
Secure software factory
Every engineering team is rethinking its software factory. Background coding agents now take a ticket and return a pull request, and the teams that adopt them well ship dramatically faster.
We build that factory for you, securely. We deploy open-source background agents such as Open-Inspect in your own cloud, wire them into GitHub, Slack and your ticketing, and harden the whole path from laptop to production around them. Then we can keep it running.
Why it has to be built securely
- Coding agents read your code, run commands and open pull requests. Their permissions are the security boundary, not their prompt.
- Recent npm compromises stole GitHub tokens, cloud keys and SSH keys from developer machines and CI, then used them to spread.
- Long-lived tokens, over-permissioned CI and unchecked dependencies turn one compromise into many.
- Vendor-hosted agents put your code and credentials in someone else’s environment.
How it works
We build and prepare everything along the way. A person always makes the final call before anything moves on.
Lock down the path to production
Source control, CI/CD and package publishing hardened before any agent touches them.
Deploy the agents
Open-Inspect running in your cloud, sandboxed, and connected to your repositories and chat.
Scope their access
Each agent gets only the repositories, tools and credentials its work needs.
Human checkpoint
Your engineers review
Agents open pull requests. People decide what merges.
Keep it running
Monitoring, upgrades and tuning as your team and codebase grow.
What we build
Background coding agents
Self-hosted Open-Inspect, open source and MIT licensed, running in your cloud. Agents work from Slack, GitHub, Linear or the web and return pull requests attributed to the person who asked.
Agents that are safe when jailbroken
Sandboxed execution, scoped credentials, repository allowlists and approval gates. We assume an agent can be talked into anything and make sure it cannot do harm.
A hardened SDLC
Least-privilege GitHub or GitLab, protected branches, read-only CI by default, and short-lived cloud access in place of static keys.
Supply chain guardrails
Trusted publishing, provenance, lockfile review and install-time checks for malicious packages.
Developer machines
Secrets out of dotfiles, sensible device and authentication baselines, and a tested plan for a compromised laptop.
Run it for you
Upgrades, monitoring, cost control and tuning, so the factory keeps getting better after launch.
How it comes together
- 01
Harden
Lock down source control, CI/CD and publishing, usually within the first one to two weeks.
- 02
Deploy
Stand up the agents in your cloud and connect them to your repositories, chat and tickets.
- 03
Run
Hand it over with documentation, or let us operate and improve it month to month.
What you get
- Tickets that come back as pull requests
- Agents in your cloud, under your policies
- No long-lived credentials in the pipeline
- An operator for the factory if you want one
Further reading: Open-Inspect, the open-source background agent system
Tell us what's stuck.
If we can materially improve the outcome, we'll come back with a concrete first step. On-site in Toronto or remote.