PRODUCTION EDGE / CODECR.ORG14-day VPC sandbox provisioning is open for architecture-qualified teams.
Inspect the release protocol
Enterprise AI code control plane

Govern Every AI Change Before Production.

AI agents are producing code faster than enterprise teams can verify it. codecr validates the architecture before generation, coordinates enterprise context across the delivery stack, and enforces automated security and governance gates before merge.

Review Security Architecture
  • Pre-code governance
  • Private VPC
  • Customer-governed retention

Designed for Fortune 500 software estates · defense programs · regulated fintech

policy-gate / production illustrative
CHANGESET PR #8421 payments/ledger-service 9f3ac2e
  1. Context indexed41 repositories · 186 contracts
    complete
  2. Policy evaluatedFIN-ATOMICITY-02
    complete
  3. P0 condition detectedCross-file concurrency violation
    critical
  4. Merge blockedNamed approval + remediation required
    enforced
01Policy-bound gates
02Cross-repository context
03Isolated analysis
04Audit evidence

[ 01 / CONTROL GAP ]

Generation scaled.
Verification did not.

Across global enterprises, defense programs, and regulated financial systems, agent-generated changes cross repositories, ownership boundaries, data contracts, and control requirements. A diff-level assistant cannot see the system that will absorb the change.

A

Context fragmentation

Repository-local review misses the API, event, schema, and identity boundaries that define real production behavior.

B

Review saturation

Machine-scale code volume overwhelms human queues, turning time pressure into an undocumented risk decision.

C

Unbounded impact

Without automated blast-radius calculation, teams approve changes before they know which systems inherit the risk.

[ 02 / ENTERPRISE FEATURE TAXONOMY ]

One control layer.
Four enforcement planes.

Every review produces an explainable decision backed by system context, explicit policy, and traceable evidence.

PILLAR 01

Cross-Repository Context Fabric

Builds a semantic graph across repositories, symbols, call paths, schemas, service contracts, ownership, and policy.

  • Upstream dependency mapping
  • Downstream consumer analysis
  • Change and ownership provenance
PILLAR 02

Ephemeral Analysis Control Plane

Can run review workloads inside isolated, short-lived sandboxes with customer-defined retention, egress, encryption, and model routing.

  • Customer-selectable zero-retention mode
  • Explicit network boundaries
  • Customer-governed key integration
PILLAR 03

Automated Blast-Radius Governance

Traces changes through APIs, events, data stores, identity boundaries, and regulated workflows before merge.

  • Explainable P0–P3 severity
  • Named accountable owners
  • Enforceable merge decisions
PILLAR 04

Sovereign Deployment & Policy Parity

Designed to maintain the same review engine, policy packs, evidence model, and administrative controls across enterprise environments.

  • Managed private cloud
  • Customer VPC or on-premises
  • Network-isolated deployment

[ 03 / PRE-CODE GOVERNANCE ]

Approve the architecture
before agents write.

codecr converts requirements, legacy-system constraints, and repository context into an approved execution contract. Coding agents receive only the scope, decisions, and acceptance tests required for the phase they are assigned.

01 / CONTEXT GATHERING Evidence indexed

Build the evidence set.

Index legacy repositories, Jira epics, ownership, service contracts, and linked architecture decisions. codecr resolves what the change must preserve before proposing how the work should be divided.

LEGACY REPOS63symbols · contracts · owners
JIRA EPICARC-2416 acceptance criteria
CONFLUENCE ADRADR-77ledger boundary · approved
CONTEXT SEALctx_81c4bf09
02 / PHASED PLANNING Team reviewed

Approve the sequence.

Generate an editable coding plan with dependencies, owners, rollback points, and test gates. Every team edit produces a new plan version; agent execution remains locked until the required reviewers approve it.

plan.v34 / 4 APPROVALS
  1. 01
    Contract compatibility layerOwner · Platform Architecture
    APPROVED
  2. 02
    Dual-write migrationBlocked by phase 01 · rollback required
    APPROVED
  3. 03
    Consumer cutoverRequires compatibility and load tests
    APPROVED
SIGNED PLAN HASHsha256:7e91…0ac4
03 / AGENT HANDOFF Bounded export

Hand off a control contract.

Export a signed, phase-specific prompt to the developer’s approved IDE or cloud agent. The envelope limits readable context, writable paths, permitted tools, required tests, and execution time.

GPT-6 AstraClaude CodeCursor
READ SCOPE
phase-01 context refs
WRITE SCOPE
2 repositories · 8 paths
REQUIRED TESTS
compatibility · rollback
EXPIRES
45 minutes
READY FOR APPROVED AGENTNo credentials embedded · merge authority excluded
ARCHITECTURE CONTROL POINT

codecr does not ask a coding agent to invent the system design. It exports the approved plan hash, evidence references, allowed and prohibited operations, required tests, rollback conditions, and expiration as a bounded execution contract.

[ 04 / ECOSYSTEM CONTROL MESH ]

One control layer.
Your existing stack.

codecr sits between intent, source, agents, CI/CD, and production evidence. It receives only customer-authorized context, stamps every object with provenance, and returns decisions through the system that owns the work.

