We build privacy-first and sovereign software infrastructure.
Based in Gibraltar. Serving businesses globally.
GhostBill — Non-custodial Monero payment processor with recurring billing. Zero transaction fees, Tor-native, self-hosted. The only XMR processor with full subscription lifecycle management.
ChimeraScope — Security intelligence and compliance assessment platform. External attack surface analysis with regulatory mapping across CRA, NIS2, ISO 27001, GDPR, DORA, and MiCA frameworks.
X-Gateway OS — Institutional liquidity gateway on the XRP Ledger. Real-time settlement, multi-asset support, and ISO 20022 readiness for SMEs and family offices.
ExpoScore — Blockchain privacy exposure auditor. On-chain footprint analysis across Bitcoin, Ethereum, Solana, and XRP Ledger with comprehensive risk scoring.
GexAura — Intelligent concierge platform delivering clinical-grade answers through advanced knowledge retrieval and precision-engineered workflows.
Small, focused, permissively licensed tools we maintain in the open. Each is tested and designed with explicit, conservative failure behavior.
Security & AI
- llm-security-gates — Python security gates for LLM systems: prompt-injection filtering, model-artifact scanning, and garak-based red-team scoring.
- patch-gate — Policy-gated preflight for applying untrusted unified diffs in CI and agent sandboxes: gate paths against escape/symlink/deny rules,
git apply --check, then apply. Fails closed. - csaf-check — Python API and CLI to validate CSAF 2.0 security advisories and VEX documents (
@secvisogram/csaf-validator-lib), with CI-friendly unavailable-validator handling. - forgeguard — Read-only security posture checks for authorized self-hosted Gitea and Forgejo: patch currency, CVE posture, container-registry and sign-in exposure.
- ai-vault-contract — Starter Obsidian vault and write contract for AI-maintained knowledge bases (Claude + Codex): dedup, schemas, atomic notes.
Self-hosting & deployment (shell tools; some operations require root — read each project's safety notes)
- cloudflare-origin-certs — Bulk-issue Cloudflare Origin CA certificates and wire them into OpenLiteSpeed; scoped, backed-up edits, dry-run by default.
- cloudflare-ufw-sync — Additively synchronize a UFW allowlist with Cloudflare's published IP ranges, with input validation and dry-run support.
- wp-hygiene-kit — Read-only hygiene checks for hosts serving multiple WordPress sites: discover live installs, ClamAV scan, ownership checks.
- deploy-guard-kit — Read-only pre-deployment checks for single-host deploys: reserved-port conflicts, PM2 working-directory drift, and content-marker health checks.
- site-canary — Off-host synthetic monitor for multiple sites: status, content-marker, cross-tenant leak detection, and latency, with transition-based alerts to Telegram or a webhook.
Web quality & SEO
- contrast-matrix — WCAG color-contrast matrix checker for design tokens: evaluate tokens over solid, alpha, and derived backgrounds; deterministic worst-case, CI-first, JSON/SARIF.
- indexnow-ping — Submit sitemap URLs via IndexNow and optionally Google Search Console, with a robots.txt guard that refuses to announce pre-launch sites.
gexiro.com · LinkedIn · Gibraltar
