Aunova has landed in Dubai.
We're building Greenblocks: the Digital Building Passport for premium real estate. One continuous digital identity for a development, from off-plan through construction, handover and operations.
Claims connected to evidence, not just renderings and promises.
We'll be exhibiting at IPS 2026, September 7-9, Dubai World Trade Centre. If you're around, come find us.
#Dubai #Greenblocks #PropTech #RealEstate
Aunova Technologies Ltd.
aunova@zaps.lol
npub14ymq...67zr
Aunova just landed $25k in AWS Activate credits for Greenblocks, our Digital Building Passport: developer claims turned into verifiable, comparable data at asset level.
The credits pay for the part that matters. HSM-backed signing and audit records in-region, because a passport is worth exactly as much as the signature on it.
DIFC-incorporated, building in Dubai.
#PropTech #AWS
We ran an agentic security scan against our own website and published the result as something anyone can check.
The scan covered the aunova.ae source at commit 47ddf73, detection stages S1–S9 only, 46 of 51 files, 90.2% coverage. It produced 11 raw candidate findings. 3 survived the tool's own adversarial verification stage. A person read and reproduced all three, and all three were fixed in commit e442cc4 before anything was published: a dev-server setting that disabled Host validation (developer workstation only, never part of the deployed static site), a privacy-request page that asserted an identity check without stating any procedure (closed by publishing the actual procedure, with no backend added), and an empty-string sentinel in our Nostr delivery code that a hostile relay could match to abort one send.
The tool is the Visa Vulnerability Agentic Harness, an open-source agentic SAST pipeline released by Visa under Apache-2.0. Naming it states which program produced the output and nothing more. Visa had no involvement in this scan, in its findings, or in this site.
Read the result modestly. A static marketing site has no accounts, no sessions and no server-side logic, so a short findings list is roughly what the architecture predicts. The claim here is deliberately small. It is not about how good our code is. It is that the audit is checkable rather than asserted: the tool's unmodified output and run manifest, a hash manifest, a signature over that manifest, an OpenTimestamps proof anchoring the hash to Bitcoin, and the three commands to verify each of those yourself. The artifact describes the scanned commit and nothing after it.
Our position elsewhere is that a control is something you can prove ran, not something a document asserts. It seemed fair to apply that to ourselves first, on a target where the stakes are low, before pointing the same pipeline at code where the claim would carry weight.
#AppSec #SAST #AIAgents #OpenSource #Transparency #BuildInPublic
Security audit, 27 July 2026 · aunova.ae · Aunova Technologies
The full record of the 27 July 2026 automated security scan of the aunova.ae source: what was scanned, how it was run, the three findings and their...
Off-plan buyers commit before the finished asset exists. Developers create real value through design, materials, performance and delivery, but much of that value remains difficult for buyers and investors to see and assess.
Greenblocks was created to close that gap.
Greenblocks gives every development a continuous digital identity from project launch through construction, handover and operations. It connects project information to the documents and data behind it, making the asset’s value easier to see, understand and trust.
Our new website brings this vision to life and introduces a new approach to trust infrastructure for premium real estate.
Every building has a physical identity. Greenblocks gives it a digital one.
Explore the new website:
#Greenblocks #Aunova #PropTech #DigitalBuildingPassport #DubaiRealEstate

Aunova Technologies
Aunova Technologies · Digital Building Passport
The Digital Building Passport for premium real estate. Verified building performance, easier to trust and easier to compare.
We are using #nostr as a compliant, secure, and encrypted layer for our contact form!