Software built and operated by Kodebeat
Each product is available hosted, by subscription, or licensed per seat, and is built and operated in-house.
Hosted and licensed
Operated by Kodebeat, or licensed to run inside your own estate.
A managed cache and WAF in front of your serverscastellan
Declared sites are rendered into edge configuration by a control plane and applied by an agent on each node. The edge is nginx-lua with both WAF modules in front of go-proxy-cache and Redis, and Terraform lands the same shape on any of the five major providers.
- A node never takes itself out of service: a bundle that fails validation is restored and the node keeps serving
- One setting moves the whole WAF, rate limiting, bot scoring, geo rules and signatures, between off, log only and block
- A purge is a durable record queued per site, so a node that was rebooting applies it when it returns
Your cluster audited against twelve compliance frameworks, in one PDFephemera
A read-only posture and compliance audit for a cluster, taken from an uploaded dump or a read-only CLI run against the live cluster. No agent is installed. Results arrive in minutes as a single board-ready PDF, with every finding mapped to the framework that asks for it.
- Findings mapped across twelve frameworks. ISO 27001, NIS2, NIST CSF, SOC 2, the EU CRA and GDPR among them, with remediation drafts attached
- Processing stays in the region you pick, and the raw side, cluster dumps, findings, PDFs, deletes itself after 24 hours
- What survives that deletion is the aggregate: scores and trends, so the dashboard still shows whether you are getting better
One scorecard across every repository you own, and which way it is movingproofhouse
Portfolio-wide security and quality posture across every repository an organisation owns. Teams run gandalf in their own CI and push the JSON run record here, where it is stored, projected, aggregated and trended.
- Nothing runs your code on this side: no clone credentials, no scanner licences, near-zero compute
- A gate whose scanner was missing is reported unavailable rather than counted as a pass, so the score cannot flatter you
- Cross-repo finding groups built on gandalf's versioned fingerprints, so suppressing something once settles it everywhere
A dated log of restores that actually completedlastresort
Evidence that your backups restore, produced on a schedule. A backup is fetched, restored into an isolated container with no route out, and checked against the questions you declared it should answer. The dated record is kept either way.
- The scratch container has no external egress, so a restored copy full of live credentials cannot call anything
- A failed check exits non-zero, which means cron and CI can act on it without a human reading a report
- The dated record is an evidence pack an auditor, a customer or an insurer can be handed
Scheduled failure drills, with a dated record of what survivedfiredrill
Failure drills on a schedule against a namespace or a compose stack: pods killed, disks filled, DNS withheld, certificates expired, each scored as survived, degraded or failed with the time to first impact. Every run leaves a dated record beside Lastresort's restore log.
- A fixed set of failures and thresholds, so the score compares run to run
- Each mode carries a declared blast radius and a stop condition
- The dated record is what resilience-testing obligations ask a supplier to show
One ordered list of everything about to expirestillvalid
Certificates, domains, tokens, licences and secrets expire, and each is recorded somewhere different. The dates are discovered across those systems and ranked by what breaks when they pass, not by how soon they arrive.
- Ranked by consequence: a staging certificate and a payment gateway's are not the same nine days away
- Discovery runs on a cadence, so a thing nobody registered still turns up before it lapses
What the dependency bump did, and what is worth catching up withboneyard
A reviewable account of what a dependency bump actually changed: major jumps, licence changes, downgrades and newly-added transitive packages, each with the reason it matters.
- Two axes rather than a list: drift measured in libyears, viability from maintainer activity, release cadence and archived status
- Per pull request in review, and per quarter across the whole portfolio, from the same data
Every SaaS seat nobody has used in ninety days, with the money attachedlicensereap
iam-shrink's method applied to licences: the identity provider's people crossed with each vendor's usage, per tool, to list the seats paid for and unused, priced from the contract and ready to reclaim.
- Leavers still holding seats, seats never used, tiers bought for one feature, tools that duplicate each other
- Where a vendor exposes no last-login, the seat is reported as unverified rather than counted
The cloud bill, explained in writing every month, against the budget that was setcloudledger
cost-diff run on a schedule against a declared budget, with every movement attributed to a team, a service or a dated change, and written up for the finance partner who will not open a console.
- Spend that no tag, team or ticket accounts for is reported as one number, which is the finding
- The report is the deliverable; the numbers travel with it for anyone who wants to check
An internal developer platform with your name on itpaved
Backstage in front, Argo CD and Crossplane behind, on Kubernetes. Every brand-dependent value is read as the app renders, so one container image serves any number of brands and a rebrand is a config change and a pod restart.
- A tenant is one object: namespace, quota, default-deny networking, RBAC, a scoped Argo project and a Vault path
- Nothing in the repository is a secret, every credential is generated at bootstrap
- Kyverno guardrails with assertions pinning what each policy allows, rejects and exempts
The management questions you cannot ask anyone at workmanager-os
A private space for the situations that cannot go to your team or your boss: answers drawn from a library of management playbooks, and guided tools that turn a short form into a finished document. Every playbook quoted is shown alongside the answer.
- Each account is encrypted under its own key, and deleting the account destroys that key
- The model is never asked to recall management practice from memory
Briefings assembled from primary sourcesnewsletter-stack
Eight topics, each watching one machine-readable feed and sending only what moved: open roles, regulatory diffs, dependency advisories, new packages, end-of-life dates, public incident reports and cloud pricing changes.
- Every issue is public, so a reader can see a few before subscribing to any
- One subscription page per topic, each listing the sources it reads
Desk tools
Run on your own machine, with no hosted component.
Many coding agents, each in its own worktreefleetmux
A control surface for running many coding agents at once: each isolated in its own worktree, ranked by which are blocked on you, capped by a spend budget, and scored by quality gates before the diff reaches you. Built as an addon over opencode.
- A worker per git worktree, with an urgency-ordered fleet view that reads without colour
- Quality gates score the work and feed their findings back to the agent
- A daemon underneath, so the terminal and the browser cannot disagree
A graded mock interview, run on your own machinemockterview
A realistic technical interview, conducted and graded on your own machine by a single binary. One model interviews against a rubric it never reveals; a second scores the transcript against that rubric and quotes your answers back.
- Two passes, two models: one interviews, one grades
- Transcripts and scores stay in a SQLite file on your machine
- Roles and rubrics are editable YAML, so a team can write its own
Real bugs in real codebases, solved in a terminal, graded against how the maintainer fixed themproddojo
A running environment in the browser, a bug report in a customer's words, and the project's own tests. A second model grades the fix against the commit that closed the bug for real, and shows that commit beside yours.
- Challenges drawn from open-source fixes under permissive licences, credited on each
- Teams get challenges built from their own repositories as the onboarding track
- A team track for teams shipping with agents: fifteen-minute drills from their own code and incidents, a model that tutors and never solves, and a map of which modules anyone still understands
The stack for what you are building, with the free tiers' real limits and the wiring already donegroundwork
A free picker that turns a description of a product into a stack of services with each free tier's real ceiling, a directory page per service kept to the same numbers, and a licensed starter kit with those services already wired to each other.
- One typed SDK over sign-in, billing, email, flags, storage, jobs and the admin panel
- Credentials generated at bootstrap and kept out of the repository, the way Paved bootstraps a tenant
Where this goes next
Every product here carries a paper: the problem it measures, the method behind it, and what it deliberately does not do. The whitepapers are where that thinking is written down.
Read the papers