Trust starts with local facts, not another opaque dashboard.

Kungfu is being prepared as a local-first control plane for long-running agent work. Trust follows a public software path: product-owned declarations, exact build and artifact evidence, purpose-bound assessment, and a receiver-owned decision.

Open source core

Kungfu core software is released under the Apache License 2.0. Public collaboration happens in the open repository, with security issues routed through GitHub private vulnerability reporting.

License policy

Local-first posture

The product direction is built around local journals, replayable evidence, and explicit export. Optional future services should add team, support, compute, storage, or governance capabilities without making the local core depend on login.

Auditable release evidence

Buildchain binds product-owned declarations to exact source, build, artifact, checks, and promotion evidence. It can fail or downgrade on drift; it does not invent product facts or make the receiver’s KFD-2 trust decision.

Buildchain release passport · Agent Supply Chain

Provider compliance

Official integrations should respect provider terms, credential boundaries, billing and quota attribution, and usage transparency. Kungfu should not hide costs, forge usage evidence, or bypass provider protections.

Provider compliance

Official identity boundaries

Open source rights do not grant trademark rights or imply that a fork is an official Kungfu service. Official project names, domains, package identity, and hosted services are governed separately from the code license.

Trademark policy

Acceptable use

Kungfu is intended to help developers and agents inspect runtime behavior honestly. Official services and integrations should preserve user control, evidence quality, security reporting, and truthful attribution.

Acceptable use

Developer source material

The commercial product surface lives on kungfu.tech. Developer-facing material, API references, and first-party technical facts are linked from libkungfu.dev.

Legal center

Trademark, acceptable use, provider compliance, security reporting, and website-level privacy posture are collected in the legal center.

Read legal and policy links