A self-hosted build platform
Describe what you need. Get a repository that compiles, applies its migrations and boots — with row-level security, an audit trail, feature flags and human approval gates already in it, and 139 capabilities to reuse before you write any.
No signup for the intake. It runs in your browser and produces a file you own.
Ninety seconds
A replay of a real run, not a mock-up — every line below was captured from the commands as they are printed above. If the tool changes and this does not, the two disagree in public.
Both are the same run. The video is a recording of the terminal below it, and the terminal's lines were captured from the commands actually executing — regenerated by a script, so neither can drift into showing output the tool does not produce.
Why adopt this
Every claim below is either a property of being self-hosted or a test you can run. There are no customer logos on this page because there are no customers to name yet, and inventing one would contradict everything else here.
The whole platform is YAML, SQL and Java in a repository you own. Nothing is indexed off-box, so data residency, content portability and the AI clause of a DPA stop being vendor conversations and become your own configuration.
→ the trade: no hosted SLA. The two come together.Standards stop depending on whether a reviewer was paying attention. Every generated repository ships gate tests and runs them in CI from its first commit — row-level security forced, rollback notes present, migrations contiguous.
→ each gate traces to a defect that reached production.Rebuilding identity, notification, consent or audit is the most expensive mistake available, and duplicates never get deleted. The catalogue is consulted at stage one, before the work starts, not in a design review after it.
→ 139 capabilities across 14 domains.Page, search, AI citation and the agent tool catalogue all ask the same policy, and a test asserts they cannot disagree. Premium material hidden from a page does not reappear in the answer box — the leak that is hardest to notice.
→ a property a demo cannot show and a test can.Every generated file is hashed into a manifest, and the manifest is signed — a detached
signature in the OpenSSF Model Signing format, beside the repository rather than inside it.
Change one byte of one file and rathvan verify names the file. Rewrite the
manifest to match and it fails on the signature instead.
rathvan verify . on your own repository; it exits non-zero
for anything but a tree matching a signed manifest. The signing key can be a KMS key that
cannot be exported at all.
Generation runs through a chain of model vendors, and one of the links can be an inference container on your own GPUs. Point it at yours and a product's requirements, architecture and tests are written without a byte leaving your infrastructure — the same code path, one environment variable different.
→ the honest limit: the hosted vendors are the default, and which one actually answered is recorded on every generation.What you start with
These exist in the kernel, carry migrations, and come across when you select the band that holds them. Reusing one is a line in a config file; rebuilding it is a quarter. 29 more are named and not yet demonstrated — they are marked as proposed wherever they appear, and this page will not count them as built.
Content Management · Publication · Learning · +12 more
AI-Native App Development · No-Code Development · Component & UI System · +11 more
Professional Directory · Credential Verification · Client Assignment · +10 more
Data Persistence · Data Definition · Data Movement · +9 more
Tenancy · Onboarding · Feature Flags · +9 more
Application Security · Data Security · API Security · +9 more
Authentication · Authorization · Identity Core · +7 more
AI Context · Model Routing & Failover · Grounded Generation · +6 more
Pricing Configuration · Billing · Subscription Management · +6 more
Payments Orchestration · Payouts · Money Movement Rails · +6 more
Portfolio Management · Fund Holdings · Trading · +5 more
Legal Corpus · Case Research · Matter Intake · +3 more
Capability Registry · Platform Value Delivery · Plan Management · +2 more
Expert-in-the-Loop · Expert Evaluation · Skill Management · +2 more
Each one is a named starting point, composed from what already exists rather than curated by hand — so a blueprint cannot advertise something the scaffolder would refuse. A domain the platform will not build does not appear here at all.
What a blueprint is not: a template you fill in. It renames the nouns and brings the tables, the tenancy, the audit trail and the gates. What the work is FOR is yours to write, and that is the part that takes the time.
A tutor serves a student through an course. Tenancy, identity, audit and the domain tables exist before you write anything.
--domain EDUCATION
A advisor serves a client through an engagement. Tenancy, identity, audit and the domain tables exist before you write anything.
--domain FINANCE
A doctor serves a patient through an consultation. Tenancy, identity, audit and the domain tables exist before you write anything.
--domain MEDICAL
A advocate serves a client through an matter. Tenancy, identity, audit and the domain tables exist before you write anything.
--domain LEGAL
A operator serves a shipper through an job. Tenancy, identity, audit and the domain tables exist before you write anything.
