SVTPrivateAI

The model proposes. The runtime decides.

A local-first Python runtime that runs AI agents under scoped capabilities, a deterministic policy engine, human approvals and a hash-chained audit log.

Agents are declared in YAML with scope-aware capabilities — read wide, write only where needed — and every tool call goes through one controlled path: capability check, policy evaluation, an optional human approval bound to that exact call, then a tamper-evident audit record that names the rule that acted.

Providers include Anthropic, OpenAI-compatible endpoints and a deterministic mock used by default, so it runs without an API key. MCP servers are treated as untrusted extensions, and secrets are resolved inside tools, never placed in model context. The `svt` CLI checks, explains and audits every decision.

Built

Technology

Python, Pydantic, Typer, Rich, httpx, SQLite, OpenTelemetry, MCP, pytest, mypy

svt in a terminal: doctor, a write to /etc/passwd denied outside the agent’s scope, a write inside docs/ allowed, and the audit chain verified

Index