Get started

AI writes the code.
Thea proves it.

AI agents write your code. Thea shows what changed, which checks ran and who let it merge.

exit 0
$python scripts/atlas.py check
    Contract 3.52.0: OK
    $thea gate scripts/verify.py
      Named for this file, run in orderA failed or skipped gate refuses the commit.
      $thea contract · generated on every build
      Counted, never typedEvery number above is generated from the repository on each build.
      Contract 3.52.0
      Runs under the agents your teams already use

      Agents ship faster than anyone can review.

      Not a smarter agent. An independent record of what each change passed.

      1. "Done" becomes evidence

        An agent's summary is self-reported. Thea replaces it with the exit codes of your formatter, type checker and tests.

      2. Process is enforced, not suggested

        Rules run at commit and again in CI. A skipped check counts as a failure.

      3. Every mistake becomes a rule

        A refused change is recorded with the guard that stops it. 105 failure shapes closed so far.

      See every agent at work.

      Which agents ran, what they changed, which checks passed. It reads Thea's records and never judges.

      • Agents and sessions

        Claude Code, Codex, opencode and Hermes, read from each runtime's own session files.

      • Checks

        PASS, FAIL or NOT RUN for every changed file. It never shows a green it did not read.

      • Mistakes

        The failure ledger: every shape an agent repeated and the guard that now stops it.

      Four guarantees no agent can talk its way around.

      The agent never grades its own homework.

      Your own toolchain decides. The exit code is the verdict, never the agent.

      • PASS, FAIL or NOT RUN for every check
      • A missing tool is named, never passed by default
      • Same answer in the hook, in CI and over MCP
      scripts/verify.pyillustrative
      1. Formatterruffexit 0 · PASS
      2. Type and syntaxpython3exit 0 · PASS
      3. Unit testspytestexit 1 · FAIL
      Refused. The agent reported done; the unit tests disagreed. The verdict names the failing check.
      99%correct routing with Thea, against 59% blind
      119/119agent controls passing, each refusing a planted bypass
      89%fewer tokens than pasting tool lists
      36languages routed by one contract

      Generated from a recorded run of contract 3.52.0. See the benchmarks

      Adopt agents without lowering the bar.

      Every verdict auditable, every rule reviewable code. Nothing leaves your infrastructure.

      Audit trail
      What ran, what passed, what was refused and why.
      Policy as code
      Versioned and reviewed with the repository.
      No egress
      Runs on your machines and your CI.
      Open core
      MIT licensed. Read every line that judges your code.

      From a check on your machine to a mark anyone can trust.

      1. Available now

        Open core

        CLI, hooks, MCP server and CI check on contract 3.52.0. Free and MIT licensed.

      2. Private beta

        Dashboard

        A local Mac app that shows every agent, check and repeated mistake. Nothing leaves the machine.

      3. Next

        Pull request checks

        A GitHub check and one comment per pull request: which gates ran, passed, were skipped or refused.

      4. Planned

        Team sync and policy

        Opt-in. Ships verdicts, never source code. Rules such as "no agent merges to main without the security gate".

      5. Planned

        Thea Verified

        A signed receipt that a change passed its own toolchain on a runner its author did not control.

      Start free. Scale when your agents do.

      Enforcement is never paywalled. Plans differ only in how many agents connect at once.

      Before you roll it out.

      Stop trusting. Start proving.

      Install in minutes. The next change that skips a check does not land, and you see why.

      AI governance at every team size.

      One engine, from one developer to a whole organization.

      Developers

      Let the agent run. Keep the receipts.

      "All tests pass" is a claim. Thea replaces it with evidence you read in a second.

      • Your agent asks Thea for a file's checks before it edits
      • The git hook refuses a commit that failed or skipped one
      • Runs on your machine: no account, nothing to host

      Compare plans

      Compare plans

      $ thea gate scripts/verify.py 1. formatter: ruff format --check scripts/verify.py 2. compiler_or_typechecker: python3 -c 'import ast,sys; [ast.parse(open(f, encoding="utf-8").read(), f) for f in sys.argv[1:]]' scripts/verify.py 3. unit_tests: pytest
      Teams

      One policy for every agent and repository.

      One versioned contract gives every agent and pipeline the same answer.

      • One contract file per repository, reviewed like code
      • Same gates locally, at the hook, in CI and over MCP
      • Shared dashboard, gate history, approvals and audit export

      Compare plans

      $ python scripts/verify.py # the done set, each gate PASS / FAIL / NOT RUN contract · planted_suite · agent_controls code_shape · examples · context_cost markdown · lint · own_enforcement
      Business

      Controls that refuse, evidence an auditor can read.

