Dweve

Contact Dweve | AI, Security & Legal Questions

Use one form for product and business questions. Email security@dweve.com for responsible disclosure or legal@dweve.com for privacy and contracts.

Contact Dweve

Use the form to reach Dweve. Tell us what you need, and we will reply through the email address you provide. Use the form if you are unsure. These addresses are for a security finding or a legal and privacy request.

Want the trace surface or the backend matrix for your workload? Write to hello@dweve.com.

"arnhem, netherlands" # one team builds it all

"declared-boundary" # managed mesh or licensed direct operation

"kera" # self-modifying fusion graph, commercial

"core, loom, nexus, spindle, mesh, aura, fabric"

on github.com/dweve-ai, Rust except Jacquard

sparse mixture, a few active per request

Every report is logged with a timestamp and a tracking reference. No black-hole inbox.

We resolve, credit the reporter where wanted, and close the loop in writing.

We confirm severity and scope, and agree a coordinated timeline with you.

A person acknowledges within 24h on a business day, with a tracking reference.

Email security@ with the affected component, version, and reproduction steps.

Amsterdam workspace planned for 1 November 2026: The Stack, a new AI hub at Jacob Bontiusplaats 9. Post and visits go to Arnhem until then.

Built by a small team in Arnhem, in the Netherlands.

You do not need to know anything technical to talk to us. If you want to try our tools, or you simply want to know who we are, you are in the right place. Here is what matters most.

We will not push you. If you write to ask a question, you get a plain answer. You decide what to do next, in your own time.

We handle contact messages under our published privacy policy. It explains where the message goes and who can access it.

One team in the town of Arnhem in the Netherlands builds the whole thing. When you write to us, a real person from that team writes back.

Whatever you write to us is kept on machines here in Europe, under European law. It is not shipped off to a country you have never heard of.

Your email and your message are not handed to advertisers or anyone else. We use them only to read you and to write you back. Nothing more.

Writing once does not sign you up to anything. You will not start getting a stream of letters you did not ask for. You are in charge.

Your note leaves your computer through a locked connection, like a sealed envelope.

It lands in an inbox kept on machines here in Europe, read only by our small team.

One of us opens it, reads it, and writes you a plain answer. Then it simply rests there.

If you ever want us to forget you, just ask. We delete your details, no questions.

The clearer the brief, the more useful the first call. No canned demo, no scripted discovery.

We leave you the next hour, no forced follow up

Scoping call: reference, pricing band, outline

A person replies with a call agenda and any questions

hello@dweve.com with sector, workflow, framework

An outline of joint work whose output is a written fit assessment, not a sales pitch.

A pricing band for the typical engagement we run in that sector, in writing.

A reference customer in your sector, under NDA at first.

The regulator, audit finding, or deadline that makes this real now, not next year.

The compliance framework already in scope. DORA, NIS2, EU AI Act, MDR, or similar.

The system you want to replace or augment, and what it is replacing.

Coordinated disclosure. We agree a timeline with you and credit you in the fix note on request.

Every report is logged with a timestamp and a tracking reference.

credit on request, named in the fix note

A crafted input that exhausts memory in a single Core kernel path.

denial of service, information disclosure, supply chain pin drift

A deployment configuration that lets one tenant read another tenant trace.

data residency break, cross tenant read, privilege escalation

A path that lets a request mutate a Ledger Merkle root without a signature.

remote code execution, auth bypass, trace forgery

Wrong channel? Send to hello@dweve.com and we forward it to the right owner.

The nature of the request and the relevant article

Data subject rights, processing agreements, and contract questions under EU jurisdiction. The entity is Dutch and data stays inside Europe.

Affected component, version, reproduction steps

Vulnerabilities in the platform, a deployment, or the supply chain. Read by a person, acknowledged within 24h on a business day, handled under coordinated disclosure.

A reproducible case, the repo, the version or commit

Numerus, Reed, BitWeave, Lattice, Twin, FMI, AION, Ledger, Selvedge, Knot, HEDL, Bindery, Winnow, Jacquard. Issues and pull requests live on the repos. All Rust except Jacquard (TypeScript and React).

