CyberCLI

Mission

Arm the rebels.

The big cyber vendors charge $36,000 a year and ask you to ship your alerts to their cloud. The SMBs, MSPs, and homelab operators they price out of reach deserve the same agentic, sovereign, auditable security operations capability — without the invoice and without the data egress.

Long form ↗ Read the Manifesto + Founder's Note

Three commitments

Sovereign by default
Your alerts never leave your environment. Local AI runs on your hardware. BYOK frontier models stay routed through your keys. The license verifier is fully offline. We never see what your network sees.
OSS-extending, not OSS-locked
We build ON the OSS substrate the security community already trusts — Wazuh, Suricata, ClamAV, Falco, Keycloak. We don't ask you to throw it out and we don't try to lock you in. If you walk away, your OSS keeps running.
Auditable autonomy
Every AI decision is hash-chained, signed, and replayable. The Trust Ladder caps the AI's authority per action class — we visualize the leash. "Human-in-the-loop" is not a marketing word; it's a per-template ceiling you can audit.

Founder

Chris — CyberCLI founder

Chris. The operator who built this because nobody else would.

Ten years running BladeOne, an independent cybersecurity firm, after more than a decade in U.S. government cyber operations and a tour with the U.S. Secret Service. The pattern across every one of those years: small teams who needed enterprise security capability without the enterprise invoice, and were left choosing between an MDR retainer that owns their data and a half-working OSS stack that nobody has time to maintain.

CyberCLI is the product I kept wishing existed for those teams: agentic security operations on your hardware, your data, your audit chain. The open-source community already builds the world-class detection substrate. CyberCLI orchestrates it, layers an agentic AI on top with a visible Trust Ladder, and ships it as a single binary. Same kind of work my team has been doing for a decade, made buyable.

I've been working with AI since college at Rice University's A.L.I.C.E. Foundation, well before the LLM era. The shift Karpathy and Altman keep pointing at, one operator plus modern AI doing what used to take a hundred-person company, is real. CyberCLI is what that looks like in security.

About Me (full version) coming soon. Chris-voice draft pending.

The build crew

One operator. A council of AI.

Altman calls it the billion-dollar one-person company. Karpathy calls it Software 3.0. If CyberCLI ever joins those companies, this is the council that did the work — five AIs from five labs, each picked for what it actually ships, not for what its press release promises. Below: who's on the bench, and what each one's load-bearing on this build.

Anthropic
Anthropic
anthropic.com

Claude · Opus 4.8

Builder of record

Writes the code. Runs the commits. Ships the deploys. Holds session state across hours-long builds and drives the engine end-to-end. Pauses before destructive actions and asks. Long-context, multi-step, no shortcuts is the lane.

OpenAI
OpenAI
openai.com

Codex · GPT-5.5

Second reviewer · research drafter

Pulls live web sources for architecture decisions. Drafts proposals Claude then implements. Spot-checks every claim with a different training corpus — the blind spots one model alone would miss are the ones Codex catches.

Google Gemini
Google
gemini.google.com

Gemini · 4.0

Third reviewer

Independent cross-check on architecture forks, pricing logic, edge cases. When two reviewers agree, three makes a quorum. The standing rule across the council: if any one of us dissents, look harder before shipping.

xAI
xAI
x.ai

Grok · 4.3

Live intel · strategic dissent

Real-time X search. Pulls today's market sentiment, today's competitor moves, today's pricing noise — the other reviewers reason from a training cutoff; Grok reads what's happening this week. Often the contrarian voice when the others quietly converge.

Cursor
Cursor
cursor.com

Composer · 2.5

Code-level pair · fourth reviewer

Trained specifically for code review and edit precision. Catches the file-level bugs and subtle correctness gaps the others miss. Fast enough to fold into every commit, not just every milestone — caught the IPv6-mapped SSRF in the notification engine on first invocation.

IN
In-house · trainer01
CyberCLI LLC

The Stable

Production runtime · trained here

Qwen 7B/8B, Llama 3.3, DeepSeek R1 — QLoRA-tuned on abliterated open-weight bases on a 2× RTX Pro 6000 trainer. The council above builds the product; the Stable IS the product. Tested, evaluated, MANIFEST-pinned — ground truth before any model ships to a customer.

Council and Stable are different things. The council is the build crew — the AIs that designed this with chris, argued with each other, caught each other's mistakes, and wrote the code that ships. The Stable is the production runtime — the Cyber Guild roles you'll find inside CyberCLI when you install it. Both are first-class. Neither is hidden behind a marketing word.

No AI gets attribution here without the work to back it. Every cited model has shipped a load-bearing change in production — code, design, pricing strategy, or training pipelines. Receipts available on request.

Rebellions are built on hope.