# Orygn Orygn LLC is a software and security company based in the Houston, Texas area. Orygn builds custom software, internal tools, workflow automation, and security-focused systems for small businesses and growing teams. Orygn also publishes open-source security tools for Microsoft Entra ID, file integrity, and CI/CD supply chain security. ## Services - [Custom Software Development](https://orygn.tech/services/custom-software): Purpose-built software for workflows that have outgrown off-the-shelf tools. - [Internal Tools](https://orygn.tech/services/internal-tools): Admin dashboards, client portals, and operational interfaces for internal use. - [Workflow Automation](https://orygn.tech/services/workflow-automation): Automating repetitive processes across multiple systems and tools. - [Security Hardening](https://orygn.tech/services/security-hardening): Infrastructure review, configuration audits, and hardening for cloud and identity systems. - [Website Design](https://orygn.tech/services/web-design): Website design, development, improvement, and migration for small businesses in the Houston area. Orygn works across major platforms (WordPress, Shopify, Wix, Squarespace, Webflow, GoDaddy, Weebly, BigCommerce, Square, and more) and also builds fully custom sites. - [Accessibility and Section 508](https://orygn.tech/services/accessibility): Manual web accessibility audits and Section 508 conformance testing performed by a certified DHS Trusted Tester. WCAG 2.1 and 2.2 Level AA testing, VPAT and Accessibility Conformance Report (ACR) authoring, code-level remediation, screen reader and keyboard testing, and re-test validation. Orygn tests the site and fixes the code, no accessibility overlays or widgets. For private businesses and government, education, and healthcare vendors nationwide, based in the Houston, Texas area. ## Products - [File X-Ray](https://orygn.tech/products/file-xray): Browser-first metadata inspector for 20+ file formats (images, PDFs, documents, video, audio). GPS map view, AI-powered summaries via Gemini, byte-level PDF forensics, risk classification, and metadata stripping with strip-diff reports. Live at https://filexray.orygn.tech - [WebShield](https://orygn.tech/products/webshield): Production security scanner checking transport, network, and application layers. Security headers, TLS handshakes, CVEs via OSV.dev, DNS (CAA/MX/DNSSEC), email auth (SPF/DMARC/DKIM/MTA-STS/BIMI), exposed paths, trackers, and tech fingerprinting. 27-article knowledge base with copy-paste remediation configs for Nginx, Apache, Vercel, Netlify, and more. Live at https://webshield.orygn.tech - [BitSeal](https://orygn.tech/products/bitseal): Cryptographic provenance system that seals files with BLAKE3 Merkle trees, Ed25519 Authority signatures, and Bitcoin-anchored timestamps via OpenTimestamps. Neon Postgres ledger, published Authority verification key, and open-source Python SDK with offline verification. Live at https://bitseal.orygn.tech - [Vendor Access Vault](https://orygn.tech/products/vendor-vault): Vendor access management application that vaults credentials with AES-256-GCM encryption (per-credential IV, separate authTag), gates plaintext reveals behind just-in-time access requests with admin approval and auto-expiration, and writes an append-only audit log of every action with actor, IP, and user agent. Includes vendor directory with risk metadata, rotation tracking with cron emails and atomic access revocation, RBAC (owner / admin / viewer) with multi-tenant org isolation, TOTP 2FA, Google OAuth, Cloudflare Turnstile bot protection, Cmd+K commander, in-app notifications inbox, vendor comments, and CSV audit export. Also includes a free, no-signup one-time secret tool at https://vendorvault.orygn.tech/tools/one-time-secret for sharing a single password, API key, or note as a link that reveals it once, then self-destructs; the secret is encrypted in the browser and the decryption key travels only in the link's URL fragment, so the server stores only ciphertext. Built on Next.js 16, Neon Postgres with Drizzle ORM, Auth.js v5, Resend, Tailwind 4 with Shadcn UI, tested with 101 Playwright E2E specs. Live at https://vendorvault.orygn.tech - [DiligenceDesk](https://orygn.tech/products/diligencedesk): Federal contractor due diligence tool reconciling 8 public U.S. data sources (SAM.gov, DOL Wage and Hour, OSHA, ITA Consolidated Screening List, USAspending, SEC EDGAR, GLEIF, NIST NVD) plus a Section 889 prohibited-hardware registry into a deterministic PASS/WARNING/FAIL/NEUTRAL verdict. Includes batch CSV auditing, interactive risk graph, sector-risk overlay (32 NAICS / 44 PSC codes), local-first audit history, 18-page reference knowledge base, and PDF/CSV export. Live at https://diligencedesk.orygn.tech - [Beaconly](https://orygn.tech/products/beaconly): Free AI discoverability audit tool running 35 checks across robots.txt, llms.txt, JSON-LD structured data, and page structure to determine whether AI crawlers can find and cite a site. Live at https://beaconly.orygn.tech - [OPA MCP](https://orygn.tech/products/opa-mcp): Open-source Model Context Protocol server that gives Claude, Cursor, VS Code, and any MCP-compatible client a structured interface to Open Policy Agent and Regal. 