We design operating systems for teams that deliver.

Urgent work starves strategy. We give teams AI agents they can trust — governed operations that deliver today and protect what matters tomorrow.

Led by Andy Woolterton — two decades in enterprise architecture and AI strategy. Building governed agent systems for insurance and professional services.

Proof in the real world

AFTER-IMAGE (CREATIVE VENTURE)

Built a luxury photography brand from zero using NullProof's own framework. Multi-Clock Work handled strategy, governance, and back-office operations — freeing the founder to focus on client-facing creative work. Live, taking commissions.

Visit After-Image →

PORTFOLIO EXPOSURE RADAR (INSURANCE)

Continuous intelligence for emerging risk. 13 source workflows monitoring regulatory, litigation, scientific, and market signals. Cross-referenced against client portfolios with automated scoring and agent-driven escalation.

See the signal architecture →

NullProof Studio (internal pilot)

Built the operating system that runs this studio. One human, governed AI agents, 90 days from zero to production. 68% reduction in decision latency, >95% compliance rate.

See the operating model →

What we build

GOVERNED AGENT SYSTEMS

AI agents that operate under explicit trust boundaries. Durable event queues, belief graphs, hallucination detection, three-stage validation with supervisor arbitration. The governance isn't bolted on — it's the architecture.

See the operating model →

INSURANCE & RISK INFRASTRUCTURE

Signal monitoring across regulatory, litigation, scientific, and market sources. Claims processing with FNOL routing. Portfolio exposure scoring. Built for brokers and underwriters who need to know what changed overnight.

Portfolio Exposure Radar →

OPEN-SOURCE TOOLING

en-quire: an MCP server for governed markdown and YAML editing. Section-level addressing, RBAC, git-native approval workflows, full-text search. Works in any language. On npm and Docker Hub.

GitHub → nullproof-studio/en-quire

Published thinking

Field notes from building agent systems in production. Not theory — operational decisions, trade-offs, and what we learned.

The Identity Gap: Agent Security's Missing Layer

Published agentic AI stack architectures — five-layer, seven-layer, and nine-layer frameworks in common circulation, alongside Microsoft's own agentic AI roadmap reviewed as of April 2026 — cover compute, models, orchestration, tooling, and observability. None include trust as a named layer. Agents can hold wallets, execute payments, and submit documents - they just can't prove who they are. This paper examines why the identity layer is missing from agent runtimes, how existing standards (W3C DIDs, Verifiable Credentials) can fill the gap, and why the window to build it openly is now.

15 min Mar 2026
Read →

Trust Management for Agent Operations

Every governance framework in use today embeds trust assumptions calibrated on decades of human behaviour. Agents break those assumptions. This paper argues that trust management - the explicit identification, assessment, and governance of trust signals - needs to become a discipline in its own right, with registers, scoring, thresholds, and continuous monitoring, paralleling how organisations already manage risk.

18 min Mar 2026
Read →

en-quire: Governed Markdown Editing for Agent Systems

Agents that manage documentation need more than file access — they need structure, governance, and the ability to edit precisely without reading everything. en-quire gives them that: section-level editing, searchable document structure, and git-native approval workflows, all without imposing a schema on your markdown.

18 min Mar 2026
Read →

The Creative Operations Stack

In a 14-week single-studio pilot, decision latency fell by roughly 68% and no projects went unreviewed. Three integrated frameworks for managing AI-augmented creative work.

10 min Jan 2026
Read →
Studio

Led by Andy Woolterton

Founder, Designer, and Chief Architect. Two decades in enterprise architecture, AI strategy, and creative systems design. Creator of the Multi-Clock Work framework for managing creative operations across time horizons.

TypeScript Node.js MCP SQLite FTS5 n8n Docker DID/VC A2A Protocol
NULLPROOF STUDIO · PRIORITISE WITHOUT MORE MEETINGS MULTI-CLOCK THINKING · FEWER FIRES PROTOCOLS YOU CAN RUN · TOOLS THAT HOLD THE LINE GOVERNANCE BY DESIGN · TRACEABLE DECISIONS NULLPROOF STUDIO · PRIORITISE WITHOUT MORE MEETINGS MULTI-CLOCK THINKING · FEWER FIRES PROTOCOLS YOU CAN RUN · TOOLS THAT HOLD THE LINE GOVERNANCE BY DESIGN · TRACEABLE DECISIONS