--domain LOGISTICS
A agent serves a buyer through an listing. Tenancy, identity, audit and the domain tables exist before you write anything.
--domain PROPERTY
A recruiter serves a candidate through an placement. Tenancy, identity, audit and the domain tables exist before you write anything.
--domain RECRUITMENT
A analyst serves a asset owner through an incident. Tenancy, identity, audit and the domain tables exist before you write anything.
--domain SECURITY
A professional serves a client through an engagement. Tenancy, identity, audit and the domain tables exist before you write anything.
--domain OTHER
How it works
Four steps. Nothing is installed until the third, and the plan is printed before anything is written to disk.
One sentence at build.rathvan.com. The intake reads what it can and asks only what is left, showing the words it matched for every answer it filled in. Six questions are never pre-filled: they are irreversible, and a decision made by not reading a screen is not a decision.
open https://build.rathvan.com → download rathvan.json cd ~/Downloads
Nothing installed and nothing to sign up for: the console is a static page
and the file is written by your browser. It lands in your downloads folder, and the CLI
reads rathvan.json from whichever directory you are standing in — so work
from where the file is.
You will need Node 20+ (for npx) and a JDK 21+ — the thing
being scaffolded is a Java project, and the CLI checks for both before it starts rather
than failing forty lines in.
You see every file that will be created, everything that will be skipped with the reason, and a warning when the selection is unusual for what you described.
npx "https://build.rathvan.com/rathvan-cli.tgz?v=c96f20c2448c" new ./your-product
Prints the plan and writes nothing. If more than one
rathvan.json is in that folder an older one is read silently, so name the one
you mean: --config ./rathvan.json.
The CLI runs the build it just generated and reports the test counts — rather than printing "next, run the build" and leaving you to discover a broken tree. A failure is diagnosed, and it names whose problem it is: the scaffold, your machine, or your change.
npx "https://build.rathvan.com/rathvan-cli.tgz?v=c96f20c2448c" new ./your-product --yes ✓ BUILD SUCCESSFUL 4 tests · 4 passed · 0 failed
Four gates run: the migrations are present, numbered contiguously, carry rollback notes,
and every table with row-level security has it forced as well as enabled — because
ENABLE alone does not apply to the table owner, which is the role your
application connects as.
cd ./your-product && ./gradlew testCounts 4 tests · 4 passed · 0 failed · 0 skipped
Not ./gradlew test. An up-to-date test task
prints BUILD SUCCESSFUL having run nothing, which looks exactly like having run
everything — 4 actionable tasks: 4 up-to-date is not a passing suite.
testCounts never goes up-to-date, prints the count, and fails when it drops.
check and build depend on it, so those are safe too; it is
test alone that will lie to you. The generated README says so as well.
Steps 1–4 need no server: the console is a static page and the CLI runs on your machine. The console becomes a client only when you point it at a builder you run — and until you do, it says so in every artifact it renders rather than implying work happened.
git clone <this repo> && cd rathvan ./setup.sh
One script for a machine that has never seen the repository. It checks the
prerequisites first — a missing JDK is a sentence, not a stack trace forty lines in —
builds the kernel, the builder service, the console and the CLI, generates a token, and
then verifies: the gates in all three modules, the console's drift check, and a
throwaway product scaffolded and built. "It installed" and "it works" are different claims
that look identical from the outside. ./setup.sh --check reports and changes
nothing.
build-platform/service/build/install/rathvan-builder/bin/rathvan-builder
Configuration comes from ~/.rathvan/builder.properties,
./builder.properties or --settings <path> — so a key is set
once rather than re-exported in every shell. The environment wins over the file,
deliberately: a file is a default and what you type is an intent. The startup banner says
where a key came from and never what it is.
Then the connect sheet in the console header: the endpoint above, any email,
and the token as the password. A builder on your own machine is called by your browser
directly — the hosted proxy runs at Cloudflare's edge, where localhost is the
edge's own network and never your laptop.
