▮ ARI HARRISON
Founder · NovoMCP · the open computational chemistry engine

The system between a model
and a decision that matters.

Getting a model to say something is easy. Building the system so its answer can be acted on is the work: safely, correctly, repeatedly, with a record of what happened. NovoMCP is what I built: the open computational chemistry engine, MCP + REST, Apache-2.0, boots with zero external services. Before it, reinforcement-learning agents for autonomous discovery in high-stakes manufacturing. The domain changed; the systems thinking did not.

01Tools in the engine69
02Run on a fresh clone · zero wiring14
03Autonomous discovery funnel11stages
04Endpoints beat the current TDC #13/22
05LicenseApache-2.0
06Backing · NVIDIA / AWS / Microsoft3
§ Status // current
Building
NovoMCP: the open computational chemistry engine. MCP + REST, 69 tools, self-hostable under Apache-2.0 or run as a per-org cloud deployment. Solo founder.
Shipped
  • Open-sourced NovoMCP at v1.0 (July 2026): engine, compute wrappers, surfaces, and trained models under Apache-2.0; orchestration core BSL 1.1 → Apache 2029-07-12. Boots with no auth, no account, no API key.
  • Shipped through v1.4.0: an ALCHEMI-accelerated axis across geometry, energy, and conformer search (ase ↔ alchemi, crest ↔ alchemi, same tool call, reference path or GPU path chosen per call), plus a pluggable auth / metering / audit spine so the same code runs standalone or hosted.
  • Consolidated ~30 services from Azure to AWS with no customer-visible downtime, then trimmed the hosted footprint to api.novomcp.com for the OSS launch.
  • Three audited wins over the current TDC ADMET #1 (NovoExpert); FAVES V4 compliance API for regulated pipelines; both on ChemRxiv.
  • Published the engine's GPU compute services as standalone open repos: gromacs-md, novomcp-nnp, novomcp-qm.
  • Shipped novomcp-lite, the cheminformatics standalone: 9 zero-config tools, pip install novomcp-lite. Open-sourced NovoMD (MIT): local-first molecular descriptors as library, CLI, Hugging Face MCP, and Docker REST.
Backed by
NVIDIA Inception · AWS Activate · Microsoft Founders Hub
Open to
Product, AI, and 0-to-1 leadership conversations. San Francisco / Bay Area or remote. Production AI systems, MCP-shaped infrastructure, and applied AI where correctness is the requirement. Reach me ↓
§ About

The interesting problem is not getting a model to say something. It is building the system around the model so its output can be acted on: safely, correctly, repeatedly, with a record of what happened. That is the work.

NovoMCP is what I built. One computational chemistry engine, 69 in-silico tools across ADMET, docking, molecular dynamics, quantum chemistry, structure prediction, and compliance, that speaks both MCP (Claude Desktop, Cursor, Codex, Zed, any MCP-compatible assistant) and REST (any pipeline that posts JSON). Two ways to run it: self-host under Apache-2.0 on your own hardware, or a per-org cloud deployment with the FAVES compliance API wrapped around it. Same engine either way.

Engine, never platform (positioning call). Scale-to-zero by default (unit-economics call). Human-in-the-loop via MCP elicitation, not an autonomous agent on someone else's molecules (trust call). Open-sourced as an engine, not a hosted product (moat call: the moat is FAVES compliance, the operated cloud, and the trained models, not the code). See the full product portfolio →

Before NovoMCP: reinforcement-learning agents for autonomous discovery in high-stakes manufacturing. The systems ran continuously, diagnosed their own failures, and improved without intervention. Different domain, same problem shape. The agent is not the product; the system that makes the agent safe to deploy is the product. That is the throughline.

The Stack
The Engine
MCP + REST, 69 tools, 14 always-available on a fresh clone (v1.4.0)
Runs Local
Boots with zero external services. No auth, no account, no API key; audit to ~/.novo/audit.jsonl
Pluggable Spine
Auth · metering · audit swap local ↔ hosted ↔ custom by env flag, same code standalone or operated
Open Compute
RDKit · GROMACS · AutoDock-GPU · OpenFold · Boltz · Gnina · xTB · ANI-2x · AIMNet2 · MACE
License
Apache-2.0 (orchestration core BSL 1.1 → Apache 2029-07-12)
Compliance
FAVES V4 (hosted): 8 jurisdictions, 1,585 structural alerts
Surfaces
MCP · REST · Workbench (v1.5.x) · Chrome ext · Word add-in · dashboard
Verticals
Drug discovery + materials science
Ecosystem
NVIDIA Inception · AWS Activate · Microsoft Founders Hub
§ Decisions // how I decide what to build, cut, and delay
Distribution · MoatD-01

I opened the engine at v1.0.

The straightforward call was to keep it closed and sell a hosted platform. I open-sourced it instead: Apache-2.0 top level, BSL 1.1 → Apache 2029 for the orchestration core. The moat is compliance, the operated cloud, and the trained models. Not the code that calls RDKit and orchestrates docking.

RESULT → Distribution flips from "sign up" to "clone the repo." Adoption compounds where a platform pitch can't reach. Regulated buyers still need compliance under an SLA; that is what they buy.
Positioning · CopyD-02

Engine, never platform.

Platform, OS, infrastructure, orchestration: every competitor uses those nouns, so they collide. I locked the public language to computational chemistry engine, with one test on every sentence: could a competitor put this on their homepage unchanged? If yes, replace the noun.

RESULT → One word does the work of a positioning deck. Sales copy, marketing, the assistant's own prompts. The same word everywhere.
Trust · CutD-03

Killed the autonomous campaign system.

The original product had a campaign / quality-gate schema for autonomous runs. I cut it. Human-in-the-loop via MCP elicitation at every funnel stage replaced it. The user's own assistant prompts them at each gate.

