Aldeci is a clean, production-ready DevSecOps decision and verification engine that transforms raw security artifacts into actionable risk assessments, compliance evidence, and automated remediation workflows.
This is a streamlined version of Fixops containing all core functionality with ~13,500 lines of production-ready code across 29 essential modules.
Aldeci 1.0 includes:
- Input Normalization: SBOM (CycloneDX/SPDX), SARIF 2.1.0, CVE feeds, VEX, CNAPP
- Pipeline Orchestration: Modular execution with crosswalk mapping
- Configuration System: YAML-based overlay profiles with dual-mode (demo/enterprise)
- Decision Framework: 6-step decision tree (enrichment → forecast → threat model → compliance → LLM → verdict)
- Enrichment: KEV/EPSS/CVSS aggregation with exploit intelligence
- Forecasting: Bayesian inference and Markov chain probability models
- Threat Modeling: Attack path analysis and reachability scoring
- Risk Scoring: Weighted severity algorithms
- Compliance Mapping: CWE-to-control mappings for NIST 800-53, NIST SSDF, PCI DSS, ISO 27001, OWASP
- Compliance Evaluation: Framework-based control satisfaction checking
- Multi-LLM Consensus: Queries 4 providers (GPT-4o-mini, Claude-3, Gemini-2, Sentinel-Cyber)
- Hallucination Guards: Input citation validation, cross-model agreement, numeric consistency
- Deterministic Fallback: Operates without LLM API keys using mathematical models
- Policy Engine: OPA/Rego integration with trigger-based actions
- External Connectors: Jira, Confluence, Slack delivery systems
- Exploit Feeds: Auto-refresh KEV/EPSS feeds with retry logic
- Evidence Management: Cryptographic signing (RSA-SHA256), compression, atomic writes
- Artifact Storage: Secure persistence with SHA256 checksums and audit logging
- ROI Dashboard: Forecast tracking, ticket metrics, feedback analysis
- Analytics Store: Persistent storage for forecasts, exploit snapshots, policy metrics
- CLI: Command-line interface with 8+ commands
- API: FastAPI web service with 10+ endpoints
- Middleware: Performance tracking, correlation IDs, structured logging
- AI Agent Detection: Framework signature matching (LangChain, AutoGPT, etc.)
- Marketplace: Remediation pack recommendations for compliance gaps
- Advisory System: Threat profiles and recommended controls
- Python 3.10+ (tested with CPython 3.11)
- pip and virtualenv
# Clone the repository
git clone <aldeci-repo-url>
cd Aldeci
# Create virtual environment
python -m venv .venv
source .venv/bin/activate # On Windows: .venv\Scripts\activate
# Install dependencies
pip install -r requirements.txt
# Copy environment template
cp .env.example .envEdit config/fixops.overlay.yml to configure:
- Module enablement (guardrails, compliance, LLM features, etc.)
- API tokens and credentials
- Thresholds and maturity levels
- Dual-mode settings (demo vs enterprise)
# Demo mode (no external dependencies)
python -m core.cli demo --mode demo --output out/pipeline-demo.json --pretty
# Enterprise mode (with encryption and external services)
python -m core.cli demo --mode enterprise --output out/pipeline-enterprise.json --pretty
# Custom pipeline run
python -m core.cli run \
--overlay config/fixops.overlay.yml \
--design artefacts/design.csv \
--sbom artefacts/sbom.json \
--sarif artefacts/scan.sarif \
--cve artefacts/cve.json \
--output out/pipeline.json# Set API token
export FIXOPS_API_TOKEN="your-token-here"
# Launch FastAPI server
uvicorn apps.api.app:app --reload
# The API will be available at http://127.0.0.1:8000
# API docs at http://127.0.0.1:8000/docs# Upload artifacts
curl -H "X-API-Key: $FIXOPS_API_TOKEN" \
-F "file=@samples/design.csv;type=text/csv" \
http://127.0.0.1:8000/inputs/design
curl -H "X-API-Key: $FIXOPS_API_TOKEN" \
-F "file=@samples/sbom.json;type=application/json" \
http://127.0.0.1:8000/inputs/sbom
curl -H "X-API-Key: $FIXOPS_API_TOKEN" \
-F "file=@samples/scan.sarif;type=application/json" \
http://127.0.0.1:8000/inputs/sarif
curl -H "X-API-Key: $FIXOPS_API_TOKEN" \
-F "file=@samples/cve.json;type=application/json" \
http://127.0.0.1:8000/inputs/cve
# Run pipeline
curl -H "X-API-Key: $FIXOPS_API_TOKEN" \
http://127.0.0.1:8000/pipeline/run | jqAldeci follows a modular pipeline architecture:
Input Artifacts → Normalization → Crosswalk → Modules → Evidence
↓ ↓ ↓ ↓ ↓
SBOM/SARIF Standardize Link Data Analysis Signed
CVE/VEX Formats Sources Engines Bundles
- InputNormalizer (
