Proof I build governed AI in the open: sitkastack's vendor-risk-triage framework is shipped at v1.0.5, eight phases complete, open source under Apache 2.0. 1,377 tests at 100% coverage across twelve packages. The full implementation lives on GitHub, with a worked example on /demo.
The open-source framework is a free reference implementation. It is deliberately not a turnkey audit defense. Paid sitkastack engagements deliver the calibrated, client-specific, audit-ready version mapped to your regulatory context and your data.
Eight phases shipped: Discovery & Risk Classification; Data Contracts & Privacy; Architecture & Threat Model; Agent + RAG + Ingestion + Eval; Eval Depth + Retrieval Quality; Operational Hardening; Production Polish; Multi-tenancy + Schema Migration.