<!-- Generated from reviewer-dinis-cruz.html by scripts/site/generate.mjs. Edit the page, not this file. -->

# RiskMandate — Dinis Cruz, who runs the review

Dinis Cruz runs the reviewed level of an Agent Behaviour Policy: two sessions with your team and a sign-off. Every line on this page is read off a page they publish themselves, with the date it was read.

Source: https://riskmandate.ai/reviewer-dinis-cruz.html

---

# Dinis Cruz

Founder of RiskMandate.ai and the sgit.ai network; former OWASP Board member and organiser of the OWASP Summits; creator of the O2 Platform.

## Every line below is read off a published page.

Nothing here was written from what somebody told us in conversation, and nothing here was composed by this site. A biography we wrote ourselves is the last thing that should stand beside a price this size, so the sources are named and dated and you can check them before you decide.

## What they have actually done.

The method being reviewed is theirs. What an agent can reach, what it was authorised to do, the gap derived from the two and the barrier that stands in the way of each capability — the model, the sixteen published template vaults and the read keys that open them are all on this site, in the open.

The business risk layer for autonomous systems. Its field demo is published as a vault of 124 files and 98 commits inside one encrypted store.

Encrypted vaults with git semantics — clone, commit, branch and merge files encrypted before they leave your machine — under Apache-2.0, and the network of sites of which riskmandate.ai is one. Thirty-one vaults are published with their read keys as the evidence.

And organiser of the OWASP Summits, Lisbon 2011 and Woburn 2017 — the working-session format with no spectators and only participants, which the Open Security Summit series went on to build on. Current open-source work still ships under the owasp-sbot organisation.

The OWASP static-analysis engine of 2010 to 2012, and the first of a line of open-source tooling that continues in the osbot and mgraph families, memory_fs, Issues-FS and sgit-ai — all Apache-2.0 and all on PyPI.

A platform for the conversation between technical security teams and the board, built with knowledge-graph technology. Apache-2.0, with the community edition and the investment repository public.

Role-aware cybersecurity briefings built on semantic knowledge graphs, with source attribution: CISO, engineer and board views of the same news. Open source and serverless, with the seed pitch and unit economics published in the open.

## What the two half-hours can be held in.

A session is a conversation rather than a document, so the language it runs in is a real difference between one reviewer and another.

The language every published site in the network is written in.

Named editor of record of the Portuguese newsroom on newsroom.sgit.ai.

## Read them before you book them.

The long-form research and essays, published CC BY 4.0.

Signed when written in the first person; the unsigned ones are written in the site's own voice by the team of agents and say so.

## What you should know before you weigh the review.

Runs the companies whose strategy these sites describe, and sells the running service rather than the code. The market this site describes is one they intend to be in — and this review is sold by that company, by the person who designed the method being reviewed. Read the review knowing that. It is why the sign-off names a person and a date rather than an organisation.

Availability: One name on this list today. No queue is published and none is promised: ask, and the answer comes back within a day. **Confirmed 22 September 2026**, and stated as a date rather than a calendar because a calendar on a page is stale the moment somebody books. On this list since 22 September 2026.

## The sign-off carries a name and a date.

Not an organisation and not a logo: the file committed to your vault at the end of the reviewed level names the professional who signed it and the day they did.
