Ross ROSS = Recommend OSS · open-source software intelligence for agents

build-trust/ockam

Orchestrate end-to-end encryption, cryptographic identities, mutual authentication, and authorization policies between distributed applications – at massive scale. observed · 2026-08-28

github.com/build-trust/ockam · homepage · Rust · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

61/100

  • Activity 60
  • Release rhythm 40
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 6.5
  • age_days: 2833
  • days_rel: 429
  • days_push: 241
  • n_releases_24m: 23

Full methodology

Adoption not part of the score

4633 stars · 558 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Ockam is a Rust library and CLI toolkit for building secure-by-design distributed applications with end-to-end encryption, cryptographic identities, mutual authentication, and authorization policies. It creates secure channels between systems in private networks without exposing public endpoints, audited by Trail of Bits.

Use cases

  • connect to customer databases behind firewalls without exposing public endpoints
  • establish end-to-end encrypted channels between distributed services
  • manage cryptographic identities and credentials for machine-to-machine authentication
  • replace VPNs and reverse proxies for secure SaaS-to-customer-data connections
  • enforce zero-trust authorization policies on data in motion
  • securely tunnel Kafka or database traffic across networks

When to choose

  • you need end-to-end encryption and mutual authentication between services across untrusted networks
  • you want to eliminate publicly exposed API endpoints and ad-hoc credential distribution
  • you need audited, formally reviewed cryptographic protocols for zero-trust networking
  • you want a CLI plus Rust library to orchestrate secure connections at scale

When to avoid

  • you only need standard TLS between services and have no identity or policy requirements
  • your stack requires non-Rust SDKs today (TypeScript support is not yet available)
  • you need a general-purpose VPN or full mesh networking solution rather than application-layer secure channels

Facets

library · maturity active

auth authorization cryptography security networking chat-interface cli sdk security microservices networking developer-tools rust windows cli cross-platform end-to-end-encryption zero-trust mutual-authentication secure-channels key-management e2ee tunnels credentials messaging linux macos

10 sources

Member repositories

RepositoryRoleHealth v2
build-trust/ockammain61

For agents

markdown · JSON · MCP: product_card(name="build-trust/ockam")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem