Your trusted partner for the software your business runs on
An engineering organisation that works round the clock on machines you own, on model keys you own, under the merge policy your repository already carries. Every action lands in an append only trail, every comment says it came from a bot, and access is by invitation only.
No hiring rounds, no onboarding, no ramp-up. Consistent senior-level output, around the clock.
No hiring rounds
No job posts, no interview loops, no notice periods, no backfill when someone leaves. You describe the work and the work starts.
No onboarding, no ramp-up
Every AI dev reads the repository before it writes a line, and the context lives in the code and the audit log rather than in one person's head.
Consistent senior-level output
The same standard on a Tuesday morning and a Sunday night: planned, written, reviewed and merged through gates that are machines, not moods.
01The boundary
Your machines. Your keys. Your gates.
We sell orchestration, judgement and the trail. We never resell inference, and we never run the coding agent on our own hardware for a paying customer.
You ownYour boxes
The machines, the keys and the policy
Where it runs
Your own VMs. The runner dials out to the control plane and opens no inbound port.
When it runs
Round the clock. It pulls the next task and streams every event back while you sleep.
Whose model keys
Yours. Every supported provider, plus any OpenAI-compatible endpoint. We never resell tokens.
Who sets the merge policy
Your own .maintainer.yml. Turn auto-merge off, or route a lane through a human, and that is the policy.
Who ships to production
Your own pipeline, after the merge. We do not operate your deploy.
We ownOur servers
Orchestration, judgement and the record
Who decides a merge
One gated merge call. The gate is re-asserted on a fresh read, bound to the commit it validated, and every refusal is a named code.
The record
Append-only and tamper-evident: each row carries the hash of the row before it, so a gap is visible.
Disclosure
Every automated comment says it is a bot. A blank token counts as no token, so it fails toward disclosing.
Other bots
CodeRabbit, Copilot, Dependabot and Renovate are read as signal and never answered. No bot argues with a bot.
The line between what you own and what we are accountable for.
You bring · 01
Access
Repos, APIs, MCP servers and servers. Scoped credentials you can revoke in one move.
You bring · 02
VMs
The boxes the fleet runs on. Developers that do not sleep, on hardware you already pay for.
You bring · 03
AI tokens
BYOK across every supported provider, plus any OpenAI-compatible endpoint.
02Procurement
What your reviewer asks, answered in order
Some of this is built and some of it is not. Each row says which, because you find out either way.
Single sign on
Enterprise SSO routed by your verified email domain. It signs in people who already hold an account in your organisation.
Directory provisioning
Planned
SCIM is on the roadmap and not built. Until it ships, the account exists in your organisation before its owner can sign in, and a sign in with no account behind it is refused and recorded.
Service levels
Planned
We will not quote an availability target we have not signed. The service levels page gets written when there is one to publish.
Data processing terms
For the personal data we process on your behalf, you are the controller and we are the processor, acting on the instructions your installation and your .maintainer.yml express. The addendum names the subprocessors and the transfer safeguards.