Architecting the
autonomy stack.
Three production codebases. One operator. VITNA, formerly VIGIL, is the active bet, the compliance evidence layer for AI agents. GRiiD and CRYpT are archived studio work, no longer maintained.
Built solo. Built honest.
Built for the operator on call.
COSTRINITY is an Indigenous-owned software studio in Regina, Saskatchewan, Treaty 4 territory, Canada. We build operator-grade software for the AI agent era. The compliance evidence layer that lets teams prove what their autonomous systems did, map it to the regulations that apply, and deploy without inheriting unbounded risk.
The studio shipped three production codebases in three months. The first two taught us what high-frequency execution audit logs and local-only privacy architectures actually look like in practice. The third, VITNA, is the twelve-month bet that those lessons land in a category-defining product.
Three codebases. One focus.
VITNA
Compliance evidence layer for AI agents
Pre-flight compliance checks agents call before they act, and audit-grade, signed records of what they did. Mapped to SOC 2 / PCI / ISO / NIST / GDPR / India DPDP across 13 jurisdictions. EU AI Act Article 12 aligned.
GRiiD
Solana trading primitives
Self-hosted execution toolkit: grid, DCA, whale-copy, sniping. Archived. No longer maintained or publicly available.
CRYpT
Local-only file encryption
Authenticated file encryption built on standard, well-reviewed primitives (AES-256-GCM, ChaCha20-Poly1305) with Argon2id key derivation. No cloud, no key escrow. Free edition available.
Three months. Three codebases. One arc.
CRYpT
Local-only file encryption. Shipped what privacy primitives feel like when there's no cloud and no escrow. Set the "your data never leaves your machine" rule that every later product inherits.
GRiiD
Solana trading primitives. Taught us what operator-grade telemetry needs when an automated process executes with no human in the loop. Audit-log discipline carried directly into VITNA.
VITNA
The compliance evidence layer for AI agents. Where the prior two codebases' lessons compose: local-first architecture from CRYpT, audit-log discipline from GRiiD, written for the operator who has to prove what an agent did.
Operator-first.
Build honest.
Ship narrow.
Three things the studio holds to. The product gets built for the human on call, not the team that deployed it. The marketing says what shipped, not what's planned. The roadmap stays narrow because focus is the scarcest input at this stage.
Operator-first
The person on call when an agent burns through API credits at 3am sees a different problem than the ML engineer who deployed it. Tools built only for the engineer leave the operator holding the pager.
Build honest
Every claim on this site is what's true today. VITNA's Aadhaar detector ships with a measured ~10% false-positive rate from Verhoeff alone, and we explain why that's a mathematical ceiling, not a bug. The fix (context gates) is a Phase 1 line item, not a marketing promise.
Ship narrow
Three production codebases proved we can build broadly. VITNA gets the next twelve months alone. GRiiD and CRYpT are archived and no longer maintained. Velocity is a moat only when paired with focus.