Hraness writes a component in Rust when a memory bug or a garbage-collection pause there would corrupt state or break a guarantee, and in TypeScript otherwise. Rust offers memory safety without a garbage collector, explicit ownership, and a type system strict enough to rule out many invalid states on its own. It costs slower iteration, a smaller hiring pool, and more ceremony per feature. So the choice is made one component at a time, by asking where that trade pays.
the rule for choosing rust
The places that qualify are few and named: kernels that must not crash while holding other people's state, evaluators that run input the program does not fully trust, and paths where deterministic output has to hold up in a hostile environment.
Everything else stays in TypeScript. Bun's toolchain is fast, the type system covers most of the same modeling, and a crash there costs a failed request rather than a corrupted vault. Rust appears in the portfolio where its guarantees carry weight, and nowhere else.
three places rust pays
vhalla is the largest example: a peer-to-peer workspace whose crates hold cryptographic material, durable journals, and wire state for rooms that persist across restarts. Its cores are no_std and ban unsafe, and the deterministic-core lesson is drawn from this codebase. The ban matters because Rust's safety argument holds only where every unsafe block can be audited, and in the cores there are none to audit.
ALGAL's kernel is the second. Its expression evaluator and its run-record engine must produce identical output on every platform, indefinitely. Writing the kernel in Rust, with the TypeScript runtime as the parity oracle described in its own lesson, is what makes verify a credible offline check. The evaluator compiles to wasm for the Bun side from the same source, so the same rules run in both places.
Oh's memory kernel is the third, and its plan records the reasoning. Other tools build views from this store, so it needs Rust's predictability: no garbage-collection pauses and no memory surprises. Its parity suite covers the port the way ALGAL's covers the runtime.
why the rest stays typescript
The rest of the portfolio is TypeScript by choice: GhostGet's provider orchestration, PeopleBlade's contact graph, the sites, the queues, and the release promotion workflows. These layers mostly wait on network and disk. Rewriting them in Rust would buy memory safety the work does not need and cost iteration speed it does. Their typical failures, such as a wrong API call, a bad parse, or retries in the wrong order, are better handled by parsing outside values from unknown and by keeping a claims ledger.
The line falls between memory risk and logic risk. xcb's Rust core and ALGAL's unsafe bans sit on the memory side; GhostGet and the product sites sit on the logic side. Each repository records its own choice.