Secure software factory

Every engineering team is rethinking its software factory. Background coding agents now take a ticket and return a pull request, and the teams that adopt them well ship dramatically faster.

We build that factory for you, securely. We deploy open-source background agents such as Open-Inspect in your own cloud, wire them into GitHub, Slack and your ticketing, and harden the whole path from laptop to production around them. Then we can keep it running.

Why it has to be built securely

  • Coding agents read your code, run commands and open pull requests. Their permissions are the security boundary, not their prompt.
  • Recent npm compromises stole GitHub tokens, cloud keys and SSH keys from developer machines and CI, then used them to spread.
  • Long-lived tokens, over-permissioned CI and unchecked dependencies turn one compromise into many.
  • Vendor-hosted agents put your code and credentials in someone else’s environment.

How it works

We build and prepare everything along the way. A person always makes the final call before anything moves on.

  1. Lock down the path to production

    Source control, CI/CD and package publishing hardened before any agent touches them.

  2. Deploy the agents

    Open-Inspect running in your cloud, sandboxed, and connected to your repositories and chat.

  3. Scope their access

    Each agent gets only the repositories, tools and credentials its work needs.

  4. Human checkpoint

    Your engineers review

    Agents open pull requests. People decide what merges.

  5. Keep it running

    Monitoring, upgrades and tuning as your team and codebase grow.

What we build

  • Background coding agents

    Self-hosted Open-Inspect, open source and MIT licensed, running in your cloud. Agents work from Slack, GitHub, Linear or the web and return pull requests attributed to the person who asked.

  • Agents that are safe when jailbroken

    Sandboxed execution, scoped credentials, repository allowlists and approval gates. We assume an agent can be talked into anything and make sure it cannot do harm.

  • A hardened SDLC

    Least-privilege GitHub or GitLab, protected branches, read-only CI by default, and short-lived cloud access in place of static keys.

  • Supply chain guardrails

    Trusted publishing, provenance, lockfile review and install-time checks for malicious packages.

  • Developer machines

    Secrets out of dotfiles, sensible device and authentication baselines, and a tested plan for a compromised laptop.

  • Run it for you

    Upgrades, monitoring, cost control and tuning, so the factory keeps getting better after launch.

How it comes together

  1. 01

    Harden

    Lock down source control, CI/CD and publishing, usually within the first one to two weeks.

  2. 02

    Deploy

    Stand up the agents in your cloud and connect them to your repositories, chat and tickets.

  3. 03

    Run

    Hand it over with documentation, or let us operate and improve it month to month.

What you get

  • Tickets that come back as pull requests
  • Agents in your cloud, under your policies
  • No long-lived credentials in the pipeline
  • An operator for the factory if you want one

Further reading: Open-Inspect, the open-source background agent system

Tell us what's stuck.

If we can materially improve the outcome, we'll come back with a concrete first step. On-site in Toronto or remote.