How it’s built

The receipts, not a wall of logos.

A product that sells audit evidence should be able to show its own. Here is who wrote what, what has to pass before anything ships, and the stack it all runs on.

How it was built

Built by AI, reviewed by a human, verified by tests.

We’d rather show you the receipts than a wall of logos. Here is who wrote what, and what had to pass before it shipped.

Claude Opus 5
Control engine

Built the Azure detection library and the run pipeline — 247 registered controls, 689 automated tests.

689 tests
Claude Fable
Security audit

Audited the codebase and database before launch: 7 critical and 17 high findings, all remediated and re-verified against the live database.

22 / 22 posture checks
Antigravity
Delivery pipeline

Wired the CI/CD: vulnerability scans, typecheck, tests and a from-zero database security gate that every deploy must clear.

16 DB assertions
Human review
Product & architecture

Scope, priorities, and the calls that matter — including the decision to report unverified controls honestly rather than pad the score.

every merge

Built on

No exotic stack. Nothing you can’t audit yourself.

Boring, well-understood infrastructure — because the product’s whole job is to be trustworthy. Every deploy is scanned, gated by tests, and reproducible from source.

  • Microsoft AzureResource Manager + Graph
  • PostgreSQLRow-level security
  • DockerReproducible images
  • GitHub ActionsGated deploys
  • TrivyImage + filesystem scans
  • Let's EncryptTLS, auto-renewed
  • TanStack StartReact 19, server-rendered
  • Node.jsEngine runtime

See what it finds in your tenant.

Connect a read-only service principal and the first evidence run completes the same day.