Some become extremely expensive ways of learning something obvious.Some become extremely expensive ways of learning something obvious.Some become extremely expensive ways of learning something obvious.
6 sites live (2026)
Blake (thebdot) / architect, builder, writer
I build AI systems that prove what they claim.
A credential broker whose operator can't read the secrets. Compliance evidence that exists before
the auditor asks for it. An evaluation that checks whether the French answer is as good as the English one.
Each one comes with a way for you to check it yourself.
# vault.melx.buzz: Sepulchre$ bash tools/verify-policy.sh
==> operator-scoped token reading inbound DENIED# osfi.melx.buzz: osfi-gate$ osfi-gate verify ./evidence
==> signed evidence bundle OK# open-articles: every number, reproduced$ make reproduce && make test
==> no credentials, no provider calls PASS█
Zero-knowledge operators✦Policy as code✦OSFI B-13 · B-10 · E-21 · E-23✦Tamper-evident audit✦MCP authorization✦ISO 20022✦Bilingual AI evaluation✦Open standards✦Zero-knowledge operators✦Policy as code✦OSFI B-13 · B-10 · E-21 · E-23✦Tamper-evident audit✦MCP authorization✦ISO 20022✦Bilingual AI evaluation✦Open standards✦
01 — Live work
Shipped in public, each one checkable.
Each screenshot scrolls through its page. Click one to open the live site.
01Security · Credential broker
Sepulchre
Built with
App
TypeScript
Hono
Astro
MCP SDK
Zod
Security
HashiCorp Vault
OIDC / JOSE
Argon2
Hash-chained audit
Data
PostgreSQL
Drizzle ORM
PgBouncer
MinIO (S3 WORM)
Ops
Turborepo
Docker
Kubernetes
Terraform
Ansible
Traefik
Prometheus
Cloudflare Pages
“Don't trust us. Verify us.”
A credential broker for the secrets that pass between people. The operator who runs it
can't read what flows through it: an explicit Vault deny policy blocks access no matter what other permissions exist.
A script you can run yourself checks that promise against the live system.
“The audit evidence is written before anyone asks for it.”
For Canadian banks, insurers and credit unions. osfi-gate runs in the build pipeline on every change.
It maps scanner findings to controls anchored in OSFI guidance, applies the policy the risk team keeps in Git,
and files a signed record of every decision. Anyone can verify those records offline.
OSFI B-13 · B-10 · E-21 · E-23
24 controls from Semgrep, Trivy, Gitleaks, Checkov
“Is the French answer as good as the English one?”
A bilingual quality harness. It runs the same corpus, questions and metrics through an AI content pipeline
in English and in Canadian French, then reports the gap between the two. It also tracks Canadian-specific failures:
Quebec forms replaced by France equivalents, and valid Canadian French "corrected" into something else.
Interactive architecture and concept diagrams across the Score Anything Loyalty platform, independent open-source projects
and reference studies. The thread running through them is AI architecture: hosted multi-agent systems, on-box constrained decoding,
computer vision, and how to choose between them based on the constraints that bind.
The Athlete Loyalty Exchange runs itself and is governed by AI agents. Fans buy and sell athlete coins with loyalty points,
and prices move in real time with demand and performance. There are no drafts, salary caps or season-long commitments.
It runs on loyalty points only, so it stays a closed, non-cash ecosystem.
The Score Anything Loyalty platform I build at 3 Halves Labs.
SCORE is an open, modular fan engagement, loyalty and AI platform for sports clubs, music artists, venues and agencies.
It brings fan engagement, marketing and operations together so organizations own their fan data,
replace point solutions, and open new revenue streams.
Research-grade motion analysis from ordinary video.
A markerless biomechanics platform. It estimates pose from video, lifts it to 3D, and compares an athlete's movement
with elite reference models from any camera angle, using joint-angle features, Procrustes alignment and dynamic time warping.
Newton-Euler inverse dynamics and a 9-state Kalman filter with IMU fusion estimate forces without a lab.
Motion capture labs cost $100k–500k; this needs a camera.
A 3D star chart of the 3HL repositories, built into Gitea. Each repository is a star, sized by lines of code and haloed by
recent commits, with planets for its largest folders and a red ring where possible secrets turn up. Fly inside a repo and
folders become spiral arms, files become stars and imports become arcs, while the full history replays author by author.
The data lives inside each repository, so every viewer sees only the repositories they can already open.
13 repos ~1M lines, 2.8k commits
Live issues, PRs & CI runs flare their star
Permission-aware follows Gitea access
History replay every commit, every author
git.3halves-labs.com · 3HL star chart
repo galaxy · sky theme
AI operations · In development
SCORE MCP Server
Built with
Stack
TypeScript
Node.js 22
MCP SDK
Zod
jose
Identity
Keycloak OIDC
Device-authorization grant
Token exchange
Contract
OpenAPI control-plane contract
Fake control plane
Testing
Vitest
Ajv
Operator-task evals
Anthropic SDK
Transport
stdio
Remote connector
Docker
Claude runs the platform. A human signs every change.
An MCP server that lets Claude operate SCORE: users and permissions, services, errors, GDPR requests, audit events,
loyalty reports and usage. It acts as the signed-in person, using their own Keycloak token, and holds no admin
credentials of its own. Every write is two-phase: a propose_* tool creates an approval, a human approves it
in the dashboard, and only then can execute_approved run it. No tool can approve, and a test enforces that.
41 tools 30 read, 11 write
Two-phase writes propose → approve → execute
Acts as you your identity, your rights
5 guided routines health check, offboarding…
claude · score-mcp
# signed in as you, via Keycloak› who_has_access service=odooread› access_drift read› propose_revoke_access user=wendy→ approval created pending waits for a person to approve in the dashboard› execute_approved applied# no tool can approve. tests/boundaries.test.ts
Developer kits · Web & mobile
SDK Kits
Built with
Mobile
Kotlin Multiplatform
Swift (SPM + CocoaPods)
Ktor (OkHttp / Darwin)
Android AAR
XCFramework
Web
TypeScript
React
tsup
web-vitals
IndexedDB
Loyalty SDK
axios
TanStack Query
Shared
JSON Schema wire contract
Generated typed events
Vitest
Gitea CI
npm
One event model, every screen.
Tracking and loyalty SDKs that put SCORE inside a club's own apps and sites. The mobile tracker is one Kotlin Multiplatform
core for iOS and Android, with a native Swift facade. The web tracker is React-first, with consent gating, regional
privacy policies (GDPR, CPRA, LGPD, Québec), PII scrubbing and a durable queue. All of them share a typed event taxonomy
and a JSON Schema wire contract, so an event looks the same from every platform.
A neutral, open standard for describing sports schedules, constraints and optimization goals, for traditional sports, esports and competitive events.
Sports scheduling is fragmented because every vendor describes the problem in its own way. OSSS standardizes the
description of the problem and leaves the solution to whoever solves it, so scheduling rules stay portable
and schedules can be audited and explained.
A governed MCP server for ISO 20022 payment operations. AI agents can initiate and validate payments, and every action goes through an audit layer first.