Project Incubation: Vexum - APPROVED
- Dominant language
- JavaScript
- Stars
- 75
- Forks
- 40
- Avg merge
- 1m
- Merged PRs (30d)
- 5
Description
### Entry Path
Direct Entry (Advanced Contribution)
### Labs Compliance
- [x] I confirm that the codebase continues to meet [Labs Acceptance Requirements](https://community.finos.org/docs/governance/lifecycle-stages/labs/#labs-acceptance-requirements)
- [x] I confirm that the codebase meets [Labs Ongoing Maintenance Requirements](https://community.finos.org/docs/governance/lifecycle-stages/labs/#labs-ongoing-maintenance-requirements)
### Acceptance Checklist
- [x] At least two maintainers from different organizations (one must be a FINOS member)
- [x] Active use by at least two financial services organizations
- [x] At least one detailed end-user adoption story provided
- [x] Consistent adherence to the contribution workflow in CONTRIBUTING.md
- [x] Public roadmap/backlog with target outcomes and timelines is available
### Incubating Acceptance - Evidence
## Maintainers
- Dmitry Grankin (Vexa) — @DmitriyG228
- Peter Smulovics (Morgan Stanley, a FINOS member) — @psmulovics
- Preeti Gupta (Citi) — @preetiagarwal26
## Active use by financial-services organizations
- **A Eurosystem central bank:** self-hosted and live since December 2025 (full data sovereignty). See the adoption story below. *(Name withheld pending the institution's consent to be referenced publicly.)*
- **Morgan Stanley** (FINOS member): committed to run a pilot deployment.
## Detailed end-user adoption story — a Eurosystem central bank
This institution, a Eurosystem central bank, operates under strict security, data-residency, and audit requirements: meeting content cannot leave the bank's own infrastructure, and no third-party cloud or external model may process it. That rules out cloud meeting-AI and makes a self-hosted, open project necessary.
Since December 2025, the bank has run Vexa/Vexum **self-hosted on their own infrastructure (OpenShift)** for real-time transcription, speaker identification, and meeting storage and retrieval. They are now **piloting the agentic knowledge-as-code workspace**, running entirely inside the bank against the bank's own locally-served LLMs. No meeting data or inference leaves the bank's boundary.
## Contribution workflow
Apache-2.0, DCO-enforced, PR-based review per https://github.com/Vexa-ai/vexa-core/blob/main/CONTRIBUTING.md . The upstream project (https://github.com/Vexa-ai/vexa — 2.6k+ stars) has an established multi-contributor track record; vexa-core is the FINOS-targeted contribution under the same workflow.
## Public roadmap
https://docs.core.vexa.ai/roadmap/status (plus /stages and /approach) — staged target outcomes with an honest shipped-vs-planned status tracker.
### Maintenance & Health Commitment
- [x] The Project Team commits to public tracking of all activity using GitHub Issues
- [x] The Project Team commits to maintaining an up-to-date shortlist of 'Good First Issues' or 'Help Wanted'
- [x] The Project Team commits to replying to all community inquiries and issues with reasonable promptness
- [x] The Project Team commits to publicly visible adherence and updates to the project roadmap
- [x] The Project Team commits to pre-release integration with a FINOS-approved dependency and license scanner
- [x] The Project Team commits to build and release processes that use NO private or undocumented steps
- [x] The Project Team commits to presenting a project update once every six months at a public TOC meeting
- [x] The Project Team commits to adhering to Maturity Level 2 of the [OSPS Baseline](https://baseline.openssf.org/)
### Maintenance Readiness - Evidence
The project is set up to fulfill these commitments today:
- Public activity tracking via GitHub Issues on https://github.com/Vexa-ai/vexa-core
- Coordinated-disclosure security policy: https://github.com/Vexa-ai/vexa-core/blob/main/SECURITY.md
- Apache-2.0 with NOTICE; DCO sign-off enforced on all commits (see CONTRIBUTING.md)
- Fully public build/release path — Docker Compose + Makefile, no private or undocumented steps
- Public roadmap with status tracker: https://docs.core.vexa.ai/roadmap/status
Committing to, ahead of / at incubation:
- Add a project-level OpenSSF Security Insights file
- Integrate a FINOS-approved dependency + license scanner into pre-release CI
- Reach OSPS Baseline Maturity Level 2
- Maintain an up-to-date "Good First Issues" / "Help Wanted" shortlist
### Status Badging
- [x] Project Team commits to adopt the [FINOS Incubating badge](https://community.finos.org/docs/governance/lifecycle-stages/incubating#badge) in the README.md once approved
Contributor guide
Assessment
This issue has not been assessed yet.