Platform
The runtime underneath the report
Where the investigation runs, what it reads, and where it is required to stop.
The same engine installs into your own cluster or runs on ours, and neither version can pass the approval boundary on its own.
How it runs
Choose a deployment model without changing the evidence contract.
Self-hosting via HelmBetaReviewed
Read-only by default
Connectors are scoped to read.
Production Master proposes changes; applying one is a separate, human-initiated action.
Runs where your evidence lives
Self-host the runtime via Helm inside your own infrastructure, or use the managed service.
The investigation engine is identical.
No host lock-in
The runtime depends on no specific cloud or execution platform.
Hosting choices sit behind explicit interfaces.
Bring your own model keys
Point the runtime at your own LLM provider credentials, or use ours on the managed plans.
What happens between the alert and the answer
7 stages. The investigation can stop at any of them, and it always stops before production changes. Select a stage to see what it produced in this sample.
Detect
An alert, a deploy, or a request opens an investigation with an explicit evidence window.
Evidence moves only through an agreed path
Five gates, each one named before an evaluation starts — the source, the credential scope, the window, the report audience, and the person who owns the next action.
Anything outside that written agreement stays disconnected.
Run it where your evidence already is
The same runtime installs into your own Kubernetes cluster or runs on ours, and the investigation it performs is the same one either way.
Self-host via Helm — available now to closed-beta teams.