Skip to content

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

Aldeci 1.0 - DevSecOps Decision Engine

Aldeci is a clean, production-ready DevSecOps decision and verification engine that transforms raw security artifacts into actionable risk assessments, compliance evidence, and automated remediation workflows.

This is a streamlined version of Fixops containing all core functionality with ~13,500 lines of production-ready code across 29 essential modules.

What's Included

Aldeci 1.0 includes:

Core Pipeline

  • Input Normalization: SBOM (CycloneDX/SPDX), SARIF 2.1.0, CVE feeds, VEX, CNAPP
  • Pipeline Orchestration: Modular execution with crosswalk mapping
  • Configuration System: YAML-based overlay profiles with dual-mode (demo/enterprise)
  • Decision Framework: 6-step decision tree (enrichment → forecast → threat model → compliance → LLM → verdict)

Risk Assessment

  • Enrichment: KEV/EPSS/CVSS aggregation with exploit intelligence
  • Forecasting: Bayesian inference and Markov chain probability models
  • Threat Modeling: Attack path analysis and reachability scoring
  • Risk Scoring: Weighted severity algorithms

Compliance

  • Compliance Mapping: CWE-to-control mappings for NIST 800-53, NIST SSDF, PCI DSS, ISO 27001, OWASP
  • Compliance Evaluation: Framework-based control satisfaction checking

LLM Features

  • Multi-LLM Consensus: Queries 4 providers (GPT-4o-mini, Claude-3, Gemini-2, Sentinel-Cyber)
  • Hallucination Guards: Input citation validation, cross-model agreement, numeric consistency
  • Deterministic Fallback: Operates without LLM API keys using mathematical models

Automation

  • Policy Engine: OPA/Rego integration with trigger-based actions
  • External Connectors: Jira, Confluence, Slack delivery systems
  • Exploit Feeds: Auto-refresh KEV/EPSS feeds with retry logic

Evidence & Audit

  • Evidence Management: Cryptographic signing (RSA-SHA256), compression, atomic writes
  • Artifact Storage: Secure persistence with SHA256 checksums and audit logging

Analytics

  • ROI Dashboard: Forecast tracking, ticket metrics, feedback analysis
  • Analytics Store: Persistent storage for forecasts, exploit snapshots, policy metrics

Interfaces

  • CLI: Command-line interface with 8+ commands
  • API: FastAPI web service with 10+ endpoints
  • Middleware: Performance tracking, correlation IDs, structured logging

AI Agents & Marketplace

  • AI Agent Detection: Framework signature matching (LangChain, AutoGPT, etc.)
  • Marketplace: Remediation pack recommendations for compliance gaps
  • Advisory System: Threat profiles and recommended controls

Quick Start

Prerequisites

  • Python 3.10+ (tested with CPython 3.11)
  • pip and virtualenv

Installation

# Clone the repository
git clone <aldeci-repo-url>
cd Aldeci

# Create virtual environment
python -m venv .venv
source .venv/bin/activate  # On Windows: .venv\Scripts\activate

# Install dependencies
pip install -r requirements.txt

# Copy environment template
cp .env.example .env

Configuration

Edit config/fixops.overlay.yml to configure:

  • Module enablement (guardrails, compliance, LLM features, etc.)
  • API tokens and credentials
  • Thresholds and maturity levels
  • Dual-mode settings (demo vs enterprise)

Running the CLI

# Demo mode (no external dependencies)
python -m core.cli demo --mode demo --output out/pipeline-demo.json --pretty

# Enterprise mode (with encryption and external services)
python -m core.cli demo --mode enterprise --output out/pipeline-enterprise.json --pretty

# Custom pipeline run
python -m core.cli run \
  --overlay config/fixops.overlay.yml \
  --design artefacts/design.csv \
  --sbom artefacts/sbom.json \
  --sarif artefacts/scan.sarif \
  --cve artefacts/cve.json \
  --output out/pipeline.json

Running the API

# Set API token
export FIXOPS_API_TOKEN="your-token-here"

# Launch FastAPI server
uvicorn apps.api.app:app --reload

# The API will be available at http://127.0.0.1:8000
# API docs at http://127.0.0.1:8000/docs

API Usage Examples

# Upload artifacts
curl -H "X-API-Key: $FIXOPS_API_TOKEN" \
  -F "file=@samples/design.csv;type=text/csv" \
  http://127.0.0.1:8000/inputs/design

curl -H "X-API-Key: $FIXOPS_API_TOKEN" \
  -F "file=@samples/sbom.json;type=application/json" \
  http://127.0.0.1:8000/inputs/sbom

curl -H "X-API-Key: $FIXOPS_API_TOKEN" \
  -F "file=@samples/scan.sarif;type=application/json" \
  http://127.0.0.1:8000/inputs/sarif

curl -H "X-API-Key: $FIXOPS_API_TOKEN" \
  -F "file=@samples/cve.json;type=application/json" \
  http://127.0.0.1:8000/inputs/cve

# Run pipeline
curl -H "X-API-Key: $FIXOPS_API_TOKEN" \
  http://127.0.0.1:8000/pipeline/run | jq

Architecture

Aldeci follows a modular pipeline architecture:

Input Artifacts → Normalization → Crosswalk → Modules → Evidence
     ↓                ↓              ↓           ↓          ↓
  SBOM/SARIF    Standardize    Link Data    Analysis   Signed
  CVE/VEX       Formats        Sources      Engines    Bundles

