A self-hosted build platform

Start from a platform, not from an empty directory

Describe what you need. Get a repository that compiles, applies its migrations and boots — with row-level security, an audit trail, feature flags and human approval gates already in it, and 139 capabilities to reuse before you write any.

No signup for the intake. It runs in your browser and produces a file you own.

13stages, from a prompt to an operable capability
7tracks, each reshaping which stages apply
139capabilities already built, to reuse before building
3gates where a human is required

Ninety seconds

Watch it happen

A replay of a real run, not a mock-up — every line below was captured from the commands as they are printed above. If the tool changes and this does not, the two disagree in public.

Both are the same run. The video is a recording of the terminal below it, and the terminal's lines were captured from the commands actually executing — regenerated by a script, so neither can drift into showing output the tool does not produce.

Why adopt this

Six arguments, each with something you can check

Every claim below is either a property of being self-hosted or a test you can run. There are no customer logos on this page because there are no customers to name yet, and inventing one would contradict everything else here.

There is no exit to negotiate

The whole platform is YAML, SQL and Java in a repository you own. Nothing is indexed off-box, so data residency, content portability and the AI clause of a DPA stop being vendor conversations and become your own configuration.

→ the trade: no hosted SLA. The two come together.

Governance that executes

Standards stop depending on whether a reviewer was paying attention. Every generated repository ships gate tests and runs them in CI from its first commit — row-level security forced, rollback notes present, migrations contiguous.

→ each gate traces to a defect that reached production.

Reuse before rebuild

Rebuilding identity, notification, consent or audit is the most expensive mistake available, and duplicates never get deleted. The catalogue is consulted at stage one, before the work starts, not in a design review after it.

→ 139 capabilities across 14 domains.

One authorisation decision

Page, search, AI citation and the agent tool catalogue all ask the same policy, and a test asserts they cannot disagree. Premium material hidden from a page does not reappear in the answer box — the leak that is hardest to notice.

→ a property a demo cannot show and a test can.

Provenance you can verify, not a claim you have to accept

Every generated file is hashed into a manifest, and the manifest is signed — a detached signature in the OpenSSF Model Signing format, beside the repository rather than inside it. Change one byte of one file and rathvan verify names the file. Rewrite the manifest to match and it fails on the signature instead.

→ run rathvan verify . on your own repository; it exits non-zero for anything but a tree matching a signed manifest. The signing key can be a KMS key that cannot be exported at all.

The model call can stay inside your network

Generation runs through a chain of model vendors, and one of the links can be an inference container on your own GPUs. Point it at yours and a product's requirements, architecture and tests are written without a byte leaving your infrastructure — the same code path, one environment variable different.

→ the honest limit: the hosted vendors are the default, and which one actually answered is recorded on every generation.

What you start with

110 capabilities, already built

These exist in the kernel, carry migrations, and come across when you select the band that holds them. Reusing one is a line in a config file; rebuilding it is a quarter. 29 more are named and not yet demonstrated — they are marked as proposed wherever they appear, and this page will not count them as built.

Growth & Engagement 15

Core — every product needs it

Content Management · Publication · Learning · +12 more

Development Ecosystem 14

Essential — most products need it

AI-Native App Development · No-Code Development · Component & UI System · +11 more

Professional Network 13

Core — every product needs it

Professional Directory · Credential Verification · Client Assignment · +10 more

Data 12

Core — every product needs it

Data Persistence · Data Definition · Data Movement · +9 more

Platform Foundation 12

Essential — most products need it

Tenancy · Onboarding · Feature Flags · +9 more

Security & Compliance 12

Essential — most products need it

Application Security · Data Security · API Security · +9 more

Identity 10

Core — every product needs it

Authentication · Authorization · Identity Core · +7 more

AI Fabric 9

Core — every product needs it

AI Context · Model Routing & Failover · Grounded Generation · +6 more

Monetization 9

Core — every product needs it

Pricing Configuration · Billing · Subscription Management · +6 more

Embedded Fintech 9

Core — every product needs it

Payments Orchestration · Payouts · Money Movement Rails · +6 more

Wealth & Protection 8

Core — every product needs it

Portfolio Management · Fund Holdings · Trading · +5 more

Legal Services 6

Core — every product needs it

Legal Corpus · Case Research · Matter Intake · +3 more

Enterprise Architecture 5

Essential — most products need it

Capability Registry · Platform Value Delivery · Plan Management · +2 more

Human Intelligence 5

Core — every product needs it

Expert-in-the-Loop · Expert Evaluation · Skill Management · +2 more

Start from a blueprint, not from empty

Each one is a named starting point, composed from what already exists rather than curated by hand — so a blueprint cannot advertise something the scaffolder would refuse. A domain the platform will not build does not appear here at all.

What a blueprint is not: a template you fill in. It renames the nouns and brings the tables, the tenancy, the audit trail and the gates. What the work is FOR is yours to write, and that is the part that takes the time.

Education platform

A tutor serves a student through an course. Tenancy, identity, audit and the domain tables exist before you write anything.

--domain EDUCATION

Financial services platform regulated

A advisor serves a client through an engagement. Tenancy, identity, audit and the domain tables exist before you write anything.

--domain FINANCE

Healthcare platform regulated

A doctor serves a patient through an consultation. Tenancy, identity, audit and the domain tables exist before you write anything.

--domain MEDICAL

Legal services platform regulated

A advocate serves a client through an matter. Tenancy, identity, audit and the domain tables exist before you write anything.