ENTERPRISE ENGINEERING CONTROL MESH CUSTOMER-AUTHORIZED CONNECTIONS
POLICY + CONTEXT + EVIDENCE codecr Enterprise control graph
01
Source ControlWebhooks + scoped APIs
  • GH
    GitHub EnterprisePRs · checks · ownership
    SCM
  • GL
    GitLab Self-ManagedMerge requests · pipelines
    SCM
  • BB
    Bitbucket Data CenterPull requests · build status
    SCM
02
Knowledge & MCPApproved MCP servers + APIs
  • JI
    JiraEpics · criteria · risk owners
    INTENT
  • CO
    ConfluenceADRs · standards · runbooks
    INTENT
  • SN
    ServiceNow via Model Context ProtocolChanges · CMDB · approvals
    CONTROL
03
TelemetryEvents + evidence links
  • DD
    DatadogTraces · errors · service map
    RUNTIME
  • PD
    PagerDutyIncidents · responders · impact
    RUNTIME
  • SP
    SplunkEvents · detections · audit
    RUNTIME
REQUIREMENT-TO-CODE TRACE

The ticket is part of the security boundary.

When configured, codecr reads approved Jira fields and follows linked Confluence decisions, then binds each requirement to changed symbols, tests, owners, and rollout conditions. If an AI-generated PR compiles but violates the approved business intent, codecr blocks merge and cites the exact requirement that failed.

JIRA / ACC-219Usage cap must remain tenant-configurable.6 acceptance criteria · Product approved
CONFLUENCE / ADR-77No hard-coded billing grace period.Architecture decision · Security owner
6 / 6criteria mapped
!
PR #9104 BLOCKEDHard-coded default contradicts ACC-219 and ADR-77.

Reference connection patterns for the codecr product specification. Availability depends on deployment, vendor edition, customer authorization, connector configuration, and approved API or MCP endpoints. Product names identify interoperability targets and do not imply endorsement or partnership.

[ 05 / LIVE SECURITY PLAYGROUND ]

Watch the control plane
stop a bad change.

Choose a failure mode and inspect the simulated pull request, isolated analysis lifecycle, exact blocking evidence, and bounded remediation handoff. The playground uses synthetic data; it does not connect to a repository or invoke an external agent.

SIMULATED PR ENVIRONMENT HARDWARE-ISOLATED MICROVM NETWORK EGRESS · DENY RETENTION · ZERO SOURCE
pull-request.diff GPT-6 Astra
AI-GENERATED CHANGE

PR #9104 · billing/renewal-orchestrator

agent/usage-proration → main12 files · +284 −73

GOVERNING INTENT Jira ACC-219 · Confluence ADR-77
codecr / microvm ANALYSIS COMPLETE
  1. 01
    Allocate hardware-isolated microVMDedicated kernel · ephemeral memory
    COMPLETE
  2. 02
    Mount read-only PR snapshotSource scope minimized · egress denied
    COMPLETE
  3. 03
    Map intent, policy, and dependencies6 requirements · 4 services · 2 policies
    COMPLETE
  4. 04
    Destroy analysis workspaceDecision evidence sealed · source removed
    DESTROYED
BLOCKING RULEREQ-TRACE-011

Agent introduced a fabricated 45-day default that bypasses the tenant-configured billing contract.

Blast radius
4 services · billing path
Required owner
@billing-architecture
INTERACTIVE PRODUCT SIMULATION

No external model, source-control system, or production service is contacted. Timings and findings demonstrate the intended control workflow and are not performance claims.

[ 06 / ENTERPRISE BENCHMARK REPORT ]

ANONYMIZED FINTECH REFERENCE ARCHITECTURE

Scaling AI Code Governance
at a Global Fintech.

PUBLICATION CONTROL Evidence attachment required

This case-study draft uses buyer-supplied benchmark inputs. Customer attribution, source telemetry, methodology, and written publication approval must be attached before the results are represented as validated outcomes.

01THE CHALLENGE

Agent velocity overwhelmed the human review boundary.

The supplied case-study input reports a 400% surge in weekly pull-request volume as AI coding agents expanded across 1,200 microservices. Review queues became the release bottleneck while cross-repository contracts, payment controls, and ownership evidence remained fragmented.

Estate
1,200 microservices
PR growth
+400%
Risk domain
Payments + identity
02THE IMPLEMENTATION

A policy-bound review plane inside the customer VPC.

The supplied implementation record describes codecr deployed inside an isolated VPC, connected through customer identity, KMS, repository scopes, and private telemetry routes. A signed .codecr.yaml policy set converted security ownership, blast-radius limits, and payment-service controls into enforceable merge gates.

AI AGENTS + SCM1,200 servicesScoped PR events
CUSTOMER VPCcodecr control planePrivate inference · customer KMS
MERGE GATES.codecr.yamlEvidence + owner decisions
82% reduction in PR review queue latency Reported outcome · baseline and comparison windows required
0 critical P0 flaws leaked to production Reported outcome · severity taxonomy and incident evidence required
$4.2M saved annually in developer hours Reported outcome · volume, rate, and attribution model required
BENCHMARK EVIDENCE RECORD Numbers do not become proof until the measurement record closes.
  • 01Baseline and comparison dates
  • 02PR population and exclusion rules
  • 03P0 severity and escape definition
  • 04Developer-rate and attribution model
  • 05Customer publication approval

Claim-control notice: The values above are supplied inputs for an anonymized case-study draft and have not been independently verified. Replace this notice only after the evidence record and customer approval are complete.

[ 07 / ENTERPRISE VALUE MODEL ]

Model the review burden.
Price the risk.

Use your current engineering scale and review economics to build a conservative annual scenario. Every assumption is visible, adjustable during the POC, and excluded from contractual guarantees unless validated against your data.

