Skip to main content

Platform

The runtime underneath the report

Where the investigation runs, what it reads, and where it is required to stop.
The same engine installs into your own cluster or runs on ours, and neither version can pass the approval boundary on its own.

Runtime surfacedeploymentpipeline stagestrust boundary

How it runs

Choose a deployment model without changing the evidence contract.

Self-hosting via HelmBetaReviewed

Every action is cleared by a person

Production Master proposes changes; a person clears each one — approving that action, or pre-authorising its risk class for a single investigation with a time-boxed, revocable grant.

BetaReviewed

Runs where your evidence lives

Self-host the runtime via Helm inside your own infrastructure, or use the managed service.
The investigation engine is identical.

No host lock-in

The runtime depends on no specific cloud or execution platform.
Hosting choices sit behind explicit interfaces.

Bring your own model keys

Point the runtime at your own LLM provider credentials, or use ours on the managed plans.

From alert to answer

7 stages. The investigation can stop at any of them, and it always stops before production changes. Select a stage to see what it produced in this sample.

Investigation pipeline · checkout-apiPM-SAMPLE-001 · 14:23–14:31 UTC
↑ human approval boundary
Stage 0114:23 UTC

Detect

An alert, a deploy or a direct request opens an investigation and starts gathering evidence from the sources you've connected.

In this sample
checkout-api p99 · 410 ms → 2.9 s
Opens PM-SAMPLE-001, timestamped 14:23–14:31 UTC in this sample.
Stage 0214:24 UTC

Gather

Read-only connectors pull the deploy diffs, metric series, logs and cluster events inside that window.

In this sample
1 commit · 3 series · 2,140 lines · 18 events
Volume and origin are recorded per source, before anything is interpreted.
Stage 0314:24 UTC

Exhibit

Each source becomes a numbered exhibit, with its origin, timestamp and volume recorded alongside it.

In this sample
E-01 · E-02 · E-03 · E-04
From here on, a claim that cannot name an exhibit cannot enter the report.
Stage 0414:26 UTC

Hypothesise

Candidate explanations are written as falsifiable statements that an exhibit could disprove, not as prose.

In this sample
H-01 … H-04
Four candidates, each stated so that a specific exhibit could disprove it.
Stage 0514:28 UTC

Challenge

Each candidate is tested against the exhibits. Rejections are kept, with the exhibit that rejected them.

In this sample
3 rejected · 1 held · cache degradation ✗ E-04
A rejection is a result. It ships with the report rather than being deleted.
Stage 0614:30 UTC

Report

The surviving explanation, its citations, its confidence and the ledger of rejections are assembled.

In this sample
87% sample confidence
Below certainty: the sample neither reproduces the issue nor observes recovery.
Stage 0714:31 UTC

Gate

A remediation is proposed and the investigation stops there. A human decides whether it is applied.

In this sample
A-01 · awaiting approval
Nothing here runs on the system's own authority: a person clears A-01, or pre-authorises its risk class for this investigation.

Stage 01, Detect. An alert, a deploy or a direct request opens an investigation and starts gathering evidence from the sources you've connected.

detect → gather → exhibit → hypothesise → challenge → report → gate · the run always stops before the gate

An agreed path, or no path

Five gates, named before evaluation starts: source, credential scope, evidence, audience, action owner.
Anything outside that agreement stays disconnected.

01
An evidence source you approve
Named per connector, in writing, before anything is connected.
02
A minimum, agreed credential
Scope is minimized and agreed per connector before anything is connected — detail on /security.
03
Evidence gathering
Starts gathering evidence from the sources you've connected.
04
A cited report
Audience agreed in advance, every claim carrying its exhibit.
05
A human approval boundary
Named owner for the next action. Nothing consequential runs until a person clears it.
Shipped
Human approvalBeta
Self-host via Helm, to closed-beta teamsBeta
Not yet published
Encryption, retention and the subprocessor register — status published on /security.
Roadmap
Air-gapped installPlanned
this page is a statement of practice, not a certification · no compliance badges

Run it where your evidence already is

The same runtime installs into your own Kubernetes cluster or runs on ours, and the investigation it performs is the same one either way.

Self-host via Helm — available now to closed-beta teams.