution route, and it does not purport to revoke rights already granted.

That direction does not invent the legal terms. Before distribution or authorized collaboration begins, the owner and qualified counsel must settle chain of title, exact proprietary distribution, end-user, notice, source-access, exception, and written collaboration terms; the current native license metadata and its package/SBOM presentation also require disposition, with NOTICE behavior reviewed separately. Public identity, funding, company structure, accountable maintainer and security ownership, website terms, and any commercial offer will be published only when real and current.

05 / CONTACT

Contact paths will open
when someone owns them.

Activation pending

No general, design-partner, press, accessibility, or security mailbox is claimed as monitored in this local preview. Those paths will be published only after routing, response expectations, privacy handling, and backup ownership are tested.