A scaffolded product deploys itself, opens its own pull requests, and points a hostname at what it deployed. Every one of those needs a credential this platform deliberately does not hold — and until now there was nowhere to put them, so they lived in whichever shell happened to be open.
rathvan config set GITHUB_TOKEN rathvan config set CLOUDFLARE_API_TOKEN rathvan config set GCP_SERVICE_ACCOUNT_KEY rathvan config test
The value is never an argument. set prompts and does not
echo, because a secret typed as an argument is in your shell history and in the process
list of everyone on the machine for as long as the command runs. --stdin
exists for scripts, where a pipe is the point.
test makes one read-only call per credential to the provider's
own endpoint and reports the identity, not just validity — GITHUB_TOKEN as
qiseed is a different answer from valid, and the difference is what
catches a token belonging to the wrong account. A credential with no probe says so rather
than showing a tick: "we did not check" and "we checked and it is fine" must not look the
same.
Stored at ~/.rathvan/credentials.properties, mode 600, and it
warns if the file is readable by others. This is not a secret manager — it is a file
with the same protection as your SSH key. A team sharing credentials wants Vault or Secret
Manager, both of which the catalogue lists under secrets. Anything exported in
your environment wins over the file, and list tells you which is in force.
Without one the builder still starts, authenticates and reads state — and refuses to
generate, naming the missing half rather than failing somewhere unrelated. That refusal is
the same fact builderFeature { live } already reported, said at the point it
bites.
ANTHROPIC_API_KEY=sk-ant-... in ~/.rathvan/builder.properties
The adapter lives in service/ and never in the kernel — ports
and adapters, no vendor import in core, with a test that walks the kernel source and fails
if it ever names the endpoint. Swapping vendors is a constructor argument. Grounding is a
separate labelled block rather than glued to the prompt, because retrieved facts and
instructions are different kinds of thing and a model that cannot tell them apart will
follow text it was only meant to read.
What you get today
Everything below runs now. Where something is missing or gated, this page says so — that rule is the reason the rest of the page is worth reading.
Anthropic, Gemini, Claude-via-Vertex, OpenAI and a local runtime, behind one port. The chain fails over across vendors, and every answer records who served it.
a retired model is an environment change, not an incidentBring your own model key per user: encrypted at rest, never readable back out, and placed at the head of your chain with the platform's behind it — so a spent key fails over instead of going dark.
no key, no storage — plaintext is never a fallbackA GitHub App you install on exactly the repositories you choose. Access tokens are minted on demand, live an hour, and are never stored — and a connection cannot be claimed by anyone the flow was not started by.
revoke it from GitHub, and it is revokedA desktop image with a bundled Java runtime and its own console, or the CLI with nothing installed at all. Documentation you point it at becomes the grounding its answers cite.
nothing leaves the box you run it onUse cases
A track is not a label on a project. It decides which stages tighten, which relax, and where the work is allowed to ship — which is why a workspace belongs to exactly one of them.
Create from scratch, or change an existing codebase
Shareable, true to brand and design system
Generate, iterate and optimise pages and headless content
never average across variants — the aggregate hides the losing one
Who it is for
Nobody starts at stage one. Where you enter depends on what you already know.
You own golden paths and nobody follows them. Ship a scaffold that carries the standards inside it, so conformance is the default rather than a review comment.
enters at ③ architectureYou need a service with auth, audit, tenancy and migrations before you can write the part that is actually yours. That is a fortnight you can have back.
enters at ① reuse mapPartners integrate without talking to you: dynamic client registration, scoped tokens, and a capability catalogue their agents can consume over MCP.
enters at ④ designRefusals
Not policy, not a confirmation dialog. Each is prevented by the shape of the code, which is the difference between a rule and a preference.
STAGED is the last state. No method expresses the move past it, so no amount
of approval gets there without a person.
NONE, and NONE does
not pass. A demo can never produce a staged workflow.
Gates
Everything between them can run unattended once the owner has said so for that session. These three cannot, and the colour they are drawn in is used for nothing else on this page.
Gate 1
Problem, criteria, and what is deliberately out of scope. Half the expensive failures were decided here, before a line was written.
Gate 2
A landed rollout on a known stack, confirmed by a real query against the deployed host rather than by a green pipeline.
Gate 3
A flag, a rollback, a runbook, limits, a cost and a named owner. Without them a capability is running, not live.
Where it runs
Self-hosted, which is one decision with a great many consequences. Data residency is yours to set. Nothing is indexed off-box. There is no exit to negotiate, because the platform is already in a repository you own. It also means there is no hosted SLA — that trade comes as a pair, and it is worth knowing which side you are choosing.
Twenty minutes of questions produces a file that describes your product. What you do with it afterwards is your decision.