RESULT → Less code, a clearer trust model, and the funnel runs inside the assistant the user already trusts. The audit log is the quality gate now.
Infra · Unit economicsD-04

Scale-to-zero by default.

Every compute service ships with min_replicas = 0. Only the public-path surfaces keep a warm replica. Pre-warm is an opt-in tier capability, not a default cost. I carried the cold-start posture from Azure forward to AWS rather than retrofitting it later.

RESULT → Unit economics stay honest from day one. The bill does not grow with idle.
Go-to-market · PricingD-05

Self-hosted or cloud. No middle.

The prior model had a Free / Core / Scale / Enterprise credit ladder. I killed all of it at the OSS launch. Two paths now: self-hosted, free forever (Apache-2.0) or cloud deployment, contact for pricing (per-org subdomain, SAML SSO, GPU pool, FAVES compliance). No self-serve middle tier.

RESULT → The ladder was noise between the two real buyers: someone who runs the engine, and someone who wants it operated under an SLA. Removing the middle cut decision friction and a lot of billing complexity.
Infra · SecurityD-06

Private-endpoint everything.

EKS API, Aurora, Redis, internal ALBs: all private. The catch is that GitHub-hosted CI runners can't reach any of it, so every kubectl apply times out. Rather than poke holes, I committed to build on GH runners, deploy via OIDC → SSM → bastion, applied uniformly across every NovoServices repo.

RESULT → The pattern does not re-litigate per port. New services pick up a pre-wired bastion for free. Security posture is a default, not an exception.
§ Boundaries // what I don't claim

Stated limits.

A limit named plainly is the strongest credibility instrument available. Nobody fabricates a limitations page. Here is where the work stops.

  • Clinical modelNovoExpert-3 is validated on cardiovascular and GI endpoints, and explicitly out-of-domain on oncology, CNS, and infectious. The model suppresses a number there rather than emit a low-confidence one.
  • ADMET winsThree endpoints beat the current TDC #1 (MapLight+GNN) on AUPRC, margins +0.003 to +0.013. None clears the +0.02 landmark margin. Audited against the live TDC leaderboard, not self-reported.
  • FAVESA screening and liability instrument, not a regulatory sign-off. It returns status, alerts, and provenance; a human owns the submission.
  • WorkbenchShips as open source in v1.5.x. Today it is a design-partner preview, not a public release.
§ Publications // A. Harrison, 2026 · measured, sourced
View all on Google Scholar →
§ Projects // what shipped
Open source · Engine

NovoMCP

One engine, two surfaces (MCP + REST). 69 tools across cheminformatics, ADMET, docking, MD, quantum chemistry, structure prediction, materials science, and an 11-stage autonomous discovery funnel. Clone it and it boots with zero external services; 14 tools work on a fresh clone, the rest unlock as you wire optional compute. A pluggable spine (auth / metering / audit) swaps local ↔ hosted ↔ custom by env flag. Wraps open compute (RDKit, GROMACS, AutoDock-GPU, OpenFold, Boltz, Gnina, xTB, ANI-2x, MACE) and sources its cheminformatics from the open novomcp-lite package (v1.4.0). Apache-2.0 top level; orchestration core BSL 1.1 → Apache 2029.

Hosted · Compliance

FAVES compliance API

The moat around the OSS engine. Regulatory compliance for pharma and biotech pipelines: DEA schedules, EU REACH, PAINS filters, structural alerts, sponsor whitelists, PMDA / KFDA / TGA, plus the operational commitments a regulated submission needs (SLA, immutable audit-log retention, drift monitoring, IQ/OQ/PQ documentation, SAML SSO). Closed and paid; access on request. Not shipped with the OSS engine.

Preview · Workstation

NovoWorkbench

The molecule canvas, 3D viewers, and discovery funnel as a native desktop for macOS and Windows. Local RDKit, offline alert screening (PAINS + druglikeness rule sets), bring-your-own-LLM chat, model-agnostic. Tauri + Python sidecar; Apple Developer ID notarized (team 8N9K9B7Y69). Design-partner preview; ships as OSS in v1.5.x.

Open source · Apache-2.0

novomcp-lite

NovoMCP's cheminformatics, standalone, for people who want the wrappers rather than the whole engine. pip install novomcp-lite: 9 zero-config tools (RDKit properties, profiling, synthetic-accessibility, PAINS/BRENK alerts, library screening, plus ChEMBL / ClinicalTrials.gov / bioRxiv / PubMed literature search), as a Python library or an MCP server. Two dependencies, no keys. The exact code the full engine runs on, so the numbers match. Prompted by a researcher who wired the engine to his agent and asked for a lighter build.

Open source · MIT

NovoMD

SMILES in, 32+ molecular descriptors out, from a real 3D conformer. Geometry, energy, electrostatics, surface, and volume, calculated on your own machine, no account, no API key. Ships as a Python library, a CLI, a Hugging Face MCP endpoint, and a Docker REST service: the one-engine-many-surfaces pattern at library scale, fully open. The design call: scope discipline. No ADMET, no pKa, no binding, documented in the README and shipped as an agent skill so assistants are told explicitly where the tool's authority ends.

Systems · Autonomy

Autonomous Systems

Before NovoMCP: reinforcement-learning agents in high-stakes manufacturing. Continuous operation. Self-diagnosing on failure. Improving without intervention. The architectural pattern is the same one NovoMCP runs on: agents that pursue objectives, not just answer questions. The domain changed. The systems thinking did not.

§ Writing
All writing on Substack →
§ Contact

Open to product, AI, and 0-to-1 leadership conversations.

RESUME: in revision, available on request. // SF / Bay Area or remote.