Getting a model to say something is easy. Building the system so its answer can be acted on is the work: safely, correctly, repeatedly, with a record of what happened. NovoMCP is what I built: the open computational chemistry engine, MCP + REST, Apache-2.0, boots with zero external services. Before it, reinforcement-learning agents for autonomous discovery in high-stakes manufacturing. The domain changed; the systems thinking did not.
ase ↔ alchemi, crest ↔ alchemi, same tool call, reference path or GPU path chosen per call), plus a pluggable auth / metering / audit spine so the same code runs standalone or hosted.api.novomcp.com for the OSS launch.pip install novomcp-lite. Open-sourced NovoMD (MIT): local-first molecular descriptors as library, CLI, Hugging Face MCP, and Docker REST.The interesting problem is not getting a model to say something. It is building the system around the model so its output can be acted on: safely, correctly, repeatedly, with a record of what happened. That is the work.
NovoMCP is what I built. One computational chemistry engine, 69 in-silico tools across ADMET, docking, molecular dynamics, quantum chemistry, structure prediction, and compliance, that speaks both MCP (Claude Desktop, Cursor, Codex, Zed, any MCP-compatible assistant) and REST (any pipeline that posts JSON). Two ways to run it: self-host under Apache-2.0 on your own hardware, or a per-org cloud deployment with the FAVES compliance API wrapped around it. Same engine either way.
Engine, never platform (positioning call). Scale-to-zero by default (unit-economics call). Human-in-the-loop via MCP elicitation, not an autonomous agent on someone else's molecules (trust call). Open-sourced as an engine, not a hosted product (moat call: the moat is FAVES compliance, the operated cloud, and the trained models, not the code). See the full product portfolio →
Before NovoMCP: reinforcement-learning agents for autonomous discovery in high-stakes manufacturing. The systems ran continuously, diagnosed their own failures, and improved without intervention. Different domain, same problem shape. The agent is not the product; the system that makes the agent safe to deploy is the product. That is the throughline.
~/.novo/audit.jsonlThe straightforward call was to keep it closed and sell a hosted platform. I open-sourced it instead: Apache-2.0 top level, BSL 1.1 → Apache 2029 for the orchestration core. The moat is compliance, the operated cloud, and the trained models. Not the code that calls RDKit and orchestrates docking.
Platform, OS, infrastructure, orchestration: every competitor uses those nouns, so they collide. I locked the public language to computational chemistry engine, with one test on every sentence: could a competitor put this on their homepage unchanged? If yes, replace the noun.
The original product had a campaign / quality-gate schema for autonomous runs. I cut it. Human-in-the-loop via MCP elicitation at every funnel stage replaced it. The user's own assistant prompts them at each gate.
Every compute service ships with min_replicas = 0. Only the public-path surfaces keep a warm replica. Pre-warm is an opt-in tier capability, not a default cost. I carried the cold-start posture from Azure forward to AWS rather than retrofitting it later.
The prior model had a Free / Core / Scale / Enterprise credit ladder. I killed all of it at the OSS launch. Two paths now: self-hosted, free forever (Apache-2.0) or cloud deployment, contact for pricing (per-org subdomain, SAML SSO, GPU pool, FAVES compliance). No self-serve middle tier.
EKS API, Aurora, Redis, internal ALBs: all private. The catch is that GitHub-hosted CI runners can't reach any of it, so every kubectl apply times out. Rather than poke holes, I committed to build on GH runners, deploy via OIDC → SSM → bastion, applied uniformly across every NovoServices repo.
A limit named plainly is the strongest credibility instrument available. Nobody fabricates a limitations page. Here is where the work stops.
First cheminformatics screening system whose full HHS/ONC- and NIST AI 600-1-aligned governance is described in operational detail. Validated 362/362 compounds post-fix across five predetermined tests. A single API call returns regulatory status (DEA / FDA / CWC / EPA / EU REACH), 1,585 structural alerts via RDKit FilterCatalog, BOILED-Egg pharmacokinetic classification, and InChIKey prior-art lookup. ~5 ms live latency, precomputed cache of 122,407,635 documents.
Read on ChemRxiv →Three audited wins over the current TDC #1 (MapLight+GNN) on AUPRC, TDC's standard metric for these endpoints: CYP3A4 Substrate, Carbon-Mangels (+0.013); Clearance Hepatocyte, AZ (+0.011); and DILI (+0.003 to +0.006). None clears the +0.02 landmark margin. CatBoost ensembles with MapLight (2573-bit) and GIN (300-dim) fingerprints, plus Chemprop v2 D-MPNN for DILI.
Read on ChemRxiv →One engine, two surfaces (MCP + REST). 69 tools across cheminformatics, ADMET, docking, MD, quantum chemistry, structure prediction, materials science, and an 11-stage autonomous discovery funnel. Clone it and it boots with zero external services; 14 tools work on a fresh clone, the rest unlock as you wire optional compute. A pluggable spine (auth / metering / audit) swaps local ↔ hosted ↔ custom by env flag. Wraps open compute (RDKit, GROMACS, AutoDock-GPU, OpenFold, Boltz, Gnina, xTB, ANI-2x, MACE) and sources its cheminformatics from the open novomcp-lite package (v1.4.0). Apache-2.0 top level; orchestration core BSL 1.1 → Apache 2029.
The moat around the OSS engine. Regulatory compliance for pharma and biotech pipelines: DEA schedules, EU REACH, PAINS filters, structural alerts, sponsor whitelists, PMDA / KFDA / TGA, plus the operational commitments a regulated submission needs (SLA, immutable audit-log retention, drift monitoring, IQ/OQ/PQ documentation, SAML SSO). Closed and paid; access on request. Not shipped with the OSS engine.
The molecule canvas, 3D viewers, and discovery funnel as a native desktop for macOS and Windows. Local RDKit, offline alert screening (PAINS + druglikeness rule sets), bring-your-own-LLM chat, model-agnostic. Tauri + Python sidecar; Apple Developer ID notarized (team 8N9K9B7Y69). Design-partner preview; ships as OSS in v1.5.x.
NovoMCP's cheminformatics, standalone, for people who want the wrappers rather than the whole engine. pip install novomcp-lite: 9 zero-config tools (RDKit properties, profiling, synthetic-accessibility, PAINS/BRENK alerts, library screening, plus ChEMBL / ClinicalTrials.gov / bioRxiv / PubMed literature search), as a Python library or an MCP server. Two dependencies, no keys. The exact code the full engine runs on, so the numbers match. Prompted by a researcher who wired the engine to his agent and asked for a lighter build.
SMILES in, 32+ molecular descriptors out, from a real 3D conformer. Geometry, energy, electrostatics, surface, and volume, calculated on your own machine, no account, no API key. Ships as a Python library, a CLI, a Hugging Face MCP endpoint, and a Docker REST service: the one-engine-many-surfaces pattern at library scale, fully open. The design call: scope discipline. No ADMET, no pKa, no binding, documented in the README and shipped as an agent skill so assistants are told explicitly where the tool's authority ends.
Before NovoMCP: reinforcement-learning agents in high-stakes manufacturing. Continuous operation. Self-diagnosing on failure. Improving without intervention. The architectural pattern is the same one NovoMCP runs on: agents that pursue objectives, not just answer questions. The domain changed. The systems thinking did not.
Open to product, AI, and 0-to-1 leadership conversations.
RESUME: in revision, available on request. // SF / Bay Area or remote.