Open source · stage 1

Devseis Endpoint Auditor

A read-only audit of Windows, Linux, macOS, iPhone and Android devices against a security baseline, GDPR technical controls, EU AI Act controls and organisational controls, written up by a small AI auditor model that runs on the device. Check your phone now.

Read-only collectorsPowerShell, Linux shell and macOS shell scripts. They read settings and never change the system.
One evidence formatSame JSON for every OS, joined to a catalog with ISO 27001, GDPR and AI Act references.
Synthetic dataRealistic evidence with the same rules, so the auditor model can be built before real data exists.
Runs locallyEvidence stays on the device. Nothing is sent anywhere.
Offline vulnerability matchingInstalled software is matched against a signed OSV/NVD/CISA KEV bundle by exact version rules.
Phones tooA browser check for iPhone and Android: what the browser can detect plus guided questions, each result labelled detected or self-reported.

Sample audit (synthetic)

Loading…
CheckStatusFoundReferences

Roadmap

  1. Collectors, evidence format, catalog (74 checks), synthetic data — done
  2. Control library and fix guidance in Devseis's own wording — done; expert review welcome
  3. Training data v0.3: 39,500 grounded examples for Windows, Linux, macOS, iPhone and Android — done
  4. Offline vulnerability matching (OSV, NVD, CISA KEV, EPSS), signed bundle — done
  5. Desktop app (Electron + WebLLM) and phone check (this Space) — done, with the base model
  6. Fine-tune Qwen2.5-0.5B-Instruct on this Mac (CPU, LoRA) — in progress
  7. Evaluate on held-out data, publish the scores and the model
  8. Installers per OS; tests on real Windows and Linux machines

Not a certification. ISO 27001 certification needs an accredited auditor, and much of GDPR and AI Act compliance is organisational. The tool collects evidence and flags gaps. See the README for how to run the collectors.