# Secure software factory

Every engineering team is rethinking its software factory. Background coding agents now take a ticket and return a pull request, and the teams that adopt them well ship dramatically faster.

We build that factory for you, securely. We deploy open-source background agents such as Open-Inspect in your own cloud, wire them into GitHub, Slack and your ticketing, and harden the whole path from laptop to production around them. Then we can keep it running.

## Why it has to be built securely

-   Coding agents read your code, run commands and open pull requests. Their permissions are the security boundary, not their prompt.
-   Recent npm compromises stole GitHub tokens, cloud keys and SSH keys from developer machines and CI, then used them to spread.
-   Long-lived tokens, over-permissioned CI and unchecked dependencies turn one compromise into many.
-   Vendor-hosted agents put your code and credentials in someone else’s environment.

## How it works

We build and prepare everything along the way. A person always makes the final call before anything moves on.

1.  ### Lock down the path to production
    
    Source control, CI/CD and package publishing hardened before any agent touches them.
    
2.  ### Deploy the agents
    
    Open-Inspect running in your cloud, sandboxed, and connected to your repositories and chat.
    
3.  ### Scope their access
    
    Each agent gets only the repositories, tools and credentials its work needs.
    
4.  Human checkpoint
    
    ### Your engineers review
    
    Agents open pull requests. People decide what merges.
    
5.  ### Keep it running
    
    Monitoring, upgrades and tuning as your team and codebase grow.
    

## What we build

-   ### Background coding agents
    
    Self-hosted Open-Inspect, open source and MIT licensed, running in your cloud. Agents work from Slack, GitHub, Linear or the web and return pull requests attributed to the person who asked.
    
-   ### Agents that are safe when jailbroken
    
    Sandboxed execution, scoped credentials, repository allowlists and approval gates. We assume an agent can be talked into anything and make sure it cannot do harm.
    
-   ### A hardened SDLC
    
    Least-privilege GitHub or GitLab, protected branches, read-only CI by default, and short-lived cloud access in place of static keys.
    
-   ### Supply chain guardrails
    
    Trusted publishing, provenance, lockfile review and install-time checks for malicious packages.
    
-   ### Developer machines
    
    Secrets out of dotfiles, sensible device and authentication baselines, and a tested plan for a compromised laptop.
    
-   ### Run it for you
    
    Upgrades, monitoring, cost control and tuning, so the factory keeps getting better after launch.
    

## How it comes together

1.  01
    
    ### Harden
    
    Lock down source control, CI/CD and publishing, usually within the first one to two weeks.
    
2.  02
    
    ### Deploy
    
    Stand up the agents in your cloud and connect them to your repositories, chat and tickets.
    
3.  03
    
    ### Run
    
    Hand it over with documentation, or let us operate and improve it month to month.
    

## What you get

-   Tickets that come back as pull requests
-   Agents in your cloud, under your policies
-   No long-lived credentials in the pipeline
-   An operator for the factory if you want one

Further reading: [Open-Inspect, the open-source background agent system](https://backgroundagents.dev)

## Often paired with

-   [Secure Infrastructure](/services/secure-infrastructure)
-   [Forward-Deployed Security Engineering](/services/forward-deployed-security-engineering)
-   [Agentic Penetration Testing](/services/penetration-testing)

## Tell us what's stuck.

If we can materially improve the outcome, we'll come back with a concrete first step. On-site in Toronto or remote.

[Start a conversation](/contact)

---

Source: https://shadesec.com/services/secure-software-factory
