Governed AI Engineering
Signed verdicts. Runs in your editor or any terminal. Bring any LLM. Your source code never transits our cloud.
$ thoth "add rate limiting to the API"
→ specify → architect → review → build → test
→ 12 files changed · 9/9 tests passing
Signed verdict
APPROVED · 6 / 6 principles
✓ Ed25519 · Cloud KMS · independently verifiable
Generic AI assistants suggest code into a chat box. Thoth ATO runs a governed cycle inside your editor and emits a signed verdict you can verify, audit, and ship.
Ed25519 + Cloud KMS audit chain. Every cycle outputs a cryptographically signed verdict scoring 6 principles (Security, Cost, Performance, Scalability, Anti-fragility, Extensibility). Anyone can independently verify a verdict against the public key endpoint — no account required.
The Claude Code plugin invokes Claude Code's Write, Edit, and Bash tools. Real files. Real tests. Real git commits — in your editor, on your machine. Your source code never transits our cloud; only orchestration metadata and the signed verdict do, for immutable audit logging.
Run the full cycle on any provider — Anthropic, OpenAI, Google Gemini, Vertex, Ollama, or any OpenAI-compatible endpoint — via the CLI and hosted control plane (no Claude Code required). The Claude Code plugin runs local cycles on Claude; your Judge can still be any provider. Provider choice is independent of your billing tier. Full local multi-provider is on the roadmap.
Signed verdicts plus the KMS audit trail satisfy evidence requirements for EU AI Act high-risk obligations (Aug 2026), Colorado AI Act (Jun 2026), SOC2 Type II, and ISO 27001. Auditors get a verifiable chain — not screenshots.
Your source code stays in your editor.
Your cloud stays yours.
Every change ships with a cryptographically signed, independently verifiable audit trail.
Run it in your editor or any terminal, on any model. Your source and your secrets never leave your machine — only orchestration metadata and the signed verdict do.
For every cycle, Thoth assembles the specialist agents the work calls for — and creates new ones on demand when a task needs an expert it doesn't have yet. The roster grows to fit the job, all under one constitution.
Shapes the system before a line is written.
Holds every change to your constitution.
Proves the change does what it claims.
Speaks the framework your codebase already uses.
Transparent tiers. Global tax handled by our merchant of record.