SCENARIO INPUTUSD · ANNUALIZED
engineers
Engineers participating in pull-request authoring or review.
PRs
Merged, closed, and reviewed pull requests across the in-scope estate.
$ / hour
Use fully loaded cost, including salary, benefits, tax, and overhead.
MODELED ANNUAL IMPACT LIVE SCENARIO
Hours Saved on Code Review 9,624 engineering hours / year
Annual Developer Cost Savings $1,106,760 modeled capacity value / year
Estimated Risk Mitigation Value $592,457 3.3 prevented P0 / production-class incidents
COMBINED MODELED VALUE $1,699,217 before platform fees, implementation cost, or tax effects
MODEL ASSUMPTIONS

48 engineering weeks · 11 minutes saved per PR · 0.35 hours of weekly review-queue recovery per engineer · one P0/production-class escape per 3,500 PRs · 32% pre-merge interception · $180,000 modeled exposure per incident.

Illustrative scenario only. This calculator is not a performance guarantee, insurance valuation, or audited savings statement. Replace assumptions with customer-validated baselines during the 14-day POC.

[ 08 / BUYER EVALUATION MATRIX ]

Compare the control model.
Not the category label.

Several products now provide cross-repository context, AI-generated fixes, or private deployment. codecr is differentiated by binding those capabilities to a single policy, evidence, approval, and deployment-parity model.

Enterprise criterion CONTROL LAYERcodecr AI REVIEWCodeRabbit Enterprise LEGACY SASTSonarQube NATIVE AI ASSISTANTGitHub Copilot
Multi-Repo Context Depth CONTROL-GRAPH NATIVEEstate-wide dependency, contract, ownership, and runtime-path graph built for blast-radius decisions. AVAILABLELinked and automatically linked repositories can contribute cross-repository review context. PROJECT / MONOREPOStrong code analysis across configured projects; not positioned as a live cross-estate change graph. WORKSPACE-DEPENDENTRepository, issue, and agent context; cross-repository depth depends on the selected workspace and tools.
Autonomous Agentic Hotfixes GOVERNED RESOLUTIONPolicy-scoped remediation, isolated branch, full revalidation, and named human merge approval. AVAILABLEAutofix can resolve review findings; its early-access Agent can prepare and open pull requests. SUGGESTED FIXESAI CodeFix proposes fixes for supported rules; application and workflow remain separately governed. CODING AGENTCan implement work and open pull requests; independent security-policy gating must be supplied elsewhere.
True Air-Gapped / VPC Parity PARITY CONTRACTOne policy and evidence model across dedicated cloud, customer VPC, on-premises, and offline enclaves. SELF-HOSTEDEnterprise self-hosting supports private and air-gapped requirements; model and configuration determine the final boundary. ON-PREM COREServer analysis can run on-premises; AI CodeFix service dependencies affect full offline feature parity. REGIONAL CLOUDEnterprise data residency is documented; no equivalent fully air-gapped Copilot service mode is documented.
Custom As-Code Policy Enforcement .codecr.yaml MERGE-BLOCKING POLICYRepository-native rules bind paths, blast radius, severity, owners, signatures, exceptions, and retained evidence. CONFIG + CHECKS.coderabbit.yaml, guidelines, tools, and custom checks configure review behavior; enforcement semantics differ. QUALITY GATESQuality profiles and gates enforce analyzer results through CI and project administration. INSTRUCTIONSRepository and path instructions guide agent behavior; they are not deterministic compliance policy gates.
Guaranteed Zero-Retention Ephemeral Memory CONTRACT-SCOPEDJob-isolated in-memory analysis, source-free evidence, and zero source retention defined in the deployment schedule. SELF-HOSTED OPTIONSelf-hosted Enterprise can opt out of retention; configured LLM routing remains part of the data boundary. FEATURE-DEPENDENTLocal analysis retains customer control; LLM-assisted fixes introduce a separate service data path. PROVIDER ZDRGitHub documents provider-level ZDR for many models, while requests still pass through Copilot service controls.

Procurement note: Publicly documented capabilities reviewed 5 September 2026. Product plans, previews, configuration, and contract terms change; validate each vendor in your own technical and legal diligence.

[ 09 / AGENTIC RESOLUTION PIPELINE ]

Trace the risk.
Resolve under control.

One continuous decision path converts a pull request into system-wide evidence, an enforceable severity decision, and a policy-bound candidate fix.

STEP 01 · GRAY ZONE

Ingest the change. Calculate the blast radius.

codecr resolves the PR against repository topology, symbols, APIs, events, schemas, ownership, and policy. The output is a sealed context graph of every affected service and runtime path.

INGEST / PR #8421CONTEXT SEALED
CHANGESET9f3ac2e18 files
PR 41 repositories 186 contracts 7 services
STEP 02 · RED ZONE

Detect the P0. Expose the dependency path.

Policy engines rank exploitability and production impact, then trace the failure across every dependent system. P0 conditions block merge and name the exact evidence, owner, and remediation requirement.

THREAT / CR-RACE-017P0 · BLOCKED
orchestratorledger-serviceevent busbalance model
!
Double-settlement window2 policy violations · 7 affected services
STEP 03 · CONTROLLED RESOLUTION

Resolve in isolation. Merge only on command.

codecr sends the finding, constraints, and permitted scope to an approved remediation agent, then re-runs every gate against the isolated patch. A named approver invokes Merge Agentic Fix only after policy and human approval conditions pass.

RESOLUTION / ISOLATED BRANCH3 FILES · 1 TEST
01Candidate patchagent/codecr-fix-017
02Policy re-check18 / 18 gates passed
03Named approvalrequired before merge

[ 10 / CUSTOM POLICY GOVERNANCE ]

Security policy travels
with the code.