Key Components

  • InputNormalizer (apps/api/normalizers.py): Parses and standardizes security artifacts
  • PipelineOrchestrator (apps/api/pipeline.py): Coordinates module execution
  • DecisionTree (core/decision_tree.py): 6-step decision framework
  • EnhancedDecision (core/enhanced_decision.py): Multi-LLM consensus engine
  • RiskEnrichment (risk/enrichment.py): KEV/EPSS/CVSS aggregation
  • ComplianceMapping (compliance/mapping.py): CWE-to-control mappings
  • PolicyEngine (core/policy.py): Automated action dispatch
  • EvidenceHub (core/evidence.py): Cryptographic signing and storage

Directory Structure

aldeci/
├── apps/api/          # FastAPI application and pipeline
├── core/              # Core business logic (18 modules)
├── risk/              # Risk assessment engines (4 modules)
├── compliance/        # Compliance mapping (1 module)
├── marketplace/       # AI agents and remediation packs (2 modules + packs)
├── config/            # Configuration files
├── data/              # Data storage (feeds, uploads, evidence)
├── tests/             # Test suite
├── requirements.txt   # Python dependencies
├── .env.example       # Environment template
├── ARCHITECTURE.md    # Architecture documentation
└── README.md          # This file

Configuration

Dual-Mode Operation

Aldeci supports two operational modes:

  1. Demo Mode: In-memory mocks, no external dependencies, suitable for testing
  2. Enterprise Mode: Real services (OPA, MongoDB, ChromaDB), encryption, full features

Configure mode in config/fixops.overlay.yml:

mode: demo  # or enterprise

Module Control

Enable/disable features per deployment:

module_matrix:
  guardrails:
    enabled: true
  compliance:
    enabled: true
  llm_consensus:
    enabled: true
  policy_automation:
    enabled: true
  analytics:
    enabled: true

LLM Configuration

Configure LLM providers (optional - system works without them):

llm:
  providers:
    - name: gpt-4o-mini
      api_key_env: OPENAI_API_KEY
    - name: claude-3
      api_key_env: ANTHROPIC_API_KEY
    - name: gemini-2
      api_key_env: GOOGLE_API_KEY

Features

Mathematical Decision Models

Aldeci uses mathematical models as the primary decision-making engine:

  • EPSS Scores: Exploit prediction (0-1 scale, threshold ≥0.7)
  • KEV Status: CISA Known Exploited Vulnerabilities catalog
  • Bayesian Inference: Likelihood ratios for severity forecasting
  • Markov Chains: 30-day exploitation probability projections

LLMs enhance these decisions with explanations, MITRE ATT&CK mappings, and compliance narratives.

Hallucination Protection

Three-layer protection system:

  1. Input Citation Validation: Ensures LLM cites actual input fields
  2. Cross-Model Agreement: Detects outlier responses (30% disagreement threshold)
  3. Numeric Consistency: Validates LLM numbers match computed values

Failed validations reduce confidence by 15% penalty.

Evidence Management

  • Cryptographic Signing: RSA-SHA256 signatures for audit trails
  • Retention: 90 days (demo), 2555 days (enterprise/7 years)
  • Format: Encrypted bundles (.tar.gz) with JSON manifests
  • Immutability: Atomic writes with SHA256 checksums

Compliance Frameworks

Supported frameworks:

  • NIST 800-53
  • NIST SSDF
  • PCI DSS
  • ISO 27001
  • OWASP Top 10

CWE-to-control mappings enable automatic gap identification.

Development

Running Tests

# Run all tests
pytest

# Run with coverage
pytest --cov=. --cov-report=html

# Run specific test
pytest tests/test_pipeline.py

Code Quality

# Lint code
make lint

# Format code
make format

# Type check
make typecheck

Observability

Telemetry

Aldeci exports OpenTelemetry metrics and traces to a collector at http://collector:4318.

To disable telemetry:

export FIXOPS_DISABLE_TELEMETRY=1

Metrics

  • HTTP latency per endpoint
  • Error ratios
  • Inflight request counts
  • Module execution times

Logging

Structured JSON logging with correlation IDs for request tracing.

Security

Authentication

API authentication via API key:

export FIXOPS_API_TOKEN="your-secure-token"

Secrets Management

Store sensitive credentials in environment variables:

  • OPENAI_API_KEY: OpenAI API key (optional)
  • ANTHROPIC_API_KEY: Anthropic API key (optional)
  • GOOGLE_API_KEY: Google API key (optional)
  • FIXOPS_JIRA_TOKEN: Jira API token (optional)
  • FIXOPS_CONFLUENCE_TOKEN: Confluence API token (optional)
  • FIXOPS_SLACK_WEBHOOK: Slack webhook URL (optional)

Evidence Encryption

Enable evidence encryption in config/fixops.overlay.yml:

limits:
  evidence:
    encrypt: true

Requires cryptography package installed.

License

See LICENSE file for details.

Support

For issues, questions, or contributions, please open an issue on the repository.

What's Different from Fixops?

Aldeci 1.0 is a streamlined version of Fixops that includes:

  • ✅ All core functionality (~13,500 lines)
  • ✅ Production-ready code only
  • ✅ Clean directory structure
  • ✅ Complete documentation
  • ✅ Working installation process
  • ❌ Removed WIP/experimental code
  • ❌ Removed duplicate/legacy implementations
  • ❌ Removed incomplete features

Aldeci focuses on the essential, working features that provide immediate value.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages