Open source

The libraries behind our products

Our TypeScript packages handle tenant isolation, data protection, human review of AI proposals and audit logging. Each package works on its own in an existing backend. Postgres is the only database you need.

Open-source release in November 2026

We are preparing the packages for release under the MIT licence: the public repository, npm and the documentation for each package. Until then we show you the code, its tests and the documentation in a call.

What you get

Capabilities and automated checks

Automated checks cover the capabilities below and catch changes that break them. Each section explains what is tested.

  1. Row-level security

    Postgres row-level security applies to every customer-scoped table. The scope is set for each request. Queries without a scope return no rows, and writes are rejected.

    How we test itIntegration tests use a real Postgres database with Prisma, Drizzle and plain SQL. A separate check verifies that every scoped table has a policy.

  2. Postgres only

    Queues, events, notifications, files, encryption keys, audit logs and workflow state are stored in Postgres. They use the same database and backup process, without a separate message broker or control plane.

    How we test itA browser test checks that requests stay on the host. Lint checks also validate the generated list of sub-processors.

  3. AI with review

    Agents propose typed changes to existing records. A person can review, edit, accept individual changes or reject the proposal. Before applying it, the system checks for changes to the underlying data. Reversals use the audit log.

    How we test itChromium tests exercise proposals, edits, rejection, application and reversal in every host application. Each write is verified through the API.

  4. GDPR

    Each table defines how to export and erase personal data, with a check for missing tables. Encryption keys are stored in your database, and blind indexes allow searches on encrypted data. Sensitive fields are redacted from logs and traces by default.

    How we test itTests export and erase data in a running database. CI fails if a table or a column containing credentials has not been classified.

  5. EU by default

    The default model provider processes data in the EU. Identity services and telemetry are self-hosted, with no automatic reporting to an external service. Confidential content is sent only to a self-hosted model. You can choose a different provider configuration.

    How we test itTests check provider residency and the disclosure rules. A lint check prevents model calls that bypass those rules.

  6. Audit trail

    Each applied AI action adds an entry to a hash-chained log, recording who acted and on whose behalf. Reversals add new entries and preserve the original records. The chain is verified against a reference hash stored outside the database.

    How we test itAll three storage implementations are tested for tampering and forks. Every MCP tool call is logged. Checks for the Article 30 record of processing activities are not yet implemented.

The packages

25 packages in two kits

The build kit 17

The build kit provides an application template with rules and automated checks for coding agents. Its libraries handle HTTP, sign-in, tenant isolation, queues, events and data protection using Postgres.

Custom software →

Shared Postgres infrastructure

  • @octabits-io/rlsSQL policies for row-level security, with request-scoped access through Prisma, Drizzle or plain SQL.ApprovalReynt
  • @octabits-io/eventsLive events from the database to the browser: a transactional outbox, LISTEN/NOTIFY and SSE.ApprovalReynt
  • @octabits-io/activityA notification feed with read status per user. Notifications are saved in the same transaction as the event that triggered them.ApprovalReynt
  • @octabits-io/queueDurable background jobs on Postgres, with validated payloads and a dead-letter queue.ApprovalReynt
  • @octabits-io/storageA common file-storage interface for Postgres, S3-compatible storage and local disks.ApprovalReynt
  • @octabits-io/backfillOne-off data migrations that fail deployment if they do not complete. Partial runs are never marked as finished.ApprovalReynt
  • @octabits-io/postgresA shared SQL interface for pg, PGlite and postgres.js, with Postgres errors returned as typed values.ApprovalReynt

Data protection

  • @octabits-io/piiEncrypts fields using keys stored in your database, with blind indexes for search and pseudonyms for model inputs.ApprovalReynt
  • @octabits-io/data-subjectPer-table handlers for access, erasure and data portability requests under Articles 15, 17 and 20 GDPR, with a coverage check.ApprovalReynt
  • @octabits-io/data-lifecycleClassifies scoped tables and runs scheduled deletion according to their retention periods.ApprovalReynt
  • @octabits-io/signingSigning keys per purpose: HMAC, short tags and tokens, compared in constant time.ApprovalReynt

Foundation

  • @octabits-io/createCreates a new application on the platform with one command: development rules and automated checks for coding agents, AI steps under human review, and sign-in through your identity provider.
  • @octabits-io/resultA shared Result type for expected errors, with a stable 1.0 release.ApprovalReynt
  • @octabits-io/serverThe HTTP core of a multi-tenant API without a framework: auth, rate limits, idempotency, MCP.ApprovalReynt
  • @octabits-io/mailSends mail through your own SMTP relay, with input sanitised against header injection and no vendor API.Approval
  • @octabits-io/sessionBrowser sign-in without a framework: session stores, a route guard, OIDC and Better Auth.Reynt
  • @octabits-io/telemetryLogs, traces and metrics over OTLP, without the OpenTelemetry SDK and without a collector.ApprovalReynt

The oversight kit 8

The oversight kit lets people review typed AI proposals and accept or reject them. It records applied changes in a hash-chained log, checks which content each model may receive and stores workflow state in Postgres.

AI oversight →
  • @octabits-io/proposalTyped AI proposals that can be accepted in part, applied and reversed, with checks for changes to the underlying data.ApprovalReynt
  • @octabits-io/agent-uiFramework-independent review state with bindings for Vue, Nuxt UI and React.ApprovalReynt
  • @octabits-io/agent-ledgerA hash-chained log of agent actions, their initiators and the information needed to reverse them.ApprovalReynt
  • @octabits-io/disclosureChecks which content can be sent to each model and records a digest of every call.Approval
  • @octabits-io/evidenceAudit evidence for AI actions, generated from the ledger and the log of model calls.Approval
  • @octabits-io/intakeImports CSV and Excel files as one reviewable proposal, with every value traced to its row in the file.Approval
  • @octabits-io/knowledgeSearches documents stored in Postgres and checks that quoted text appears in the cited passage before accepting an answer.Approval
  • octaflow0.28.0Workflows that save their progress in Postgres, with decision steps that ask a person only when the model is unsure, and an AI integration that defaults to an EU provider.ApprovalReynt

Help with integration

The packages will be free to use. We also offer paid support to integrate them and build a workflow for your system. Write to us to see the code before the release.