Platform access
Start with a new app, an existing repo, or one reviewable PR.
The first conversation is about scope: the product to create, the codebase to continue, or the finding to fix. Do not include source code, credentials, or secrets in this form.
Scope review
Confirm whether the first path starts from a blank product brief, an existing repo, a security finding, or a live PR.
First governed artifact
Create the app scaffold or run one build/remediation task, then review the diff, checks, policy state, preview, and rollback note.
Evidence packet
Inspect hash, timestamp, reviewer state, CI result, and control-family mapping where relevant.
Publish only with approval
Customer artifacts and logos are never implied. They publish only when the customer approves them.
Production submissions require a durable backup sink. If backup is missing, the API refuses the request instead of accepting it silently.