Security teams define deterministic merge conditions in the repository. codecr evaluates the rule against live blast radius, affected paths, severity, ownership, approvals, tests, and time-bound exception authority.

.codecr.yaml POLICY AS CODE
version: "1"
policy_set: payments-production

scope:
  paths:
    - "services/payments/**"
    - "contracts/ledger/**"
  branches: ["main", "release/*"]

rules:
  - id: PAY-BLAST-004
    description: "Require security approval
      for high-blast-radius payment changes"
    when:
      blast_radius:
        services_impacted_gte: 5
        includes: ["payments-*"]
      severity: ["P0", "P1"]
    enforce:
      decision: block
      require:
        owners:
          - "@security-payments"
          - "@platform-risk"
        signatures: 1
        tests: ["payments-concurrency"]
      exception:
        authority: "@ciso-delegate"
        expires_after: "24h"

evidence:
  retain:
    - policy_decision
    - content_hash
    - approver_signature
codecr bot / PR #8421policy.evaluate
PR Blocked: Policy Violation

$ codecr policy check --pr 8421 --explain

Policy
PAY-BLAST-004
Decision
BLOCK
Blast radius
7 services threshold: 5
Sensitive scope
services/payments/ledger
Required test
payments-concurrency missing
Security owner
@security-payments signature missing
ACTIONABLE FIX RECOMMENDATION

Split the event-contract change from the ledger mutation, restore the atomic settlement guard, and add the payments-concurrency regression test. Then request @security-payments approval; codecr will re-index the blast radius and re-run this rule automatically.

MERGE REMAINS DISABLED

Illustrative configuration syntax for the codecr product specification. Final schema, supported predicates, signing semantics, and enforcement behavior must be versioned and validated before production use.

[ 11 / HIGH-FIDELITY CONTROL PLANE ]

A critical decision,
fully evidenced.

This illustrative PR introduces a cross-file race condition across asynchronous settlement paths. codecr correlates the diff with adjacent repositories and demonstrates an enforceable merge decision at the policy boundary.

CHANGE CONTROL
Reference tenant EU PRIVATE VPC MODEL
SAMPLE · 1 P0 BLOCKED
ILLUSTRATIVE CRITICAL REVIEW

PR #8421 · payments/ledger-service

feat/async-settlementmain

COMMIT9f3ac2e OWNERPayments Platform MERGE BLOCKED

GRAY ZONE / CONTEXT, RISK & BLAST RADIUS

Risk scoreCRITICAL
96/100
Repository context 41 repos · 186 service contracts
Blast radius 7 services · 11 runtime paths
Decision confidence 98% 2 policy violations
CHANGE EVIDENCE SettlementCoordinator.ts
+18 −6
118async finalize(settlement: Settlement) {
119 const current = await store.find(settlement.id);
120- return store.finalizeAtomic(settlement.id);
121+ if (current.status === 'PENDING') {
122+ const fee = await calculateFee(current);
123+ await store.markSettled(current.id, fee);
124+ await events.publish('settlement.completed');
125 }
126}
EXECUTION PATH
  1. payments-orchestrator
  2. ledger-service
  3. settlement-events
  4. balance-read-model

RED ZONE / MERGE-BLOCKING FINDING

c]
codecr policy engineIllustrative blocking review comment
P0 · CR-RACE-017

Double-settlement window across asynchronous retry paths

At services/settlement/SettlementCoordinator.ts:118–146, finalize() performs a non-atomic read-then-write transition: it reads status === 'PENDING', awaits fee calculation, then calls markSettled() without an optimistic version predicate or row lock. consumers/SettlementRetryConsumer.ts:61 can concurrently enter the same path after Kafka redelivery; both executions pass the guard and emit settlement.completed.

Cross-repository evidence: payments-orchestrator retries HTTP 504 responses without preserving a stable X-Idempotency-Key; balance-read-model consumes settlement.completed at least once and does not deduplicate by eventId. A duplicate delivery can therefore produce two ledger mutations for the same (tenant_id, settlement_id).

Required remediation: derive the idempotency key from stable transaction identity, enforce uniqueness at the ledger boundary, replace the read-then-write sequence with an atomic conditional transition, publish through the transactional outbox, and add a concurrent-redelivery regression test. Re-run FIN-ATOMICITY-02 and EVT-IDEMPOTENCY-01 before merge.

Invokes your approved remediation agent · codecr revalidates · Never merges automatically

[ 12 / ENTERPRISE DEPLOYMENT MATRIX ]

Choose the boundary.
Keep control parity.

Commercial scope follows infrastructure capacity and review volume—not individual seats. Every tier preserves policy packs, evidence semantics, and governed merge decisions.

DEDICATED CLOUD

Isolated, operated, fast to activate.

Meter: analyzed PR volume + indexed-repository blocks

VPC PEERING

Private transport. Customer-owned data plane.

Meter: peering gateway nodes + analyzed PR volume

AIR-GAPPED / ON-PREM

Sovereign execution with no public route.

Meter: licensed analysis nodes + offline estate capacity

01 Source control Your tenant
02 Analysis plane Your VPC · ephemeral
03 Policy decision Signed evidence
CODE PROCESSINGInside customer VPC
PERSISTENCECustomer-configured
KEY AUTHORITYCustomer KMS
CONTROL PARITYTarget: full
ARCHITECTURE COMPARISON

One decision model across three deployment planes.

