Why this exists
Agents crossed from suggesting to acting. The controls did not arrive with them.
That gap is the whole reason this company exists. If what you are weighing up is whether to trust a small vendor with work that matters, this page is the evidence: why it was built, what we refuse to do to win you, how our own gates have already stopped us, and exactly where we are today.
The problem
The gap is not intelligence. It is control.
Every business now has AI that can write, summarise and answer. Very few have AI they would let act — send the message, issue the refund, change the record, ship the code. The models got good enough to be trusted with the work somewhere around the point that nobody had built the layer that decides what they are allowed to do with it.
The industry closed that gap in three ways, and all three fail the person who has to sign for the outcome. Some hand the agent broad access and add a log, which tells you what happened after it has happened. Some wrap every step in a rigid workflow and call the model step an agent, which is a script with better manners. Some sell a second product to stand in front of the first, which is a reasonable business and an admission that the runtime underneath was never built for this.
The fourth option is to put the control inside the runtime that executes the work. An action is classified before it runs. An unattended agent is capped below anything irreversible. Anything that publishes, pays, deploys or deletes waits for a named person. Every decision, including every refusal, is written down. None of that is a prompt instruction, because a model can be argued out of a prompt instruction and that is exactly what every published jailbreak demonstrates.
Autonomy where it is safe. A human where it is not. We would rather build the boring layer under the exciting one.
Principles
Six lines that decide what gets refused.
They are lifted from our own engineering foundations, where they have been governing what gets built and what gets turned down since long before there was a website to put them on. If one of them is wrong for your business, you will find that out on the first call rather than in month four.
Useful before impressive
A demonstration that lands and a workflow that survives a Tuesday are different products. You get the second one, and the first happens by accident.
Security before scale
Growth that outruns the controls is the failure mode of this entire category. Work has been turned down for this reason and will be again, including yours if it comes to that.
Clarity before cleverness
If a mechanism cannot be explained to the person who will be accountable for it, it is not finished, however elegant it is underneath.
Proof before trust
Anything asserted here should be checkable by you. That is why the tier table is published rather than described, and why the security page leads with what we do not hold.
Human dignity before automation
Automation should take the repetitive part and hand people the part that needs judgement. A system that quietly moves the blame to a person without moving the authority is a bad system.
Grow the system, do not fragment it
Every new capability joins one operating system with one set of rules, rather than becoming your fourteenth tool with its own login and its own idea of who is allowed to do what.
How we work
The gates you would be trusting have already stopped us.
Most of this platform is built by agents running on the platform, under the same gates you would be buying. They work inside scoped worktrees, they cannot promote their own work, and every substantive change is checked by a different model family from the one that wrote it before a goal can close — live today for governed software delivery, and being productised for general business work.
Between 28 June and 18 September 2026, 214 machine-built changes were promoted into this codebase through that worker, across three model vendors. That is internal engineering work with one operator watching it, and it is worth exactly as much as that sentence says: it is not a customer result, and we are not going to dress it as one.
It buys you one thing that matters. The gates get exercised every day by the most demanding user they have, rather than first meeting real pressure on your deployment. They have stopped our own launches, in writing, including one where every automated check was green and a second opinion found the defect anyway. The platform was rebuilt once, at real cost, on the lesson that agent speed amplifies good architecture and bad architecture equally.
The four refusals
What we will not do to win your business.
A list like this is only worth reading if each line has cost something. Each of these has, and each one is a thing you can check rather than take on faith.
Claim an attestation we do not hold
Not in copy, not in a deck, not in the softened phrasing on a call that means the same thing. The security page lists every certification you are likely to ask for and the word beside each one is the same word: no. When that changes, the page changes, and not a day earlier.
Name a client without a signed release
There is no logo wall on this site, and the absence is deliberate rather than unfortunate. A name, a sector, a channel, a workflow shape or a metric can all identify a business that did not agree to be identified. Yours would get the same treatment. What we publish instead is the method — how we measure, what our gate required, what it refused.
Publish a number we cannot source
Every figure on this site traces to something we can put in front of you. Where the honest answer is a method rather than a number, we print the method and accept that it is less exciting. The claims on each page are checked against a register at build time, and a page that claims something the register does not carry does not ship.
Let an agent take an action a person should own
Not to hit a demonstration deadline, not because a customer asked for it, and not because the model was very confident. This is the one that is not a marketing position: it is the product, and the moment we make an exception for ourselves the rest of this site becomes decoration.
Who you would be dealing with
Small enough that the person who answers wrote the thing you are asking about.
There is no leadership grid on this page and no account manager between you and the engineer who built the policy layer. A hard question gets a real answer the same day, and a defect found on Tuesday tends to be fixed on Tuesday, because nothing has to cross three teams to get there.
The same size has a cost, and you should price it in: few clients can be taken on at once, and you would be early enough to meet rough edges nobody has met yet. That is the trade. It is why the deal is a design partnership rather than a licence, and why we will tell you plainly when your workflow is not one we should take.
A wall of headshots would be the first thing on this site written to impress rather than to inform.
The honest position
What you would be buying into today.
One client deployment. Our own company, run end to end on the product. No third-party security attestation. No public sign-up yet: what that would get you is a trial and a documentation site, and we would rather put a system live with you than hand you both.
If what you need is a vendor with fifty logos and a certificate this quarter, this is not that vendor, and a sales call will not change it. You will hear that in the first ten minutes rather than the fourth meeting.
The buyer this suits is the opposite kind: one workflow that genuinely matters, an appetite for being early, and a willingness to argue about where the line between the agent and the person should sit. You shape the system, we build it with you, and the governance defaults for your industry get written once, properly, by people who have to live with them.
Start with the workflow, not with us.
A fortnight, and your own numbers: how long people wait, what never gets answered, which share an agent could take, and which actions should stay with a person. If you would rather shape the system than buy one, write “design partner” in the first line of the form.
Five multiple-choice questions. A person replies within one business hour.
Useful before impressive. Security before scale. Proof before trust.
