finos / finos/community

Project Incubation: Vexum - APPROVED

Open
#422 7 comments 0 reactions 1 assignee Claimed by @TheJuanAndOnly99 View on GitHub
contribution
Dominant language
JavaScript
Stars
75
Forks
40
Avg merge
1m
Merged PRs (30d)
5

Description

### Entry Path

Direct Entry (Advanced Contribution)

### Labs Compliance

- [x] I confirm that the codebase continues to meet [Labs Acceptance Requirements](https://community.finos.org/docs/governance/lifecycle-stages/labs/#labs-acceptance-requirements)
- [x] I confirm that the codebase meets [Labs Ongoing Maintenance Requirements](https://community.finos.org/docs/governance/lifecycle-stages/labs/#labs-ongoing-maintenance-requirements)

### Acceptance Checklist

- [x] At least two maintainers from different organizations (one must be a FINOS member)
- [x] Active use by at least two financial services organizations
- [x] At least one detailed end-user adoption story provided
- [x] Consistent adherence to the contribution workflow in CONTRIBUTING.md
- [x] Public roadmap/backlog with target outcomes and timelines is available

### Incubating Acceptance - Evidence

## Maintainers
- Dmitry Grankin (Vexa) — @DmitriyG228
- Peter Smulovics (Morgan Stanley, a FINOS member) — @psmulovics
- Preeti Gupta (Citi) — @preetiagarwal26

## Active use by financial-services organizations
- **A Eurosystem central bank:** self-hosted and live since December 2025 (full data sovereignty). See the adoption story below. *(Name withheld pending the institution's consent to be referenced publicly.)*
- **Morgan Stanley** (FINOS member): committed to run a pilot deployment.

## Detailed end-user adoption story — a Eurosystem central bank
This institution, a Eurosystem central bank, operates under strict security, data-residency, and audit requirements: meeting content cannot leave the bank's own infrastructure, and no third-party cloud or external model may process it. That rules out cloud meeting-AI and makes a self-hosted, open project necessary.

Since December 2025, the bank has run Vexa/Vexum **self-hosted on their own infrastructure (OpenShift)** for real-time transcription, speaker identification, and meeting storage and retrieval. They are now **piloting the agentic knowledge-as-code workspace**, running entirely inside the bank against the bank's own locally-served LLMs. No meeting data or inference leaves the bank's boundary.

## Contribution workflow
Apache-2.0, DCO-enforced, PR-based review per https://github.com/Vexa-ai/vexa-core/blob/main/CONTRIBUTING.md . The upstream project (https://github.com/Vexa-ai/vexa — 2.6k+ stars) has an established multi-contributor track record; vexa-core is the FINOS-targeted contribution under the same workflow.

## Public roadmap
https://docs.core.vexa.ai/roadmap/status (plus /stages and /approach) — staged target outcomes with an honest shipped-vs-planned status tracker.

### Maintenance & Health Commitment

- [x] The Project Team commits to public tracking of all activity using GitHub Issues
- [x] The Project Team commits to maintaining an up-to-date shortlist of 'Good First Issues' or 'Help Wanted'
- [x] The Project Team commits to replying to all community inquiries and issues with reasonable promptness
- [x] The Project Team commits to publicly visible adherence and updates to the project roadmap
- [x] The Project Team commits to pre-release integration with a FINOS-approved dependency and license scanner
- [x] The Project Team commits to build and release processes that use NO private or undocumented steps
- [x] The Project Team commits to presenting a project update once every six months at a public TOC meeting
- [x] The Project Team commits to adhering to Maturity Level 2 of the [OSPS Baseline](https://baseline.openssf.org/)

### Maintenance Readiness - Evidence

The project is set up to fulfill these commitments today:
- Public activity tracking via GitHub Issues on https://github.com/Vexa-ai/vexa-core
- Coordinated-disclosure security policy: https://github.com/Vexa-ai/vexa-core/blob/main/SECURITY.md
- Apache-2.0 with NOTICE; DCO sign-off enforced on all commits (see CONTRIBUTING.md)
- Fully public build/release path — Docker Compose + Makefile, no private or undocumented steps
- Public roadmap with status tracker: https://docs.core.vexa.ai/roadmap/status

Committing to, ahead of / at incubation:
- Add a project-level OpenSSF Security Insights file
- Integrate a FINOS-approved dependency + license scanner into pre-release CI
- Reach OSPS Baseline Maturity Level 2
- Maintain an up-to-date "Good First Issues" / "Help Wanted" shortlist

### Status Badging

- [x] Project Team commits to adopt the [FINOS Incubating badge](https://community.finos.org/docs/governance/lifecycle-stages/incubating#badge) in the README.md once approved

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.