Read the zero-trust security model
Control Dedicated Cloud VPC Peering Air-Gapped / On-Prem
LLM Telemetry Training disabled. Operational metadata and token counts only; source payloads are excluded. Customer-selectable. Telemetry crosses the private link only when explicitly enabled. No external telemetry. Local metrics remain inside the customer enclave.
Data Retention Zero-retention analysis mode. Contracted audit metadata follows a defined retention schedule. Source remains in the customer VPC. Retention follows customer storage and KMS policy. Local policy only. The customer controls destruction, backup, and evidence retention.
Model Customization Private policy packs and retrieval over approved coding standards; no cross-tenant training. Fine-tuning or adapters inside the customer model boundary, subject to the selected model stack. Offline fine-tuning or adapters using local guidelines and approved model artifacts.
Update Frequency Continuous managed releases aligned to customer change windows. Scheduled release channels with staged promotion through customer environments. Signed offline bundles delivered monthly or within customer-approved maintenance windows.
Support SLAs 24×7 P0 response, named technical lead, and contract-defined response targets. 24×7 P0 response plus peering, identity, and KMS escalation runbooks. 24×7 P0 response with remote or on-site enclave support and offline recovery runbooks, as contracted.

Final telemetry, retention, compliance, update, and SLA commitments are defined by the executed order form, data-processing terms, and deployment data-flow schedule.

[ 13 / CLOUDFLARE PRODUCTION DIRECTIVE ]

Authorize the edge.
Then prove every control.

Production publication is a controlled change, not a DNS shortcut. The release record binds the approved artifact, Cloudflare route, certificate state, cache action, WAF policy, and rollback version before codecr.org is declared ready.

FORMAL PUBLICATION REQUESTV8 · PRODUCTION PROMOTION

Promote the approved codecr release to codecr.org.

Authorize publication only after the release commit, rollback version, domain certificate status, and public-claim register are recorded. Preserve the versioned security headers, zero-retention language, and evidence qualifiers without dashboard-side overrides.

SITES RELEASE-CONTROL INSTRUCTION
DEPLOY_SAVED_VERSION \
  PROJECT=codecr \
  VERSION=8 \
  TARGET=production \
  HOSTNAME=codecr.org \
  AUDIENCE=public
This is a release-control directive, not a shell command. Execute against the immutable saved Version 8 record; never rebuild from a mutable working tree during cutover.
Release owner
Product + Security + Edge Operations
Origin
Immutable Sites production artifact
Edge
Cloudflare DNS, CDN, WAF, and TLS proxy
Rollback
Last approved Sites version
edge-release / codecr.orgRUNBOOK
  1. 01
    Publish + routeAttach the apex hostname to the approved production version; add the returned DNS and validation records before proxy activation.
    CHANGE
  2. 02
    Purge changed URLsInvalidate HTML and replaced assets after publication. Use a zone-wide purge only when the release invalidates the complete asset map.
    CACHE
  3. 03
    Enforce Full (strict)Confirm HTTPS on 443, an unexpired origin certificate, and a CN or SAN matching the requested hostname.
    TLS
  4. 04
    Exercise the telemetry WAF pathVerify managed rules, method controls, authentication, rate limits, and Security Events for the protected API route.
    WAF
01 / CDN

Purge, then observe

Purge changed production URLs, request each twice, and record CF-Cache-Status, age, asset hash, and release commit. A second request must not serve the superseded artifact.

REQUIRES CLOUDFLARE ZONE ACCESS
02 / SSL/TLS

Validate Full (strict)

Confirm the zone is set to Full (strict), the edge certificate is active for codecr.org, and HTTP redirects once to the canonical HTTPS origin without a 526 or loop.

VERIFY AFTER DNS ACTIVATION
03 / PERFORMANCE

Measure the p95 edge target

Run five warm and five cold requests from every contracted region. Attach raw timings and approve only when p95 TTFB is below 1.2 seconds for the agreed test window.

TARGET · NOT YET AN EXECUTED SLA
04 / WAF

Prove telemetry controls

Exercise allowed and denied requests against api.codecr.org/v1/telemetry/*. Confirm expected actions and event IDs in Cloudflare Security Events; do not log authorization headers or source payloads.

API ROUTE MUST BE CONNECTED
OPERATOR SURFACE Implementation runbooks now live in the dedicated documentation hub.

Install the CLI, scope edge-protected keys, configure repository webhooks, resolve policy inheritance, and deploy the VPC data plane.

Open docs.codecr.org
EXECUTIVE COLLATERAL The Executive Guide to AI Code Governance

A one-page decision brief covering the strategic risk, governance engine, sovereignty controls, deployment parity, and evidence-qualified value model.

Download executive brief (PDF)
PHASE 8 / APEX DNS + ORIGIN TLS

Activate the apex only after the certificate proves the hostname.

CHANGE TICKET REQUIRED
DNS MANIFEST / CODECR.ORGTTL · AUTO

In the Cloudflare zone for codecr.org, preserve all unrelated MX and TXT records. Remove a conflicting apex A, AAAA, or CNAME only after its owner, rollback value, and last-known TTL are captured.

