Custom software

Custom software built on proven libraries.

The first version of Approval took us half a day. We use the same open-source libraries to build your application.

The case

Approval prepares software assessments for regulated organisations. After half a day, the first version supported the full process from a department’s request to signatures by two officers. It retrieved and versioned vendor documents, extracted facts with source quotes, drafted assessments and recorded the results in a verifiable log.

Over the following days, we added document search with answers from the source register and an import for existing software inventories. We built the underlying packages first and then integrated them into Approval. The feature list below shows which packages each feature uses.

Diese Seite auf Deutsch

Feature by feature

Which packages each feature uses

Every package will be released under the MIT licence in November 2026. Until then we walk you through the code and its documentation in a call, so you can inspect it before we build your application.

Source register

The source register stores vendor documents with a size limit and a SHA-256 checksum. It creates a new version when the content changes and records it in the ledger under whoever fetched or uploaded it: a person, or the register on its own check. Every retrieval attempt is logged. You can upload non-public documents such as register extracts or signed contracts.

  • storage

Search vendor documents

Approval answers questions using stored vendor documents and cites the passages it uses. Searches are limited to passages the person’s role permits them to read, and each search is logged. If the documents do not support an answer, Approval leaves the question unanswered.

  • knowledge
  • disclosure
  • rls

Inventory import

Import your existing software inventory from CSV or Excel. Columns are matched by name. For unmatched columns, a model suggests mappings using only the headers, without access to cell contents. A person reviews and applies the import as a single proposal, which can be reversed. Imported products start with the status “not requested” and still need approval.

  • intake
  • proposal
  • agent-ledger

Vendor identity

Approval compares the company name, register entry and managing directors in the vendor’s imprint with the register extract, citing both sources. The security officer assesses any differences.

  • proposal

Review and signatures

The security and data protection officers each review the draft of their section, edit it and sign it. The signature is recorded in the ledger with a hash of the documents and of the request, so the chain shows that what was signed is what was asked. Agents cannot sign.

  • proposal
  • agent-ui
  • signing
  • agent-ledger

Model control

Every model call is checked and logged. Public vendor documents can be sent to an approved EU provider. Drafts that name the organisation’s internal systems can only be sent to a self-hosted model.

  • disclosure
  • telemetry

Evidence for the auditor

Export evidence for an individual request or the whole organisation as JSON and a cover sheet. It includes decisions, edits, citations, model calls and verification of the ledger chain, along with processing times and edit rates.

  • evidence
  • agent-ledger

Self-hosted

Deploy one container image with your own Postgres database. The application uses two database roles and row-level security for each organisation, with retention controls and support for data-subject requests. We do not engage sub-processors to run it.

  • rls
  • postgres
  • pii
  • data-subject
  • data-lifecycle

Why it is fast

What the platform already provides

The parts exist

Published packages cover tenant isolation, review of AI proposals, verifiable logging, deletion and data-subject requests. Each includes tests and documentation. We integrate these packages into your application.

One command to start

The starter creates a Next.js application with React, shadcn/ui and Postgres. It includes tenant isolation on every table, sign-in through Microsoft Entra ID or another OIDC provider, and an AI step with human approval.

Automated checks for agent-written code

Coding agents write most of the code. After each task, automated checks look for missing tenant isolation, missing migrations and model calls that bypass content checks. The agent receives specific corrections to make before we review the work.

Proven in production

Reynt, our booking platform, was built the same way and runs in production. The first packages came out of it.

The offer

Two ways to start

We can build a new application on the platform or add an AI workflow to your existing system. In either case, you own the code and run it in your environment.

Custom application

A complete application in weeks, using the same libraries as Approval.

We build your application on the octabits platform and adapt it to your data model, workflows and roles. The platform provides tenant isolation, review of AI proposals and a verifiable log. Coding agents write most of the code, supported by automated checks and our review of every change. The application runs in your environment on your Postgres database, and you own the code.

You get
A running application in your environment with tests, CI and documentation. You can use a first version within the first week.
Duration
4–6 weeks
Pricing
We agree a fixed price after the first call, with a monthly fee for ongoing maintenance. No licence fees or per-user charges.

For processes you currently manage through spreadsheets and email, where you need defined roles, approvals and an audit trail.

In your existing system

One AI workflow in your system: reviewable, logged and reversible.

We implement one workflow in which a model prepares a proposal for human review, such as a vendor assessment, a record update or a document awaiting signature. Using the oversight kit, we add a review screen, a hash-chained change log with revert support, and checks on the content sent to each model call. The workflow runs in your environment on your Postgres database. You own the application code.

You get
A working workflow in your environment, tests and documentation of which data the model may access. We measure the time per case and how much reviewers change each proposal to help you assess the results.
Duration
8–10 weeks
Pricing
Fixed price, agreed after a first call; optional ongoing support

For workflows where a model can prepare the work and a named person has to approve the result.

How the review loop works →

We also support existing development teams with architecture reviews, coding-agent setup, system design and implementation. Consulting services →

What you get

Capabilities and automated checks

Automated checks cover the capabilities below and catch changes that break them. Each section explains what is tested.

  1. Row-level security

    Postgres row-level security applies to every customer-scoped table. The scope is set for each request. Queries without a scope return no rows, and writes are rejected.

    How we test itIntegration tests use a real Postgres database with Prisma, Drizzle and plain SQL. A separate check verifies that every scoped table has a policy.

  2. Postgres only

    Queues, events, notifications, files, encryption keys, audit logs and workflow state are stored in Postgres. They use the same database and backup process, without a separate message broker or control plane.

    How we test itA browser test checks that requests stay on the host. Lint checks also validate the generated list of sub-processors.

  3. AI with review

    Agents propose typed changes to existing records. A person can review, edit, accept individual changes or reject the proposal. Before applying it, the system checks for changes to the underlying data. Reversals use the audit log.

    How we test itChromium tests exercise proposals, edits, rejection, application and reversal in every host application. Each write is verified through the API.

  4. GDPR

    Each table defines how to export and erase personal data, with a check for missing tables. Encryption keys are stored in your database, and blind indexes allow searches on encrypted data. Sensitive fields are redacted from logs and traces by default.

    How we test itTests export and erase data in a running database. CI fails if a table or a column containing credentials has not been classified.

  5. EU by default

    The default model provider processes data in the EU. Identity services and telemetry are self-hosted, with no automatic reporting to an external service. Confidential content is sent only to a self-hosted model. You can choose a different provider configuration.

    How we test itTests check provider residency and the disclosure rules. A lint check prevents model calls that bypass those rules.

  6. Audit trail

    Each applied AI action adds an entry to a hash-chained log, recording who acted and on whose behalf. Reversals add new entries and preserve the original records. The chain is verified against a reference hash stored outside the database.

    How we test itAll three storage implementations are tested for tampering and forks. Every MCP tool call is logged. Checks for the Article 30 record of processing activities are not yet implemented.

Tell us what your application should do

Send us a short description. In the first call, we show you Approval and discuss how we would build your application using the same libraries.