      An instruction file cannot stop an agent. Every Thea control is enforced, tested and recorded.

      • Narrow tools, sandboxed writes, spend and step budgets
      • Named actions wait for a human approval; a hash-chained audit trail
      • SSO, self-hosted control plane, signed provenance

      Compare plans

      # controls, each with a planted bypass that must be refused narrow_tools only the tools the task needs sandbox writes stay in the worktree budget stop at declared spend and steps approval named actions wait for a human effects side effects declared, then checked audit hash chain; an edit is named

      Adopt in stages, enforce when ready.

      Observe, then block, then govern. Each stage is one step; your agents stay as they are.

      1. Day one

        Advise

        Agents ask before they edit. Nothing blocks yet.

      2. First week

        Enforce

        Add the git hook and required CI check. Failed changes cannot merge.

      3. Team and Business

        Govern

        Turn on controls, share the failure ledger across repositories and give leads a dashboard.

      Runs where your code already lives.

      Your machine

      The CLI, hooks and MCP server run locally over standard input and output.

      Your CI

      A check in your own GitHub Actions marks every pull request.

      Your control plane

      A self-hosted control plane for shared policy, history and audit.

      Bring Thea to your team.

      Start free, or join the Business design-partner program.

      The governance layer for AI coding agents.

      Eight layers. Each answers one thing an agent should never guess.

      Wherever your agents run.

      One contract, every surface. Three ship today.

      It remembers every mistake, and guards it.

      Once is a bug. Twice is a rule.

      Seen twice becomes a rule

      How often it recurred, the guard that refuses it, the move that replaces it.

        thea failures

        Moves that worked, kept

        The move, when it applies and how it was verified.

          thea successes

          No claim without code

          Every declaration must resolve to the file that implements it, or the build fails.

          agreement.lock · atlas.py check

          Small by design

          Agents ask for one file's route instead of reading the tree.

          verify.py context_cost

          Nothing drifts

          No calendar dates in tracked text, no unbounded unpushed work, no hand edits to generated files.

          dated claims · unpushed_bound · generated files

          Every language, one contract

          Every language carries a guide, a card and a manifest.

          languages/ · cards · instruments

          Enforced, never only declared

          Each hard invariant names the function that enforces it. A control with no enforcer is refused.

          thea invariants

          One route for every agent change

          Same five steps for any agent. Each verdict is an exit code.

            thea commands

            A proof contract, not a plugin.

            Review gives an opinion. Thea gives a standard: one file that defines what proves a change.

            The method is public.

            The contract, gates and language packs are open source.

            A badge that links to proof.

            A README badge that opens the latest verdict.

            Signed verdicts.

            Signed verdicts an auditor can check without rerunning.

            Every repository gets an executable constitution.

            README, AGENTS.md, CI config and tribal knowledge become one contract the build checks.

            From edit to approved merge.

            The agent asks which checks apply. The change cannot merge until they pass.

            Port

            One record per file: route, tier, gates, past lessons and the next command.

            $ thea port scripts/verify.py --frame agent

            Gate

            The numbered commands that prove a change to this exact file.

            Verify

            Exit 0 only if every gate passed. NOT RUN is never a pass.

            $ python scripts/verify.py

            Land

            Push, pull request and merge in one step. Refused on conflict.

            $ python scripts/branchstate.py --land

            Port speaks to whoever asks.

            The same file record, framed for its audience with --frame.

            Plug in where you work.

            Change classes add gates.

            Pass a class with --change; the plan adds the gates that class requires on top of the file's own.

            $ python scripts/atlas.py plan <path> --task implementation --change security_sensitive --json

            The done set, every time.

            scripts/verify.py runs each of these once and exits 0 only if all of them pass.

              A building inspector for AI-written code.

              The agent builds. Thea checks the work and remembers every defect.

              Know what "done" means

              Every change shows which checks ran and passed.

              Catch breakage before it merges

              A failed or skipped check stops the change at commit and at pull request.

              Stop repeat mistakes

              A mistake seen twice becomes a tested rule.

              Keep your agent and your tools

              Claude Code, Codex, opencode, Hermes or a script, with the tools you already have.

              Spend fewer tokens

              Agents ask for one file's checks, not the whole repository: 89% fewer tokens, measured.

              Free, local, yours

              MIT licensed, on your machine. No account, nothing to host.

              Check
              A command your project already trusts, such as its tests or type checker. Thea calls it a gate.
              Contract
              One small file that says which checks prove which kind of change.
              Verdict
              PASS, FAIL or NOT RUN, taken from the check's exit code, never from the agent.
              Ledger
              The record of past mistakes, each paired with the guard that now stops it.

