Skip to content

Self-hosted · Vendor-neutral · Open-core

Integrate, manage and secure the AI you actually run — one ground truth.

Context, resources, sessions and identities in one self-hosted plane: Claude Code at the deepest level, Codex and Grok Build alongside — and open to any other model or provider you run.

Your agents get what they need to do real work; you keep the granular permissions, policy, budgets and audit evidence to run all of it. It complements your agents; it does not compete.

AGPL-3.0 Changelog GitHub

Olivares AI access map showing agents and sessions connected to resources by read and read/write relationships.
30
wired modules · one self-hosted release
100%
self-hosted — governance data stays under your control
0
mandatory calls home · runs air-gapped
R / RW
per-resource access · permitted vs observed

Discover · 01 / 05

Every agent in your estate, discovered passively

No proxy, no agents to babysit. Olivares watches your infrastructure and inventories every agent, session, model and MCP — with the surfaces each one reads and writes.

data-export-job holds an unreviewed write to prod-postgres — least-privilege drift, surfaced the moment it appears.

Govern · 02 / 05

One rule, before and after

Write policy as code and watch it land on the map. The unreviewed write to your production database becomes a denied, least-privilege path.

policy · prod-db-writes
policy "data-export-readonly" { agent = "data-export-job" resource = "prod-postgres" allow = ["read"] deny = ["write"] on_violation = "block + alert"}

Pin the export job to read-only on the production database; block writes.

enforcement● enforcing

Cost · 03 / 05

Spend, attributed — not estimated

Every dollar tied to the agent, model and team that caused it — with budgets and trends your finance team can act on, not guess at.

olivares · cost prod Preview
Spend by agent last 30 days
Agent Model 30d Trend % total
claude-deploy-bot claude-opus-4-8 $1,860 22.1%
data-export-job magistral-small $1,240 14.8%
support-rag-agent gpt-5.5 $980 11.7%
infra-copilot claude-opus-4-8 $880 10.5%
billing-reconciler claude-sonnet-4-6 $720 8.6%
qa-runner gpt-5.4-mini $180 2.1%
+208 more agents $2,540 30%

Audit · 04 / 05

An append-only record of who touched what

Every access in a tamper-evident, hash-chained ledger — filter it, replay it, and export it as evidence your auditors accept.

Security & Compliance · 05 / 05

Verifiable controls, mappable frameworks

mTLS, an append-only ledger and policy enforced at access time — mapped to the frameworks your auditors ask about.

mTLS between components

Mutual TLS on every internal hop; no plaintext control traffic.

● enforced

Append-only ledger

Every view and change hash-chained and tamper-evident.

● active

Guardrails

Policy enforced at access time — blocked, not just logged.

● enforced

Least-privilege collector

Passive discovery from a minimally-privileged, read-only collector.

● active
olivares · compliance matrix prod Preview
Framework coverage mapped partial in progress
Framework Access controlAudit trailRisk mgmtData governance Coverage
EU AI Act mapped mapped mapped mapped 96.9%
NIST AI RMF mapped mapped mapped partial 98.6%
ISO 42001 mapped mapped in progress mapped 97.4%
SOC 2 mapped mapped partial mapped 98.4%
coverage 98% Olivares maps your controls to each framework; coverage shown is self-assessed and illustrative — not a certification. It gives you the evidence to support your certification path.

How it works

Running in your own infrastructure

  1. 01

    Deploy

    A single container or binary on your own infrastructure. No account, no cloud dependency, no mandatory calls home.

  2. 02

    Discover

    Olivares AI passively finds every agent, session, MCP and model already running — no mandatory proxy.

  3. 03

    Map

    It builds the access graph: what each agent can reach and what it actually touches, read versus read/write.

  4. 04

    Govern

    Set policy, watch for drift and export audit evidence. Visibility becomes control as your estate grows.

How it works

vendor-neutral · runs across Claude OpenAI Gemini Llama Ollama / vLLM Postgres S3 Vault Kafka Kubernetes AWS / Cloudflare

Open source

Your infrastructure. Your data. Your ground truth.

Olivares AI is open-core under AGPL-3.0. The complete product is in the public repository, tagged and signed since v26.8.0 — to run on your own infrastructure, inspect every line, and keep your data where it belongs. A commercial license and a dedicated enterprise tier are available when your organization needs them.

  • AGPL-3.0

    The complete product, self-hosted, free — no feature gates on the core.

  • Vendor-neutral

    Not tied to any single AI vendor, identity provider or cloud.

  • Air-gapped friendly

    Olivares makes no mandatory calls home and runs in isolated, regulated networks. Fetching and updating the commercial add-ons needs an active subscription.

Support the project.

Sponsorship sustains the development, integration and updates of Olivares AI; it is not a support contract and buys no priority.

GitHub Sponsors Or on the maintainer’s profile Ko-fi

See what your agents can reach

Deploy Olivares AI on your own infrastructure and get the access map your platform and security teams have been asking for.