anvil

TRUST THE CODE
YOUR AI WRITES.

anvil is the independent, deterministic control point for AI-assisted software engineering.

The agent proposes. anvil judges the write against deterministic policy — before it reaches the diff. You can let it run without treating the agent as the auditor.

Understand the change. Apply your standards. Stop unsafe work before it reaches review.

read the docs
anvil :: pre-writeagent → anvil → diff
[ = ]
[ = ]LOCAL EXECUTION
[ = ]DETERMINISTIC POLICY
[ = ]RESIDENT GRAPH
[ = ]12 MCP CLIENTS

reference: 28.3 µs incremental :: 1.6 µs policy :: deus :: 2026-06-26

AI CAN CREATE MORE
THAN HUMANS CAN REVIEW.

AI increases how much software an organisation can produce. It also increases the distance between the people responsible for a system and the actions taken on their behalf.

After an unsupervised hour you cannot reconstruct what happened from the agent’s account. Asking the agent is not an audit: the model is biased toward its own work, compaction already dropped the rules file, and re-analysing raw logs is a tax.

Logs, monitoring, governance programmes and model-provider explanations can each show something. None of the systems teams use today establishes, on its own, whether a particular AI-assisted change deserved to be trusted.

REVIEW_CAPACITY
output outruns the people responsible for the system
SELF_REPORT
the system that created the work cannot judge it
SILENT_HOUR
non-conforming writes land before anyone looks

BABYSIT

you keep up. the agent does not.

UNSUPERVISED

the agent keeps up. you do not.

ANVIL

the agent runs. the write still has an independent judge.

[ = ]

PROTECTION IS THE ENTRY POINT.
DECISION INTEGRITY IS THE SYSTEM AROUND IT.

Today, anvil protects supported software changes as they are written and maintains a living model of the code beneath them.

That control point is the foundation for a broader system connecting intent, evidence, policy and durable decisions.

THE WRITE EITHER HAS A JUDGE,OR IT DOES NOT.

WITHOUTno judge

$ agent write src/auth.ts

skip CLAUDE.md

secret lands in src/auth.ts

the miss arrives at review, or in production

WITHindependent judge

$ agent write src/auth.ts

[ ERR ] secret-detection

write blocked at save-time

agent sees the miss immediately

[ = ]

THE CONTROL POINT
SHIPS TODAY.
THE TRUST CHAIN
COMES NEXT.

anvil sits in the workflow as an independent, deterministic judge. The first run is useful at zero config. The no arrives at write-time, so the agent can correct.

default checks

  • secret-detectioncredentials and secrets never enter the diff
  • command-safetydestructive or unexpected shell is blocked
  • antipattern-scanknown unsafe shapes in the proposed write
  • import-boundarieslayer and package rules held at save-time
  • team policydeterministic rules as the organisation matures

operating today

  • deterministic pre-write and save-time protection
  • resident graph and assistant-facing context
  • checks, policy and configurable enforcement
  • protection claims, witness chains and review capsules

system being completed

  • general intent conformance
  • connected evidence providers
  • independently verifiable decision receipts
  • closed outcome-learning loop

THE SYSTEM THAT CREATES WORK
SHOULD NOT JUDGE IT ALONE.

Decision Integrity applies to a particular action. AI may help interpret, explain or remediate, but deterministic software remains the final authority at the trust boundary.

This is the target model. General intent conformance and independently verifiable decision receipts are not presented as shipped capabilities.

INTENT

what outcome was expected

EVIDENCE

what was demonstrably true

POLICY

which constraints applied

DETERMINISTIC DECISION

the independent trust boundary

DECISION RECEIPT

what was true and why

THREE PARTS.ONE JUDGE.

Modes are understand, build, decide, learn. Parts are the graph, the policy engine, and the learning system. They are not the same list. Context supports humans and agents. anvil remains the independent control point, not the coding agent.

  1. GRAPH

    operating foundation

    living model of the software — structure, dependencies, symbols. context for protection and for the assistant.

  2. POLICY ENGINE

    operating foundation

    deterministic rules at the control point. pass or fail, predictably. not the model that wrote the change.

  3. LEARNING SYSTEM

    being built

    outcomes return to understanding. not a closed flywheel today.

DECISION INTEGRITY
FLYWHEEL

Every decision makes the next one better. The graph and protection path provide the operating foundation; the wider evidence and learning loop is still being built.

operating foundation
system being completed
  1. [1] UNDERSTAND

    resident graph and applicable context

  2. [2] BUILD

    proposed change and minimum evidence

  3. [3] DECIDE

    deterministic constraints and enforcement

  4. [4] LEARN

    outcomes improve future understanding

eddacraft
[ = ]

TRUST INFRASTRUCTURE
FOR AI-ASSISTED WORK.

eddacraft builds technology that makes AI-assisted work independently trustworthy. anvil begins with software engineering.

eddacraft.ai