TYPENAMECONTENTPROXY
A@162.159.143.30PROXIED
A@172.66.3.26PROXIED
  1. Confirm the approved Sites version and rollback version are immutable and recorded.
  2. Confirm the custom hostname mapping for codecr.org is active and its validation TXT records resolve.
  3. Create both apex A records with TTL set to Auto; do not add an apex AAAA unless the platform returns one.
  4. Wait until two independent recursive resolvers return both targets before continuing.
ORIGIN CERTIFICATE GATEBEFORE FULL (STRICT)

Test each published origin target with SNI set to codecr.org. The chain must verify, the certificate must be currently valid, and its SAN must match the apex; “it works through the edge” is not sufficient evidence.

for TARGET_ORIGIN_IP in 162.159.143.30 172.66.3.26; do
  openssl s_client \
    -connect "$TARGET_ORIGIN_IP:443" \
    -servername codecr.org \
    -verify_hostname codecr.org \
    -verify_return_error </dev/null

  echo | openssl s_client \
    -connect "$TARGET_ORIGIN_IP:443" \
    -servername codecr.org 2>/dev/null \
    | openssl x509 -noout -issuer -subject -dates -ext subjectAltName

  curl --fail --silent --show-error \
    --resolve "codecr.org:443:$TARGET_ORIGIN_IP" \
    --output /dev/null \
    --write-out "ip=$TARGET_ORIGIN_IP status=%{http_code} tls=%{ssl_verify_result}\n" \
    https://codecr.org/
done
ACCEPT ONLY IF
  • Port 443 completes for both targets.
  • ssl_verify_result=0 and OpenSSL returns no verification error.
  • notBefore ≤ now < notAfter and SAN contains codecr.org.
  • The HTTPS response is the approved artifact and not a 526, redirect loop, or fallback host.
STRICT-MODE CUTOVER
  1. 01

    Record baseline. Export the zone settings, DNS records, certificate evidence, approved version, and rollback owner.

  2. 02

    Lock the origin. Confirm HTTPS on 443 and a publicly trusted or Cloudflare Origin CA certificate that matches codecr.org. Never bypass a failed chain check.

  3. 03

    Enable Full (strict). In Cloudflare: SSL/TLS → Overview → Configure → Full (strict). Apply only inside the approved change window.

  4. 04

    Prove the public path. Test HTTP-to-HTTPS behavior, certificate chain, canonical response hash, and absence of 526 errors from at least two networks.

  5. 05

    Close or roll back. Attach evidence and monitor. On failure, restore the recorded DNS/version state and keep the release closed; do not normalize a weaker TLS posture as the final state.

ENTERPRISE WAF / API.CODECR.ORG

Reject malformed telemetry. Throttle provisioning abuse.

NOT ACTIVE · API ORIGIN REQUIRED

These are deployable Cloudflare Ruleset Engine definitions for the intended API contract. Keep them disabled until the origin publishes the named routes, validates bearer credentials at the application layer, and returns non-cacheable responses.

RULE 01 / MALFORMED TELEMETRYACTION · BLOCK

Block invalid request shape at the edge.

Scope only api.codecr.org/v1/telemetry/*. Permit CORS preflight; require every POST to carry a bounded body, JSON content type, non-truncated headers, and a bearer-shaped authorization header.

(http.host eq "api.codecr.org" and
 starts_with(http.request.uri.path, "/v1/telemetry/") and
 (
  not (http.request.method in {"POST" "OPTIONS"}) or
  http.request.headers.truncated or
  (
   http.request.method eq "POST" and
   (
    http.request.body.size eq 0 or
    http.request.body.size gt 1048576 or
    not any(http.request.headers["content-type"][*] contains "application/json") or
    not any(starts_with(http.request.headers["authorization"][*], "Bearer "))
   )
  )
 ))
Phasehttp_request_firewall_customEvidenceSecurity Events + origin auth tests
RULE 02 / PILOT PROVISIONING3 REQ / 10 MIN

Rate-limit the two privileged creation routes.

Block the fourth POST from the same source IP within ten minutes for one hour. Require authenticated origin authorization, idempotency keys, CSRF protection, and tenant-level quotas behind this edge control.

Expression:
(http.host eq "api.codecr.org" and
 http.request.method eq "POST" and
 http.request.uri.path in {
  "/v1/pilots/vpc-sandbox/provision"
  "/v1/pilots/microvm-test-cluster/deploy"
 })

Rate limit:
{
  "characteristics": ["cf.colo.id", "ip.src"],
  "period": 600,
  "requests_per_period": 3,
  "mitigation_timeout": 3600,
  "requests_to_origin": true
}
Phasehttp_ratelimitNAT reviewapproved egress exceptions only
01Connect originPublish exact routes, deny anonymous access, and emit a stable request ID.
02Log before blockRun a bounded simulation window and inspect false positives without payload logging.
03Enable + exerciseTest allowed POST, denied methods, missing headers, oversized bodies, and rate exhaustion.
04Monitor thresholdsAlert on block-rate deviation; review corporate NAT ranges and never weaken origin authorization.

Control boundary: a WAF can validate request shape and frequency; it cannot prove bearer-token authenticity or provisioning authorization. Those decisions remain mandatory at the API origin.

DAY-2 EXECUTIVE ONBOARDING

Follow conversion with evidence gates—not nurture noise.

RESEND CONNECTED · PILOT ONLY
TRIGGER EVENTpilot.email_consent.confirmedEmitted only after a signed, single-use double-opt-in link is redeemed.
EMAIL 01T+0Queue only after recipient verification, explicit purpose consent, and every provider activation gate passes.
EMAIL 02T+48HSuppress when provisioning is authorized, the pilot is withdrawn, or the recipient opts out.
DATA MINIMIZATIONCONTROL METADATA ONLYNo source code, secrets, repository payloads, tokens, or certificate material.
IMPLEMENTATION ARTIFACTResend consent + sequence contract

Versioned JSON containing the double-opt-in state machine, Resend request envelope, signed webhook normalization, suppression policy, exact consent copy, and two-message sequence.

