{ tuturama }
contactEestiet
{ software factory }

Software factory for systems that cannot break.

Tuturama is an AI-native software factory. We build products, embed with security teams inside large institutions, and contribute to the code the world runs on.

{ embedded }

Security and AI, inside the institution.

We work embedded, forward-deployed in the client's own team, with a mandate on security and artificial intelligence. The advice comes with the engineering that follows it: threat models for AI adoption, architecture reviews, tooling the team keeps after we leave.We also install the operating model we run on inside a team: roles as skills, gates before shipping, memory that outlives the session. Two to four weeks. Your people keep it.

Right now that seat is inside the CISO Office of a European retail group. Over twenty years the same seat has been inside Pearson, Société Générale, Walmart, Banco do Brasil and Kraken, always where new technology meets old structure.

Ask about an embedded engagement

{ products }

Apps with a cognitive layer.

Skywave on macOS: explore view with stations, focus and easy-to-follow rows

Skywave

live

Radio from the whole planet, in your menu bar and in your pocket.

A world radio player with a map, favourites that survive catalogue changes, and a curated station catalogue with programme schedules. Its cognitive layer turns listening into learning: vocabulary, sessions and goals sit next to the stations. The name comes from skywave propagation, the ionospheric bounce that lets a signal from Tokyo reach Tallinn. macOS and Android are live. iOS is in review.

Listening Robots mark

Listening Robots

pilot

Audio intelligence for radio.

Continuous listening to the broadcast, turned into quota compliance reports, proof of airplay and market intelligence. The cognitive layer is the listening itself: recognising speech, music and language on the live signal, hour after hour. Built for regulators, rights societies and stations, starting with regional languages that mainstream speech recognition ignores. Piloting in Europe.

Ulpiano landing page with a terminal running ulpiano check

Ulpiano

private pilot

A legal companion that lives inside your coding agent.

While the project is being born, Ulpiano reads the repository and flags trademark, privacy, licence and tax issues, records each risk next to the code, and calls a real lawyer when it is time. Reading code the way a lawyer reads a file is its cognitive layer. It suggests. It never issues a legal opinion.

The factory's own output. It is how we know the method works. More on the products

{ threads }

Three lines that run through the work.

Six years, three threads. Each one starts in the studio years and ends in something shipping now.

Audio

From explaining by ear to machines that listen.

  1. 2023

    Tuturama Studios

    Story-driven audio courses on markets and money: Wonderville, Dojima.

  2. 2024

    Icarus

    An audio series on the Internet Computer, released as a podcast on Spotify.

  3. 2026

    Skywave

    World radio on macOS and Android. Listening turned into learning.

  4. 2026

    Listening Robots

    Continuous listening to the broadcast, turned into compliance reports and proof of airplay. Piloting.

Proof

Prove it without revealing it.

  1. 2024

    Tuturama Labs

    The studio's technical arm: tokenization and zero-knowledge development behind the courses.

  2. 2025

    ZK demos

    Zero-knowledge proof demos and zkvox, a ZK voting prototype, public on GitHub.

  3. 2025

    Ghost

    A zero-knowledge canister on the Internet Computer.

  4. 2026

    proofpay

    Zero-knowledge gated x402 access for autonomous agents on Stellar.

Agents

Agents that pay and browse, and the guards around them.

  1. Apr 2026

    x402

    Solana payment scheme merged into the Rust implementation.

  2. Aug 2026

    Threat model

    For an MCP server that lets an agent pay over x402 on Stellar. Six primitives, in phases.

  3. Aug 2026

    Payment guard

    Policy before the signature and a signed audit log, proven end to end on Stellar testnet.

  4. Sep 2026

    agent-security

    Four audits as skills for coding agents, with a runnable verifier. MIT.

{ upstream }

Open source, merged.

  • Linux kernel

    Multiple commits in mainline (staging, IIO drivers), reviewed by maintainers at Intel and Huawei. More in the IIO queue.

  • Stellar CLI

    Fix for SkipWhitespace returning an early EOF on whitespace-only chunks.

  • FediMint

    Merged PRs: automated nix flake updates, deprecation warnings on hidden CLI commands, unwrap to expect in non-test code.

  • Rig

    Capture ResponseFailed errors in OpenAI stream mode. Released in rig-core 0.34.1.

  • Foundry

    Trace option consolidation, authored commit merged through the maintainers' PR.

  • x402

    Solana exact payment scheme for the Rust implementation, with integration tests and examples.

Every item links to the maintainers' review. Nothing here is self-published. The work is continuous; the live state is on GitHub. github.com/gabrielrondon · Full list, including what is in review

{ now }

Security for AI agents.

Agents now browse, pay and read private data on our behalf. The security around them lags behind what they can do. This is where the factory spends its own time in 2026: threat models for agentic spend, gates in agent tooling, guards for autonomous payments.

Findings go to the maintainers first. Methods go public as skills.

what is open right now

{ writing }

Research and essays by the founder, on traceability, verification, and the engineering hidden inside institutions, at gabrielrondon.com.