🤝 Work with us — capability sheet & open-source call
K0NSULT builds evidence-first governance tooling: systems in which a claim may not
exceed its proof. This page is the single link we send in reply to inbound interest — instead of filling in someone
else's form. Everything below is either PROOF (verifiable at a URL you can open today) or
GAP (stated plainly as not-yet-done). We publish no figure without its denominator.
Read this first. We are a
named legal entity: K0NSULT Sp. z o.o., KRS 0001239441,
NIP 5253089872, registered in Poland, EU. Our contact channel is signed (
RFC 9116
security.txt, PGP-clearsigned). If a counterparty cannot show you the same three things — legal name, public registry
number, a verifiable contact — treat their pitch as unverified, whichever direction the offer flows.
(1) What we build — three lanes
⚠️ An honesty note we are contractually free to make
Our commercial product line is not open source and we do not pretend otherwise. Apache-2.0 is
irreversible; putting a saleable asset under it would destroy the asset, so we did not. What is open is
listed above and licensed for real. We consider "open-source-washing" — an OSS badge over a closed core — a
governance defect, and we say so in our submission to the Commission.
(2) What is unusual about how we work
These are the things that are hard to hire for individually, because they are method rather than stack:
- Claim ≤ proof, enforced in the tooling. Not a slogan — a gate. A statement that cannot be tied to a
verifiable artefact is classified as GAP or narrative and does not get published as fact.
This applies to our own marketing, which is why this page has no adjectives about ourselves that we cannot evidence.
- Every metric states its denominator. "100% coverage" on our portal means evidence coverage of the
claims made — never "impenetrable", never "complete knowledge". A percentage computed with your own ruler is
narrative, not measurement.
- Adversarial verification by default. Findings are re-tested by independent reviewers prompted to
refute them, not confirm them. We have shipped fixes for defects that our own first-round remediation
introduced, and published that fact.
- We invite external audit and publish the results including the bad ones. Our stack has been audited
by a party outside our ecosystem; the round-one report produced 8 high / 11 medium / 12 low findings — all remediated,
with commit hashes. Three of the highs invalidated claims we had been making. That report is why we trust the rest.
- Regulatory literacy that is actually operational. EU AI Act Article 50 transparency duties, the
Article 57 regulatory-sandbox route, and the Digital Omnibus deferral of Annex III high-risk obligations — mapped to
concrete deadlines and concrete code, not to a slide.
- The attestor does not host. Whoever gathers the evidence must not also attest to it. Where we are
paid by a party whose work we assess, we disclose the conflict ourselves, before anyone asks.
(3) Figures — each with its denominator
9repos under Apache-2.0 (of 9 in open scope)
9/9repos with a published SECURITY.md
0blocker findings open after swarm audit
31/31external round-1 findings remediated
Denominators: "open scope" = the repositories we placed under an open licence, which explicitly excludes the
commercial line. "Swarm audit" = an internal multi-agent review across those 9 repositories, 2026-07-20. "External
round 1" = 8 high + 11 medium + 12 low findings raised by a reviewer outside our ecosystem, all closed with commit
hashes. These are counts of findings raised and closed — not a proof of absence of further defects. Figures as
of 2026-07-21.
(4) What we do NOT do
- We do not issue investment ratings, price predictions, or trading signals — and we regard a confidence percentage
published without a stated denominator and method as a governance red flag, not a feature.
- We are not a public authority, an accreditation body or a certifier. Nothing we publish is a conformity assessment.
- We do not give legal advice. Our regulatory work is decision-support; on binding matters the primary source and the
competent authority prevail.
- We do not run token sales and we hold no position in any coin. Where we use on-chain identity concepts they are
soulbound, non-transferable attestations — identity and reputation, never network liquidity.
- We do not send unsolicited recruitment mail, and we do not ask anyone to run a "verification step" on their own
machine. If a message claims to be from us and does either, it is not from us.
🟢 Contribute to the open-source stack
The open lane is genuinely open and genuinely under-resourced. We are not offering a job funnel — we are offering a
codebase you can read before you commit to anything, which is the direction of trust we think should be default.
- Licence: Apache-2.0. Contributions under the same. No CLA that assigns your copyright away.
- Where to start: every repository carries a
SECURITY.md and issues tagged for first
contributions. Reading the audit history is the fastest way to understand our standard of proof.
- What earns our attention: a small, working, tested change that fits the maintainer's direction —
over a large one that does not. Fit beats volume, every time.
- Security findings: report via security.txt. We publish
confirmed findings and the fixes, with hashes, including the embarrassing ones.
- Paid work: possible and it happens, but it starts from a contribution or a scoped, contracted
engagement — never from a form that collects your details before you have seen anything of ours.
(6) If you are approaching us — the reciprocity test
We answer inbound with this page rather than a form, and we ask the same of counterparties. Before either side shares
anything of value, both should be able to show:
- a legal entity name and a public registry number that can be looked up independently;
- a named human with a verifiable professional footprint, who will take a video call;
- a signed or otherwise verifiable contact channel, on a domain that resolves to real content;
- a description of the work that survives a technical question asked live.
Ours are above and on this domain. A counterparty that cannot match them is not necessarily malicious — but the burden
of proof sits with whoever made first contact, and that burden does not move because the offer is flattering.
Disclaimer. K0NSULT Sp. z o.o. (KRS 0001239441, NIP 5253089872) is a private company. It is
not an authority, agency or public institution; it does not certify, accredit or assess the conformity of any
entity, and it provides no legal or investment advice. Figures on this page are counts of work performed, each stated
with its denominator, current as of the publication date; they are evidence of activity, not a guarantee of absence of
defects. On binding regulatory matters the primary legal source and the position of the competent authority prevail.