Trustas code.
in8 turns identity, policy, and proof into the platform layer for autonomous, zero trust systems, agentic developer tooling, self verifying supply chains, and event driven infrastructure that runs on its own.
Assume
nothing.
Verify
everything.
From SBOM to runtime admission, every in8 system is zero trust by default, composing attestation, identity, and policy into infrastructure that gates itself, end to end.
Platform offerings
Open source platforms in production use, from agentic developer tooling to a supply chain that verifies itself. Open any to go deeper.
A supply chain
that verifies itself
forgeseal, svidmint, and assayward gate each other’s releases end to end, keyed and keyless, on real CI, with no human in the loop.
Seal · forgeseal
Generate a CycloneDX SBOM and sign it with Sigstore, producing SLSA provenance and OpenVEX. Proof of what is running.
Mint · svidmint
Issue X.509 and JWT SVIDs to the workload via platform native attestation, STS, Access JWTs, OIDC. Proof of who is running it.
Assay · assayward
Evaluate those attestations and identities against declarative policy, returning an explainable allow, deny, or audit. The decision of whether to let it run.
Admit
The gate runs as a CLI, Wasm module, npm package, K8s admission webhook, or GitHub Action, refusing to take any signature at its word.
A maker’s mark
for the agent’s tools
The trilogy verifies containers and workloads. smithmark extends the same discipline to a new artifact class, the tools the agents themselves wield: MCP servers and skills, each given a portable, signed capability attestation that the existing gate can admit on. The trilogy verifies the mark; the mark verifies the agent’s tools.
Manifest
A signed, schema-validated declaration of what an MCP server or skill exposes and requires: tools, network egress, filesystem, exec, environment, and secrets.
Provenance
SLSA build provenance and a CycloneDX dependency SBOM, composed from forgeseal rather than reimplemented, folded into the same signed statement.
Lint
Heuristic detection of the gap between what the manifest declares and what the code appears able to reach. Advisory, host unaware, and honest about it.
Verify
Keyless Sigstore signatures checked against Rekor, subject digests confirmed, and an explainable report handed to the assayward gate to admit on.
Platform primitives
Zero Trust by Default
Identity, attestation, and policy compose into infrastructure that assumes nothing and verifies everything before admission.
Agentic Developer Tooling
MCP servers that give coding agents real world reach: voice, SMS, WhatsApp, and webhook driven actions across your tools, each shipping with a signed smithmark capability manifest a policy gate can verify.
Event Driven at the Core
One queue interface across Redis Streams, SQS/SNS, Pub/Sub, Kafka, RabbitMQ, NATS, and Azure Service Bus, DLQ and circuit breakers built in.
Serverless & Edge Native
Workload identity and OAuth that run where you deploy, Lambda, Cloudflare Workers, GitHub Actions, and Deno Deploy.
Kubernetes Grade Platform
Active active multi region IaC, policy as code, eBPF observability, and HPA/VPA autoscaling, proven on real clusters.
Standards, Not Lock In
SPIFFE, CycloneDX, SLSA, Sigstore, OpenVEX, OIDC, drop in compatible with the ecosystems you already run.
Your questions,
already answered
What exactly is in8?
in8 is a platform engineering practice. We build and open-source the infrastructure layer for autonomous, zero trust systems, supply chain verification, workload identity, agentic developer tooling, and event driven backends.
Is the work open source?
Most of it is. The platform tooling ships as open source under active development on GitHub, with production grade SDKs in Go, TypeScript, and more. The ML projects are not open source, and tickettok ships as free prebuilt binaries with the source kept private.
What is the zero trust supply chain trilogy?
Three tools that compose into a supply chain that verifies itself: forgeseal proves what is running, svidmint proves who is running it, and assayward decides whether to let it run, gating each other's releases with no human in the loop.
How does smithmark relate to the trilogy?
The trilogy stays three: forgeseal, svidmint, and assayward verify containers and workloads. smithmark opens Act II, extending the same discipline to a new artifact class, the agent's own tools. It produces a signed capability attestation for MCP servers and skills, declaring what they expose and require, and feeds it to the existing assayward gate. The trilogy verifies the mark; the mark verifies the agent's tools.
Can I adopt one project without the rest?
Yes. Each project stands alone. anyq, auth-gateway, and the MCP servers drop into existing stacks; the trilogy tools compose but don't require each other.
Who builds in8?
in8 is the platform practice of Shantanu Sharma, a senior software engineer building data platforms and agentic tooling.
How do I go deeper on a project?
Open any offering above for its dedicated case study page: a full architecture deep dive with diagrams, the design decisions and trade-offs behind it, and how it aligns with the relevant standards, alongside links to the repository, SDKs, and source.