Download automation sequence (.json) SHA-256 · 96e7a202b9ed859223abdb2788f1648285cc67745dcb842b13df1292a038fbfe
TRANSACTIONAL EMAIL + CONSENT CONTROL PLANE

No confirmation. No sequence. No exceptions.

PILOT ONLY · ALLOWLIST ENFORCED

The website may prepare a local pilot manifest without email. The two-message sequence activates only after an optional, unbundled consent request is confirmed through a signed single-use link; provider credentials and consent records remain server-side.

01 / CONSENT REQUEST APIPOST · SERVER ONLY

Create the recipient and consent record without activating onboarding delivery. Return 202 pending_confirmation; the only permitted outbound message is the verification email.

02 / PROVIDER SEND ENVELOPERESEND

Map this normalized envelope at a server-side adapter. Use opaque IDs in provider metadata; never place source code, repository content, secrets, or personal data in analytics tags.

{
  "message_key": "pilot_<id>_email_1",
  "provider": "resend",
  "to": [{"email": "verified@example.com"}],
  "from": {
    "email": "onboarding@codecr.org",
    "name": "codecr Enterprise Operations"
  },
  "template": "vpc-boundary-confirmation",
  "template_version": "2026-09-05.v1",
  "variables": {
    "preflight_id": "pilot_01J...",
    "deployment_topology": "VPC Peering",
    "preference_url": "https://codecr.org/email/preferences/<token>"
  },
  "headers": {
    "List-Unsubscribe": "<https://codecr.org/email/unsubscribe/<token>>",
    "List-Unsubscribe-Post": "List-Unsubscribe=One-Click"
  },
  "metadata": {
    "preflight_ref": "pilot_01J...",
    "consent_ref": "consent_01J..."
  }
}
RESEND EVENT WEBHOOK

Verify the raw request before parsing it.

Verify the raw body and svix-id, svix-timestamp, and svix-signature against the Resend-issued WEBHOOK_SIGNING_SECRET; then deduplicate, normalize, write suppression first for bounce, complaint, or unsubscribe, and return 204.

{
  "schema_version": "1.0",
  "provider": "resend",
  "provider_event_id": "evt_opaque",
  "provider_message_id": "msg_opaque",
  "event": "delivered | bounced | complained | unsubscribed",
  "occurred_at": "2026-09-05T18:05:00Z",
  "recipient_ref": "recipient_opaque",
  "preflight_id": "pilot_01J...",
  "signature_verified": true
}
EXACT FORM COPY / LEGAL REVIEW GATE

Optional consent remains separate from sandbox administration.

Processing notice: “By continuing, you ask codecr to prepare and administer your enterprise sandbox request. We process the work email and deployment-control metadata described in the Pilot Privacy Notice for this purpose.”

Optional checkbox: “Send me the two-message VPC sandbox onboarding sequence. I agree that codecr may use my work email to send (1) the deployment-boundary confirmation and (2) the Day-2 isolation checklist. This is optional; the local preflight still works without it. I can withdraw at any time using the link in either email.”

Double-opt-in helper: “Email onboarding is currently limited to the approved pilot address. If eligible, we will first send one verification email. Onboarding begins only after you confirm; the link expires after 30 minutes.”

CAN-SPAM footer: “You received this message because you confirmed the codecr VPC sandbox onboarding sequence for {{work_email}}. Unsubscribe immediately or manage preferences. Rashad Elkersawy / codecr, Friedrich-Naumann-Str. 66, 26125 Oldenburg, Germany. Privacy: privacy@codecr.org.”

Legal boundary: this control design supports consent evidence, withdrawal, identification, and suppression; it is not a substitute for counsel’s review of codecr’s role, lawful basis, notices, retention, jurisdictions, or whether a message is transactional or commercial.

GLOBAL EDGE PERFORMANCE / CURL PROBE

Measure five cold and five warm requests per region.

TARGET · P95 < 1.2S

The probe records DNS, connect, TLS, TTFB, total time, HTTP status, remote IP, CF-Cache-Status, and CF-Ray to CSV. Run it independently from every contracted geography; one machine cannot substantiate a global SLA.

  1. Execute from controlled runners in each agreed region with synchronized clocks.
  2. Use a fresh query key plus Cache-Control: no-cache for cold samples, then one fixed primed key for warm samples.
  3. Confirm the probe query participates in the cache key; otherwise pair cold runs with an approved purge.
  4. Attach the raw CSV, runner region, release commit, and Cloudflare configuration revision to the acceptance record.
VALIDATE-CODECR-TTFB.SHEXIT 0 · PASS
chmod +x validate-codecr-ttfb.sh

CODECR_PROBE_REGION=us-east-1 \
  ./validate-codecr-ttfb.sh \
  https://codecr.org/

# Repeat from every contracted region.
# PASS requires cold and warm p95 TTFB < 1.2s.
Download TTFB validation script SHA-256 · 112a39eb4d1099a2ada6078ebf07f1227a378e35793d96e6746c5e28cedccafb
MONITOR CODECR EDGE HEALTH / ALERT CONTRACT

Detect drift before customers feel it.

THRESHOLDS DEFINED · DATA BINDING REQUIRED

Bind Cloudflare HTTP analytics, Security Events, DNS and certificate state, plus distributed synthetic probes to a single release-tagged dashboard. Every alert must include hostname, path class, colo, release commit, rule ID, request count, and a link to the rollback record.