50+ tools across authoring, evaluation, bundle ops, server management, high-level helpers, and Conftest configuration testing. The OPA binary is bundled with the npm package, so no separate OPA install is needed. Published on npm (@orygn/opa-mcp), Docker Hub (orygn/opa-mcp), the official MCP Registry (io.github.OrygnsCode/opa-mcp), and listed in the official OPA Ecosystem. MIT licensed. GitHub: https://github.com/OrygnsCode/opa-mcp-server - [Omnicord](https://orygn.tech/products/omnicord): Discord server management MCP for AI agents. Source-available Model Context Protocol server that gives Claude, Cursor, Windsurf, and any MCP-compatible client full operational control of a Discord server through your own bot. 150+ tools for chat, moderation, administration, and building a server from a one-paragraph brief, with a confirmation gate on every destructive action. No LLM inside, no cloud, token stays local. Published on npm (@orygn/omnicord), Docker Hub (orygn/omnicord), the official MCP Registry (io.github.OrygnsCode/omnicord), Smithery, and Glama. Source-available under the Elastic License 2.0. GitHub: https://github.com/OrygnsCode/Omnicord - [Deposit Record](https://orygn.tech/products/deposit-record): Free, statute-cited web tool that helps small landlords return security deposits correctly. Computes the state return deadline from the vacate date, explains deduction rules with verbatim statute quotes, citations, and last-verified dates, computes city deposit interest for San Francisco, Los Angeles, Berkeley, and the City of Boulder from published figures, and generates an editable itemized return letter in the browser. Nothing the user types leaves their device. Texas, California, Florida, New York, and Colorado are live, each with a return-letter guide. Florida branches under Florida Statutes section 83.49 (a 15-day full return, or a notice of intention to impose a claim within 30 days after the tenancy ends when any amount is kept) and adds a dedicated claim-notice guide. New York has a 14-day deadline from the day the tenant vacates under General Obligations Law section 7-108, covering both the itemized statement and the return of the balance, and adds a dedicated guide to its rent-stabilized deposit rules. Colorado, under its 2026 rewrite (House Bill 25-1249, effective January 1, 2026, which many landlord guides still show under the old rules), has a 30-day return deadline by default under C.R.S. sections 38-12-101 to 106 that a lease may extend to 60, a deposit cap of two months' rent, an exclusive four-category deduction list with nothing charged for normal wear and tear, and treble damages plus attorney fees for a wrongful withholding; it adds guides on normal wear and tear and on deposit limits. General information, not legal advice. Live at https://deposit.orygn.tech ## Open Source - [CI Evidence Pack](https://orygn.tech/products/ci-evidence-pack): CLI tool that generates tamper-evident evidence packages from CI/CD pipelines. GitHub: https://github.com/OrygnsCode/ci-evidence-pack - [Entra OAuth Consent Auditor](https://orygn.tech/products/entra-oauth-consent-auditor): CLI tool that detects risky OAuth consent grants in Microsoft Entra ID tenants. GitHub: https://github.com/OrygnsCode/Entra-OAuth-Consent-Auditor - [Entra Credential Sentinel](https://orygn.tech/products/entra-credential-sentinel): CLI tool that monitors service principal credential expiry in Entra ID. GitHub: https://github.com/OrygnsCode/Entra-Credential-Sentinel - [Zombie Account Hunter](https://orygn.tech/products/zombie-account-hunter): CLI tool that finds inactive accounts and unused licenses in Entra ID tenants. GitHub: https://github.com/OrygnsCode/zombie-account-hunter ## Research - [Research](https://orygn.tech/research): Independent research published by Orygn. - [The Recipe Is the Fingerprint: Creator Deanonymization from Default AI-Image Metadata at Scale](https://orygn.tech/research/png-residue): Privacy and AI-image forensics study. Every mainstream AI image generator writes the full generation recipe (base model, LoRAs, sampler settings, negative prompt, software build) into the PNG as cleartext by default, without the user's name. Across 15.7 million public AI images and about 92,000 creators on Civitai, that recipe alone is a behavioral fingerprint that identifies a single creator from one image 55.8 percent of the time, with no account or server. Ordinary users who own no custom assets are still identifiable 51 percent of the time, most often through the negative prompt they reuse. On DiffusionDB, where a shared bot homogenizes the recipe, the same method reaches only 1.8 percent, so anonymity is a property of metadata verbosity, not of whether a username is attached. Only stripping all free text, all resource identifiers, and the build string together drives identification below one percent. Disclosed to the tool developers and platform before publication. By Daniel Okwor, Orygn LLC. Full paper on Zenodo: https://doi.org/10.5281/zenodo.21500861 - [From Hallucination to Registration: Do the Package Names That LLMs Invent Actually Get Claimed?](https://orygn.tech/research/slopsquatting): Software supply-chain security study of slopsquatting. Five open-weight code models generate 6,800 samples and invent 1,641 distinct package names absent from npm and PyPI; the invented-name space does not saturate. Re-checked live, all 1,641 are still unregistered. Of 149 previously reported hallucinated names, 22 are registered and zero are malicious (19 trace to a single anonymous benign-placeholder operation). The install-time execution primitive is confirmed in a sealed offline lab with a benign package. By Daniel Okwor, Orygn LLC. Full paper on Zenodo: https://doi.org/10.5281/zenodo.21199427 - [A Computational Study of Base-b Deletable Primes](https://orygn.tech/research/deletable-primes): Computational number theory study counting deletable primes across bases 3 to 12. Establishes a geometric growth law, explains the even/odd parity split through Euler's totient, and adds 37 new terms to ten OEIS sequences (A096236 to A096245) plus two new sequences (A395332, A395333). By Daniel Okwor, Orygn LLC. Full paper on Zenodo: https://doi.org/10.5281/zenodo.20710618 ## Company - [Homepage](https://orygn.tech/): Overview of Orygn's services and products. - [Capabilities](https://orygn.tech/capabilities): Full list of services Orygn provides. - [All Products](https://orygn.tech/tools): Product showcase with live demos. - [Contact](https://orygn.tech/contact): Contact form to start a conversation. - [GitHub](https://github.com/OrygnsCode): All open-source repositories. - [LinkedIn](https://www.linkedin.com/company/orygn-llc/): Company profile. ## Optional - [Privacy Policy](https://orygn.tech/privacy) - [Terms and Conditions](https://orygn.tech/terms) - [Accessibility Statement](https://orygn.tech/accessibility)