What the agents
actually run on.
A multi-tenant control plane on Postgres, an orchestrator for long-running workflows, streaming chat, and workers for ingestion and deployment. Every write is idempotent and every consequential action is audited.
Eight moving parts, each with an owner.
“The AI does it” is not an answer a security review accepts. Every capability names the accountable agent and the endpoint it lives behind.
One question per turn, driven by what is still missing. Every extracted requirement cites the phrase it came from.
POST /intakes/:id/messagesDeterministic rules establish a floor and always persist; the model is merged additively above a confidence floor, and can never remove a signal the rules found.
POST /intakes/:id/classifyJSON Schema served from the backend so the form is generated once, and its answers feed pricing directly.
GET /schemas/cv_prereqsPublished formula, integer cents, basis-point multipliers. Computes from stored requirements, no client-supplied amount.
POST /projects/:id/estimateThirteen fixed sections, versioned in object storage, issued for signature with signer tracking.
POST /projects/:id/contractCard, ACH, wire or purchase order. Kickoff blocked in code until webhook-confirmed. Idempotent writes.
POST /projects/:id/checkoutRepos, IaC and pipelines generated, then deployed to the target you specified. Acceptance suite before handover.
POST /projects/:id/kickoffHealth, agent activity, spend and audit history from the moment the system is live. CSV and PDF export.
GET /projects/:id/telemetryThe delay is rarely the engineering.
Discovery, proposal writing and procurement consume the calendar before anyone writes code. That is the part the agents remove.
Built to survive a vendor risk review.
Postgres is the system of record. Redis carries cache and locks. Artifacts are versioned in object storage. Chat streams over SSE. Everything is packaged for Docker and Kubernetes, including offline bundles.
Baseline, not roadmap.
SAML and OIDC against your identity provider, with role-based access and workspace separation per org.
Every login, connector grant, signature, payment and deployment action is recorded and exportable.
Encrypted at rest across database and object storage, and in transit over TLS throughout.
Connector credentials are held encrypted under KMS and scoped per organisation and project.
Configurable retention per organisation. Delete connectors and derived indexes on request.
Cloud, private VPC, on-premise or edge. Docker and Kubernetes first, air-gapped supported.
{"error": {"code": "UNAUTHORIZED""message": "Invalid webhook signature""correlationId": "ad7d4b51-35a5-4d68-8ec5-daa21e593fca"}}
Put it through your security review.
We will walk your team through the architecture, the audit model and the deployment options before you commit to anything.