              From prompt to production.

              Agents write the code. Nothing governs it.

              Agents report "done" whether or not anything was checked.

              "All tests pass." Which tests, run where?

              A claim is not evidence. The diff does not say what ran.

              Every gate reports PASS, FAIL or NOT RUN from its exit code.

              Rules in a README are suggestions.

              Docs describe the process. Nothing stops an agent skipping a step.

              One executable contract, enforced at commit and at landing.

              The same mistake, every week.

              Each session starts from zero and repeats last week's failure.

              A ledger of failure shapes, each paired with its replacement move.

              Infrastructure, not another agent.

              Thea holds every agent to the same contract.

              Your agents

              Contract · Port · Gates · Verify · Enforce · Control · Memory

              CLIMCP serverGit hooksCI workflowllms.txt
              FormattersCompilers and typecheckersTest runnersLinters and scannersGit and GitHub
              Your toolchain, unchanged

              One change, four steps.

              Thea adds proof, a verdict and a memory.

              1. 01

                Your agent changes a file.

                Any agent, unchanged.

              2. 02

                Thea names the proof.

                The exact commands that prove it. Riskier changes get more.

              3. 03

                The checks run. The exit code decides.

                PASS, FAIL or NOT RUN. Nothing is taken on the agent's word.

              4. 04

                Bad work is stopped. The lesson is kept.

                A failed change cannot land. A repeat mistake becomes a rule.

              Agent

              Instructions advise. Thea enforces.

              Columns are categories, not named products.

              Built inPartly, or only if someone writes itNot covered

              Evidence, not adjectives.

              Recorded runs. Each figure names the instrument behind it, so you can rerun it.

              With TheaBlind

              Context and footprint

              • Tokens before routing1,724
              • Fewer than tool lists89%
              • Pairs answered324/324
              • Random baseline2.8%
              • Install8 KiB · 1 dep

              README generated block · 3.52.0

              Cross-model

              99%

              with Thea against 59% blind, across 11 models from 5 providers

              abtest.py · 11 models · 2,409 questions

              Enforcement

              17/17

              planted broken commits refused at the hook

              enforce.py · v3.52.0

              Self-test

              461

              planted mistake kinds, each refused by a test

              planted suite · 3.52.0

              A real run, failures included.

              One recorded python scripts/verify.py on a working branch. It exited 1, and the record says exactly why.

                Failure ledger

                105

                failure shapes filed, each with a guard; 40 success moves that replace them.

                $ thea failures

                Agent controls

                119/119

                control tests passing in the same run; each plants a bypass that must be refused.

                $ python scripts/verify.py

                Scope: these are evidence for routing, checks and refusals, not for end-to-end task success.

                The difference is the evidence.

                Same model, same edit. Left is illustrative; right is a recorded Thea run.

                Without Theaillustrative
                  Merged on the agent's word. Two failing gates go unnoticed.
                  With Thearecorded
                    Refused before landing. The verdict names the two gates that failed and the one that could not run.

                    Agent autonomy, with enforced limits.

                    Controls refuse rather than warn, and each names the function that enforces it. Audit-ready by default.

                    Generated sandboxes

                    Generated Docker or macOS sandboxes: no network, only the worktree writable.

                    $ python scripts/sandboxgen.py docker <contract>

                    Public by design, secret-free by rule

                    Staged secrets are blocked before a commit exists, and the line is named.

                    Supply chain

                    OpenSSF Scorecard and dependency review run in CI. Toolchain downloads are checked against digests pinned in the contract.

                    Read-only by default

                    The MCP server exposes read-only commands. Each tool's exit code is its verdict.

                    Security model

                    Verify what you install.

                    Releases are deterministic tarballs with build attestations. Dependencies install only against pinned hashes.

                    Check a release

                    gh release download "$TAG" --pattern 'atlas-*' --repo HLIntel/thea-software gh attestation verify atlas-$TAG.tar.gz --repo HLIntel/thea-software shasum -a 256 -c atlas-$TAG.tar.gz.sha256

                    Install with hashes

                    git clone --depth 1 --branch <tag> https://github.com/HLIntel/thea-software python -m pip install --require-hashes -r scripts/requirements.lock.txt python scripts/atlas.py doctor

                    Pin a tag, never main.

                    Free for one agent. Priced by how many you run.

                    CLI, MCP server, hooks and every language pack: MIT, no agent limit. Plans price the dashboard and team features.

                    What each plan includes.

                    Common questions.

                    Install Thea your way.

                    Free and open source. Download, run three commands, and every agent on the machine is governed.

