Skip to content
@Polycentric-Labs

Polycentric Labs, LLC

Polycentric Labs

Dimidium scientiae — “the half of knowledge is to know where to find knowledge.”


We build software for problems where being wrong is expensive — compliance, regulated AI, and the research that underpins both. Everything here is open source, and everything is built to be verified, not trusted: signed artifacts, traceable provenance, and a refusal to assert anything we can't trace to a primary source.

That principle is the through-line. Our platforms enforce it for the people who use them; our tooling enforces it on ourselves.

What we build

Compliance & governance infrastructure

Evidentiacompliance as code, signed and provable. An open-source, OSCAL-native GRC engine: gap analysis, AI risk statements, and a broad library of bundled frameworks (NIST 800-53, FedRAMP, CMMC, SOC 2, HIPAA, GDPR, and more). Every piece of evidence is cryptographically signed (Sigstore + GPG) and shipped with CycloneDX SBOMs, SLSA build provenance, and PEP 740 attestations — so an auditor can verify the chain instead of taking your word for it. Runs fully offline for sovereign-cloud and air-gapped deployments. Python-first, CLI-first, CI-native.

RegRailsdeterministic guardrails that decide before the model speaks. Policy-as-code for FERPA and Title IV. RegRails makes a risk-tiered, citation-faithful decision before any LLM responds, so the guarantee never depends on the model behaving. Ships with an MCP server, OSCAL/SARIF exports, a GitHub Action, and a live web demo.

Research & engineering discipline

The instruments we use to keep our own work honest — open-sourced because the discipline travels.

Labcoata hard-skeptic, multi-model research engine. Fans a question across a live fleet of models, then kills every finding it can't trace to a primary source, validates three times, and ranks what survives. A Claude Code skill and a standalone Python runner. MIT.

sonar-routerroute to the right research tool, not the loudest one. A decision-matrix skill and classifier that picks the right web-research method for a query and routes away from deep-research models when they would hallucinate. MIT.

pre-release-reviewa methodical, user-in-the-loop pre-tag review. A portable release-gate skill aligned to SLSA L3, OpenSSF Best Practices, and the OSPS Baseline — the checklist that stands between “it builds” and “it ships.”

How we work

  • Open by default. Apache-2.0 and MIT. Read the code, fork it, build on it.
  • Verifiable, not trust-me. Signed evidence, build provenance, primary-source discipline. If we claim it, you can check it.
  • CLI-first, library-first, CI-native. Tools that drop into a terminal, import as a library, and run on every pull request.
  • Built for hard environments. Regulated industries, offline and air-gapped deployments, and reviewers who read the source.

Get involved

We build in the open, and we're looking for developers who care about correctness. Star a project, open an issue, or send a pull request — each repo has its own contributing guide and good first issues. If a framework, integration, or guardrail you need is missing, that's a great place to start.

✉️ contact@polycentriclabs.com


This organization's projects are developed alongside AI platforms. Models used: Claude Opus 4.6, Claude Opus 4.7, Sonar Deep Research.

Popular repositories Loading

  1. evidentia evidentia Public

    Open-source Python GRC tool: gap analysis, AI risk statements, OSCAL-first compliance automation. Enterprise-grade evidence integrity (Sigstore + GPG), CycloneDX SBOM, PyPI Trusted Publisher OIDC +…

    Python 3 1

  2. regrails regrails Public

    Policy-as-code for FERPA + Title IV: a deterministic guardrail that decides before any LLM speaks. Risk-tiered, citation-faithful, with an MCP server, OSCAL/SARIF exports, a GitHub Action, and a li…

    Python 1

  3. pre-release-review pre-release-review Public

    A comprehensive, methodical, user-in-the-loop pre-tag review skill for Claude Code. Project-shape portable; SLSA L3 / OpenSSF Best Practices / OSPS Baseline aligned.

    Python 1

  4. sonar-router sonar-router Public

    Pick the right Perplexity / web-research tool for a query — a decision-matrix skill + Python classifier that routes away from Sonar Deep Research when it would hallucinate. MIT.

    Python 1 1

  5. labcoat labcoat Public

    Polycentric Labcoat — a rigorous multi-model, hard-skeptic research engine: fan a question across a live fleet, kill every finding that can't be traced to a primary source, validate 3x, rank. Claud…

    Python 1

  6. voidseal voidseal Public

    Risk-tiered, host-verified-sealed Hyper-V sandbox VM provisioner (PowerShell). Run untrusted code or agents in tiered isolation behind a fail-closed seal gate.

    PowerShell 1

Repositories

Showing 7 of 7 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…