Security tooling
Defensive tools for examining software before it is trusted.
ReleasedHammerhead v0.1.0
Talarurus is an independent software organization. Its first release, Hammerhead, audits potentially untrusted software repositories on your own machine.
Featured product
Hammerhead is defensive security tooling for auditing potentially untrusted software repositories. It is local-first, written in Go, and reports findings in three separate classes.
Audits run on your own machine, where the repository already is.
Hammerhead is built around a security-focused SafeWalker architecture.
Hammerhead separates its findings into three classes: Security, Hygiene, and Info.
Read results directly in your shell as part of a manual review.
Structured output for scripts and other tools.
A single command-line tool, used by hand or from your own automation.
Areas of work
Talarurus builds in three areas. Hammerhead is the first release. Work in the other areas will be published when it is ready.
Defensive tools for examining software before it is trusted.
ReleasedHammerhead v0.1.0
Focused tools for the day-to-day work of building and maintaining software.
No public release yet
Software, including AI, that runs on hardware you control and keeps your data there.
No public release yet
Principles
Security is the starting assumption. Hammerhead is built around a security-focused SafeWalker architecture.
Software that runs where your code and data already are: on your own machine.
Results should be clear enough to act on, for people and for tools.
Each tool has a defined job and a clear boundary.
About
Talarurus was founded in 2026 to build security, developer, and local-first software.
It takes its name from Talarurus, a genus of armored dinosaur.
Find Talarurus on GitHub, or get in touch at ammaar@talarurus.com.