AVAILABILITY5xx / 5 MINWARN ≥1% · P0 ≥5%Minimum-volume gates prevent low-traffic noise.
GLOBAL LATENCYWARM P95 TTFBP0 ≥1.2S / 10 MINRequire impact in two regions, or ≥2.0s in any region.
WAF POSTURETELEMETRY BLOCK RATEP0 >10× BASELINECorrelate by rule, colo, ASN, method, and path.
EDGE INTEGRITYTLS · DNS · ASSETDRIFT = PAGECertificate failure, route drift, or hash mismatch is immediate.
SIGNALWARNINGP0 / PAGERECOVERY
Origin + edge 5xx≥1% and ≥20 requests per 5 minutes for 2 windows≥5% and ≥50 requests for 5 minutes; or 3 failed probes from 2 regions<0.5% for 15 minutes and probes green
Telemetry WAF blocks>3× 7-day same-hour baseline and ≥100 blocks per 10 minutes>10× baseline and ≥500 blocks per 5 minutes; known-good synthetic blocked in 2 regions; or rule disabledBaseline band for 30 minutes; synthetic allowed; rule checksum restored
Global p95 TTFBWarm ≥0.9s or cold ≥1.1s for 10 minutes in 2 regions≥1.2s for 10 minutes in 2 regions; or ≥2.0s for 5 minutes in any regionWarm <0.8s and cold <1.0s for 15 minutes
TLS + DNSCertificate expires in ≤30 days or validation is pendingChain/hostname failure; expiry ≤7 days; apex target or proxy-state driftValid chain, >30 days remaining, approved DNS manifest restored
Static cache integritySecond asset request is not HIT when policy says cacheableSHA-256 differs from release manifest or superseded HTML is servedTwo matching hashes and expected cache state from 3 regions
NOTIFYEdge SRE + Security on callWarning → operations channel and ticket. P0 → pager, incident channel, and named incident commander.
DO NOT AUTO-DISABLEWAF protectionA high block rate can be an attack or a false positive. Require rule-level evidence and Security approval before changing enforcement.
ROLLBACK TRIGGERRelease-correlated failureRollback when a new commit causes sustained P0 5xx, latency, asset-integrity, or route failure and the previous artifact passes probes.

[ 14 / ENTERPRISE PILOT ONBOARDING ]

Bound the environment before a cluster exists.

Choose the deployment topology, identity boundary, repository scope, and policy baseline in a three-step local preflight. The workflow prepares a 14-day pilot manifest; infrastructure is provisioned only through your approved enterprise delivery channel.

PRODUCTION CHECKLIST VERIFICATIONRelease control record
2 SOURCE-VERIFIED · 4 OPERATOR GATES
SEO metadataUnique title, description, canonical URL, robots directive, and sitemap entries are configured.
SOURCE VERIFIED
Open Graph preview tagsOpen Graph and X summary metadata are configured for the homepage and security route.
SOURCE VERIFIED
WCAG 2.1 AA validationKeyboard, semantic, focus, and ARIA controls are implemented; manual assistive-technology and contrast validation remain required before conformance is claimed.
VALIDATION REQUIRED
Global performance SLAContract target: <1.2s TTFB across agreed regions. Production edge measurements and the test window must be attached before SLA sign-off.
MEASURE AT EDGE
Cloudflare hostname and Full (strict)Sites domain mapping, DNS validation, edge certificate status, and the zone encryption mode must be confirmed after the production route is active.
VERIFY IN ZONE
Telemetry API WAF policyManaged rules, explicit method and authentication controls, rate limiting, and Security Events must be tested on the connected API hostname.
EXERCISE RULES
FORMAL RELEASE POSITION

SEO and social summary metadata are confirmed in source. WCAG 2.1 AA conformance, Cloudflare zone controls, telemetry WAF behavior, and the <1.2s global TTFB commitment remain controlled release gates until evidence is attached; this page does not convert implementation intent into certification or an executed SLA.

Review the Trust Center evidence model
CONTROLLED REMEDIATION

Authorize isolated hotfix

codecr sends the finding, policy constraints, and permitted scope to your approved remediation agent inside an ephemeral branch. codecr does not generate application code; it revalidates the resulting candidate patch and keeps merge blocked until every required human approval and policy check passes.

Branch
codecr/remediate-cr-race-017
Maximum scope
3 files · 1 regression test
Action owner
Customer-controlled remediation agent
Required approval
Payments Platform + Financial Controls
Rollback
Discard isolated branch

14-DAY ENTERPRISE PILOT · LOCAL PREFLIGHT

Define the deployment boundary

Your deployment manifest stays in this browser. If you request email onboarding, your email address, selected topology, and consent information are sent to codecr. This form does not collect credentials or provision infrastructure.

  1. 01Topology
  2. 02Identity
  3. 03Scope + policy
STEP 1 / DEPLOYMENT TOPOLOGY

Where may source code be processed?

Select the trust boundary that Security and Platform Engineering will validate during the pilot.

Secrets, certificates, and repository tokens are never requested here.

CONTROLLED TRUST CENTER ACCESS

Request the evidence room and data terms

Use this request to identify the artifacts, confidentiality terms, DPA, and—where applicable—Business Associate Agreement required for your diligence review.

01Assurance evidenceCurrent reports, certificate scope, testing summaries, and remediation status.
02Data-processing termsDPA, subprocessor schedule, retention profile, and regional processing boundaries.
03Architecture evidenceData flows, control ownership, KMS design, network paths, and incident escalation.