apps/api/normalizers.py): Parses and standardizes security artifacts - PipelineOrchestrator (
apps/api/pipeline.py): Coordinates module execution - DecisionTree (
core/decision_tree.py): 6-step decision framework - EnhancedDecision (
core/enhanced_decision.py): Multi-LLM consensus engine - RiskEnrichment (
risk/enrichment.py): KEV/EPSS/CVSS aggregation - ComplianceMapping (
compliance/mapping.py): CWE-to-control mappings - PolicyEngine (
core/policy.py): Automated action dispatch - EvidenceHub (
core/evidence.py): Cryptographic signing and storage
aldeci/
├── apps/api/ # FastAPI application and pipeline
├── core/ # Core business logic (18 modules)
├── risk/ # Risk assessment engines (4 modules)
├── compliance/ # Compliance mapping (1 module)
├── marketplace/ # AI agents and remediation packs (2 modules + packs)
├── config/ # Configuration files
├── data/ # Data storage (feeds, uploads, evidence)
├── tests/ # Test suite
├── requirements.txt # Python dependencies
├── .env.example # Environment template
├── ARCHITECTURE.md # Architecture documentation
└── README.md # This file
Aldeci supports two operational modes:
- Demo Mode: In-memory mocks, no external dependencies, suitable for testing
- Enterprise Mode: Real services (OPA, MongoDB, ChromaDB), encryption, full features
Configure mode in config/fixops.overlay.yml:
mode: demo # or enterpriseEnable/disable features per deployment:
module_matrix:
guardrails:
enabled: true
compliance:
enabled: true
llm_consensus:
enabled: true
policy_automation:
enabled: true
analytics:
enabled: trueConfigure LLM providers (optional - system works without them):
llm:
providers:
- name: gpt-4o-mini
api_key_env: OPENAI_API_KEY
- name: claude-3
api_key_env: ANTHROPIC_API_KEY
- name: gemini-2
api_key_env: GOOGLE_API_KEYAldeci uses mathematical models as the primary decision-making engine:
- EPSS Scores: Exploit prediction (0-1 scale, threshold ≥0.7)
- KEV Status: CISA Known Exploited Vulnerabilities catalog
- Bayesian Inference: Likelihood ratios for severity forecasting
- Markov Chains: 30-day exploitation probability projections
LLMs enhance these decisions with explanations, MITRE ATT&CK mappings, and compliance narratives.
Three-layer protection system:
- Input Citation Validation: Ensures LLM cites actual input fields
- Cross-Model Agreement: Detects outlier responses (30% disagreement threshold)
- Numeric Consistency: Validates LLM numbers match computed values
Failed validations reduce confidence by 15% penalty.
- Cryptographic Signing: RSA-SHA256 signatures for audit trails
- Retention: 90 days (demo), 2555 days (enterprise/7 years)
- Format: Encrypted bundles (.tar.gz) with JSON manifests
- Immutability: Atomic writes with SHA256 checksums
Supported frameworks:
- NIST 800-53
- NIST SSDF
- PCI DSS
- ISO 27001
- OWASP Top 10
CWE-to-control mappings enable automatic gap identification.
# Run all tests
pytest
# Run with coverage
pytest --cov=. --cov-report=html
# Run specific test
pytest tests/test_pipeline.py# Lint code
make lint
# Format code
make format
# Type check
make typecheckAldeci exports OpenTelemetry metrics and traces to a collector at http://collector:4318.
To disable telemetry:
export FIXOPS_DISABLE_TELEMETRY=1- HTTP latency per endpoint
- Error ratios
- Inflight request counts
- Module execution times
Structured JSON logging with correlation IDs for request tracing.
API authentication via API key:
export FIXOPS_API_TOKEN="your-secure-token"Store sensitive credentials in environment variables:
OPENAI_API_KEY: OpenAI API key (optional)ANTHROPIC_API_KEY: Anthropic API key (optional)GOOGLE_API_KEY: Google API key (optional)FIXOPS_JIRA_TOKEN: Jira API token (optional)FIXOPS_CONFLUENCE_TOKEN: Confluence API token (optional)FIXOPS_SLACK_WEBHOOK: Slack webhook URL (optional)
Enable evidence encryption in config/fixops.overlay.yml:
limits:
evidence:
encrypt: trueRequires cryptography package installed.
See LICENSE file for details.
For issues, questions, or contributions, please open an issue on the repository.
Aldeci 1.0 is a streamlined version of Fixops that includes:
- ✅ All core functionality (~13,500 lines)
- ✅ Production-ready code only
- ✅ Clean directory structure
- ✅ Complete documentation
- ✅ Working installation process
- ❌ Removed WIP/experimental code
- ❌ Removed duplicate/legacy implementations
- ❌ Removed incomplete features
Aldeci focuses on the essential, working features that provide immediate value.