Sebastien Rousseau

MCP · ZERO-TRUST · DORA

CloudCDN — open-source blueprint for the AI-native edge

An open-source reference implementation a security team can read, fork, and sign — instead of a marketing PDF. Atomic Durable Objects rate limiting, WebAuthn perimeter, SLSA L3 provenance.

Read case study

An open-source reference implementation a security team can read, fork, and sign — instead of a marketing PDF. Atomic Durable Objects rate limiting, WebAuthn perimeter, SLSA L3 provenance.

Problem

As AI agents and MCP tools start calling edge APIs at scale, banks need a perimeter that survives autonomous traffic without trading away DORA-grade audit evidence. Existing CDNs offer either marketing language or opaque plans — neither produces the reference implementation a security team can read, fork, and sign.

What I built

An open-source, zero-trust MCP gateway with 42 tools, atomic Durable Objects rate limiting, WebAuthn passkey perimeter, signed URLs, and SLSA Level 3 build provenance. 3,185 tests at 100 % coverage, mapped to DORA Article 5, BCBS 239 risk-data aggregation, and Basel III operational risk capital.

By the numbers

3,185 tests
100 % line, branch, function coverage
SLSA L3
Build provenance + Sigstore signing
42 MCP tools
Every call audit-logged with structured evidence
DORA / BCBS 239
Mapped to Article 5 + risk-data aggregation

Engineering rigour

  • Tests

    3,185 tests at 100 % line, branch, and function coverage

  • Supply-chain provenance

    SLSA Level 3 build provenance + Sigstore signing

  • MCP tools shipped

    42 tools — every call audit-logged with structured evidence

  • Rate limiting

    Atomic Durable Objects (no race conditions, no double-counts)

  • Authentication

    WebAuthn passkeys + signed URLs

  • License

    Apache-2.0 / MIT

Independently verified

  • Featured in the 2026-06-11 article: CloudCDN — An Open-Source Blueprint for the AI-Native Edge
  • Mapped to DORA Article 5, BCBS 239, Basel III operational risk

Related articles

NEXT

Want this kind of evidence in your bank?

Architecture reviews, post-quantum migration plans, treasury-API programmes — all signed, all verifiable.

Get in touch

MORE CASE STUDIES

More case studies