                    Thea Dashboard for Mac

                    See every agent, check and guard in one window (tour). Installing it puts thea and thea-mcp on PATH too, and Connect wires them into each agent.

                    Join the waitlist

                    Every agent on one screen.

                    A local app for what Thea recorded: agents, changes, checks. Private beta for Mac.

                    Thea Dashboard · Checks
                    Changed filesthea verify --changed
                    src/billing/invoice.pypython · format, types, testsPASS
                    web/app/routes.tstypescript · lint, typesFAIL
                    db/migrations/0042.sqlsql · migration checkNOT RUN
                    README.mdmarkdown · lintPASS
                    Illustration with example data.

                    Eight pages, each with one source.

                    Each page reads one Thea command or file. A failed source shows NOT RUN and the error.

                    Agents and sessionsEach runtime's own session files
                    Changesgit log and git status
                    Checksthea verify --changed, run when edits pause
                    Healththea resume
                    Mistakesthea failures: the failure ledger
                    GitHubLocal repositories, and GitHub through device sign-in
                    ConnectEach agent's MCP config and its own sign-in command
                    Modelthea model: the decision layer's judgments

                    Local by design.

                    The dashboard is a reader. Verdicts come from your toolchain through Thea, and they stay on your machine.

                    Loopback only
                    Binds 127.0.0.1 and refuses any other host.
                    Per-run token
                    Each launch gets a fresh token, compared in constant time.
                    Strict headers
                    Same-origin CSP, no caching and no request log.
                    No key needed
                    No account, no webhook and no API key to run it.

                    One record, every reader.

                    CLI, hooks, CI and dashboard read one verdict. Team sync is next: opt-in, verdicts only, never source.

                    Your code stays on your machine. Not by promise. By test.

                    Thea runs locally and writes only where you choose. No account, no telemetry, no Thea server.

                    What Thea stores, and where

                    Verdicts, ledgers and contracts live in your repository, under your own git history. The live agent count lives in ~/.thea/sessions on your machine: one small file per session holding the agent's name, its session id, its working directory and when it was last seen.

                    Never a prompt, a command, a diff or a file's content. Records unseen for a week are removed.

                    Nothing phones home

                    No telemetry, licence server or sign-in. Enforcement works offline, and the agent count never decides whether a check runs.

                    Enforced by a failing test

                    The test suite scans every shipped Python file for network imports. Only the modules below may make one; anywhere else, the suite fails before the change lands.

                    Your storage, your cloud

                    Everything Thea keeps is plain files in your repository and home directory. Team sharing, when it ships, will use storage you control.

                    The only code that can reach the network.

                    Each runs only when you start it, with your own keys or remote, and talks only to the service you point it at.

                    • Model benchmark: asks the models you configure the same questions with and without Theaabtest.py
                    • Model providers: the endpoints and key names you set for that benchmarkproviders.py
                    • Repository audit: compares your live GitHub settings with your declared ones, using your tokenghaudit.py
                    • Retry wrapper the three above share; opens no connection of its own choosingresilience.py

                    What the scan does not cover

                    It reads Python imports. Git commands go only to the remotes you configured. Your agents, editor and model providers keep their own policies.

                    This website

                    No analytics, cookies, tracking or forms, and no web fonts. Live figures are read from the public README on GitHub, with jsDelivr as a fallback. Nothing you type or click is sent.

                    Policy for contract 3.52.0. Check it yourself: the scan is the case only the declared modules can open a network connection in the planted suite, and its source is on GitHub.

                    Put a contract on your agent. Then let it refuse.

                    Pick where you work. Each path ends with a contract in your repository and checks that refuse unproven changes. Pinned to 3.52.0.

                      Four places a change can be refused.

                      Turn on what you need. A gate skipped at the edit still stops the change later.

                      Paste once. Every chat starts routed.

                      A chat that cannot run code still names gates, reviews a pasted diff and labels claims. Paste into project instructions.

                      Go deeper when you need to.

                      Detailed docs, from first gate to fleet.

                      Install, commands, MCP server, enforcement and controls. Every example comes from the repository.

                      Browse all docs

                      Thea on your Home Screen

                      Opens full screen, like an app.

                      1. 1Tap Share . If you only see •••, tap that first.
                      2. 2Scroll and tap Add to Home Screen.
                      3. 3Leave Open as Web App on, then tap Add.

                      This browser cannot add apps. Open this page in Safari, then tap Share › Add to Home Screen.

                      Open the browser menu ⋮ and tap Install app or Add to Home screen.

                      On your phone, open in Safari or Chrome, then use Add to Home Screen.

                      Thea is already installed on this device.