Workload shape, target tier, the compliance framework in scope

How the commercial suite (Core, Loom, Nexus, Spindle, Mesh, Aura, Fabric) fits your environment, the trace surface, and the deployment posture you need.

One small team, in one town, who answer their own email.

There is no waiting room and no number to take. A real person replies.

If you are nearby, you are welcome to visit, just arrange it with us first.

The easiest way is a short email to hello@dweve.com.

Usually the same day, within a day at most

There is no phone tree and no ticket number, just a short reply from a person who read what you wrote.

However you reach out, a real person here reads it and replies.

Managed Fabric on the public Mesh, or licensed on customer infrastructure, including physically isolated.

Bit-identical replay, seeded, with a trace on every decision.

14 public repos on github.com/dweve-ai, Rust except Jacquard.

Core, Loom, Nexus, Spindle, Mesh, Aura, Fabric.

The real anchors: 528 Loom domain specialists, roughly 408K Core implementations across 12 backends, 25 numeric formats, a 1.36 ns Lattice hot-path lookup, BitWeave at 1.000 recall, HEDL denser than JSON, 14 public repos, and 96% less energy than a comparable GPU stack. Kera, the fusion-graph IR, is commercial.

Never a public issue. Route privately to security@dweve.com.

Fork, branch, run the suite, and the crate maintainer reviews it.

A minimal reproducible case, the version or commit, and the platform.

The open set lives on github.com/dweve-ai, with a licence stated per project, all Rust except Jacquard (TypeScript and React). An issue with a reproducible case is the front door. A focused pull request reaches the maintainer who owns that crate. The one exception is a security finding, which never goes in a public issue, it routes privately to security@.

Coordinated disclosure of a vulnerability.

Issues and pull requests on the 14 public repos.

Architecture, integration, and the trace surface.

The platform, the open source repos, security, and legal each have the channel that owns them. The map below routes your message to the right owner, with what to include. Wrong channel is fine, send to hello@ and we forward it. Nothing is lost by guessing wrong, it only adds a hop, and the person who forwards it is on the same team as the person who answers.

Ack within 24h, triage within 5 business days. Denial of service, disclosure.

Ack within 24h, triage within 2 business days. Residency break, cross tenant read.

Ack within 24h, triage the same business day. RCE, auth bypass, trace forgery.

A published security.txt with the contact, languages, and policy. A severity matrix with the ack and triage window per tier, all acknowledged within 24h on a business day. Findings are logged with a tracking reference and handled under coordinated disclosure, with credit in the fix note on request.

How to reach you, and whether you want public credit.

Your read on severity and scope, so we can triage quickly.

Clear reproduction steps and the conditions under which it triggers.

The affected component or repo, and its version or commit.

security@dweve.com is read by a person, not a queue. Send the affected component, the version, and reproduction steps. We acknowledge within 24h on a business day with a tracking reference, agree a coordinated timeline, and close the loop in writing. Scope covers the platform, a deployment, and the supply chain.

Meander 251, in Arnhem, in the Netherlands. Visit by arrangement.

Usually the same day, and within a day at the most.

On weekdays, in the daytime. We are real people with normal hours.

We work from one office in Arnhem, in the Netherlands. Email us, and if you are nearby, you are welcome to visit, just let us know first.

Ask us to forget you and we delete your details, no questions asked.

For this contact form, your message is handled by the team that answers your request. See the privacy policy for details.

Your message travels through a locked connection, like a sealed envelope.

We look after what you send. In plain words: where your message goes, who reads it, and the promises we keep. For this contact form, we use your message to answer your request. See the privacy policy for details. Nothing you write here is added to a marketing list, and nothing is passed to anyone outside Europe.

Asking a question never costs you anything.

For this contact form, we use your information to answer your request. See the privacy policy for details.

Your message is used to answer your request. See the privacy policy for the full details.

Any question about Dweve is welcome, big or small.

In plain words: what you can always ask, and the things we promise will never happen.

There is no rush and no one will chase you for an answer.