OBSERVE
Find the signal.
Start with a scoped question, a reliable source, and a clear view of what is not being observed.
OUTPUT / scoped observationZeroDev ships source-linked security tools, public research, and controlled software delivery. Inspect the proof here; get the software from the Store.
PUBLIC / PRIVATE Evidence is open; licensed software is delivered through the ZeroDev store .
DEFCON
5
nominal posture
No elevated public posture detected in the demo adapter.
Synthetic public demo adapter · checked not checked
GitHub index + RSS edge monitor
Derived readiness readouts are never official alerts
DEFCON + recon remain synthetic until verified
Warnings stay visible when a source cannot be checked
/ THE STANDARD
Make the work legible. Make the boundary explicit.
The public surface shows enough to build trust without pretending that a demo is production, a stale snapshot is live, or a private target belongs in a portfolio.
Every public claim has a source, a scope, or an honest unavailable state.
/ 00 — LIVE SURFACES
These are the public surfaces that prove the system is running: real repository metadata, a real edge monitor, and a clear private handoff.
/ 01 — METHOD
The same standard runs through research, products, public demos, and private delivery: observe carefully, build usefully, verify the boundary, then gate access.
OBSERVE
Start with a scoped question, a reliable source, and a clear view of what is not being observed.
OUTPUT / scoped observationBUILD
Turn the signal into a tool, workflow, or interface that a real operator can understand and use.
OUTPUT / working systemVERIFY
Separate observation from inference, synthetic data from live data, and public proof from private detail.
OUTPUT / auditable evidenceGATE
Use explicit entitlements, least privilege, expiry, and revocation when the work should not be public.
OUTPUT / controlled delivery/ 02 — LIVE EVIDENCE
The software index and RSS monitor are public source surfaces. The status rail distinguishes source-linked, stale, demo, and unavailable states; DEFCON and recon stay marked as demo until a verified adapter is connected.
A normalized public posture from the adapter. It is not a government alert or an incident declaration.
The chart is a visual sample until a verified public series is connected. Treat it as demonstration, not measurement.
The map and scan use synthetic scope only: no live targets, credentials, or exploit actions.
LIVE is checked source data; STALE is the last known snapshot; OFFLINE has no verified source; DEMO is synthetic.
PUBLIC STORE METADATA
Read-only catalog metadata is shared from the Store. Provider links and availability remain explicit; no preview is presented as ready to ship.
No public catalog records returned yet.
Catalog freshness: demo · checked not checked · provider mappings are never inferred.
| Signal | Surface | Observation | Severity |
|---|---|---|---|
| PROBE 12:48:09 | edge-eu-03 | rate-limit held · 184 req/s | low |
| AUTH 12:46:31 | vault-api | token replay rejected | medium |
| SCAN 12:43:17 | sandbox-net | 7 surfaces mapped · no escalation | low |
| SIGNAL 12:39:44 | north-atlantic | baseline variance · monitoring | high |
/ 03 — BUILD MAP
Cards are sourced from approved public GitHub repositories when available. Private builds explain the boundary without leaking the source.
Showing 10 systems / 10 indexed
08 / MAP TO MARKET
A research-led Ireland map studio that turns schematic layers, design maths, and original symbolic cues into garment concepts with a print-to-ship handoff.
Interactive map layers, rounded place anchors, garment previews, design-spec export, research sources, and provider handoffs.
The prototype is not a legal map. Replace the hand-simplified outline with licensed source geometry and verify commercial rights before sale.
01 / FREE SOFTWARE
A manifest-driven, privacy-conscious RSS bundle with importable profiles, an auditable source list, and a read-only live monitor for representative publisher feeds.
672 configured feeds: 556 finance and 116 cybersecurity sources, with Master, iPhone Air and iPhone Lite OPML profiles plus a Cloudflare live monitor.
No credentials, private targets, customer data or paid feed content are exposed. RSS publishers retain their own content and feed terms.
02 / PUBLIC AUDIT
A focused hardening project that turns password posture into an auditable, reviewable security surface.
Repository narrative, audit notes, and reproducible defensive techniques.
No customer environments, credentials, or live target data.
03 / GLOBAL POSTURE
A readiness and telemetry surface for turning public indicators into a calm, inspectable operator view.
Product intent, safe demo surface, and the boundary around public telemetry.
Implementation, licensed artifacts, and target-specific data remain gated.
04 / NETWORK DEFENCE
A network visibility component that provides a public proof point for defensive systems engineering.
Public implementation, setup notes, and defensive engineering context.
Deployment environments and operational telemetry are intentionally excluded.
05 / WEB HARDENING
Automated HSTS configuration tooling for Apache Tomcat and IIS with audit, auto-detection, and patch modes.
OWASP-aligned configuration checks, audit output, and safe patch workflows for supported servers.
No customer infrastructure, credentials, or production configuration is bundled with the repository.
06 / DELIVERY SYSTEM
A purchase-to-entitlement flow for shipping licensed software through verified, revocable access.
Delivery model, trust boundaries, and safe entitlement concepts.
Payment events, customer records, and distribution artifacts stay server-side.
07 / SECURITY DATA
A practical data pipeline for turning vulnerability intelligence into a portable, analyst-friendly workbook.
Converter source, data-shaping decisions, and analyst-facing examples.
No customer vulnerability data or private intelligence is bundled with the project.
08 / SECURITY DATA
A compliance-audit pipeline that turns Tenable audit archives into formatted XLSX and HTML review surfaces.
Audit-file parsing, structured exports, and a master HTML summary for analyst review.
Customer audit archives and private compliance findings stay outside the public repository.
09 / ATTACK SURFACE
A scoped recon workbench that maps assets, observations, and confidence without exposing private targets.
Safe interaction model and the principles behind scoped observations.
Private assets, target identifiers, and operational findings stay behind access control.
/ 04 — PRIVATE DELIVERY
Purchase or request access through a controlled path: verify the entitlement server-side, record the right scope and expiry, then deliver through the least-privilege channel.
Explore Print + repo delivery Request private access