Cipher Defense Team · July 2026
Open-source infrastructure launches carry a particular kind of exposure: the code, the defaults, and the deployment guidance all become public at once, and the security posture behind them is judged in the open. NGARi asked us to review that posture before their launch, not after.
Our engagement is structured the same way every Cipher Defense audit is: independent, fixed-scope, and focused on a deliverable NGARi's team can act on directly rather than a running relationship they have to manage.
We're reviewing the security assumptions baked into NGARi's infrastructure defaults, the governance around any AI components in the stack, and the documentation a downstream adopter would need to deploy it safely. The goal is a launch that holds up to scrutiny from the first day it's public.
Ahead of the release, we delivered a pre-release finding statement covering what we found and what needed to change before launch. Alongside it, we handed over a set of deliverables scoped specifically to move NGARi further along its path to SOC 2: control documentation, gap findings mapped to the relevant Trust Services Criteria, and a remediation sequence NGARi's team can execute without us in the room.
Open-source AI infrastructure sets patterns other teams copy. Getting the governance and security defaults right at launch has a multiplier effect: every organization that adopts the project inherits whatever posture it shipped with.