--domain LEGAL

Logistics and field service platform

A operator serves a shipper through an job. Tenancy, identity, audit and the domain tables exist before you write anything.

--domain LOGISTICS

Property platform

A agent serves a buyer through an listing. Tenancy, identity, audit and the domain tables exist before you write anything.

--domain PROPERTY

Recruitment platform

A recruiter serves a candidate through an placement. Tenancy, identity, audit and the domain tables exist before you write anything.

--domain RECRUITMENT

Security platform

A analyst serves a asset owner through an incident. Tenancy, identity, audit and the domain tables exist before you write anything.

--domain SECURITY

Something else platform

A professional serves a client through an engagement. Tenancy, identity, audit and the domain tables exist before you write anything.

--domain OTHER

How it works

From one sentence to a service that answers

Four steps. Nothing is installed until the third, and the plan is printed before anything is written to disk.

01
~20 min

Describe it, and answer what it asks

One sentence at build.rathvan.com. The intake reads what it can and asks only what is left, showing the words it matched for every answer it filled in. Six questions are never pre-filled: they are irreversible, and a decision made by not reading a screen is not a decision.

open https://build.rathvan.com → download rathvan.json
cd ~/Downloads

Nothing installed and nothing to sign up for: the console is a static page and the file is written by your browser. It lands in your downloads folder, and the CLI reads rathvan.json from whichever directory you are standing in — so work from where the file is.

You will need Node 20+ (for npx) and a JDK 21+ — the thing being scaffolded is a Java project, and the CLI checks for both before it starts rather than failing forty lines in.

02
1 min

Read the plan before it writes anything

You see every file that will be created, everything that will be skipped with the reason, and a warning when the selection is unusual for what you described.

npx "https://build.rathvan.com/rathvan-cli.tgz?v=c96f20c2448c" new ./your-product

Prints the plan and writes nothing. If more than one rathvan.json is in that folder an older one is read silently, so name the one you mean: --config ./rathvan.json.

03
2 min

Write it, and let it build itself

The CLI runs the build it just generated and reports the test counts — rather than printing "next, run the build" and leaving you to discover a broken tree. A failure is diagnosed, and it names whose problem it is: the scaffold, your machine, or your change.

npx "https://build.rathvan.com/rathvan-cli.tgz?v=c96f20c2448c" new ./your-product --yes
  ✓ BUILD SUCCESSFUL   4 tests · 4 passed · 0 failed
04
2 min

Check it yourself — and mind which command you use

Four gates run: the migrations are present, numbered contiguously, carry rollback notes, and every table with row-level security has it forced as well as enabled — because ENABLE alone does not apply to the table owner, which is the role your application connects as.

cd ./your-product && ./gradlew testCounts
  4 tests · 4 passed · 0 failed · 0 skipped

Not ./gradlew test. An up-to-date test task prints BUILD SUCCESSFUL having run nothing, which looks exactly like having run everything — 4 actionable tasks: 4 up-to-date is not a passing suite. testCounts never goes up-to-date, prints the count, and fails when it drops. check and build depend on it, so those are safe too; it is test alone that will lie to you. The generated README says so as well.

05
optional

Connect a builder, if you want the loop rather than the scaffold

Steps 1–4 need no server: the console is a static page and the CLI runs on your machine. The console becomes a client only when you point it at a builder you run — and until you do, it says so in every artifact it renders rather than implying work happened.

git clone <this repo> && cd rathvan
./setup.sh

One script for a machine that has never seen the repository. It checks the prerequisites first — a missing JDK is a sentence, not a stack trace forty lines in — builds the kernel, the builder service, the console and the CLI, generates a token, and then verifies: the gates in all three modules, the console's drift check, and a throwaway product scaffolded and built. "It installed" and "it works" are different claims that look identical from the outside. ./setup.sh --check reports and changes nothing.

build-platform/service/build/install/rathvan-builder/bin/rathvan-builder

Configuration comes from ~/.rathvan/builder.properties, ./builder.properties or --settings <path> — so a key is set once rather than re-exported in every shell. The environment wins over the file, deliberately: a file is a default and what you type is an intent. The startup banner says where a key came from and never what it is.

Then the connect sheet in the console header: the endpoint above, any email, and the token as the password. A builder on your own machine is called by your browser directly — the hosted proxy runs at Cloudflare's edge, where localhost is the edge's own network and never your laptop.

06
2 min

Credentials, if you are not going through a builder

A scaffolded product deploys itself, opens its own pull requests, and points a hostname at what it deployed. Every one of those needs a credential this platform deliberately does not hold — and until now there was nowhere to put them, so they lived in whichever shell happened to be open.

rathvan config set GITHUB_TOKEN
rathvan config set CLOUDFLARE_API_TOKEN
rathvan config set GCP_SERVICE_ACCOUNT_KEY
rathvan config test

The value is never an argument. set prompts and does not echo, because a secret typed as an argument is in your shell history and in the process list of everyone on the machine for as long as the command runs. --stdin exists for scripts, where a pipe is the point.

test makes one read-only call per credential to the provider's own endpoint and reports the identity, not just validity — GITHUB_TOKEN as qiseed is a different answer from valid, and the difference is what catches a token belonging to the wrong account. A credential with no probe says so rather than showing a tick: "we did not check" and "we checked and it is fine" must not look the same.

Stored at ~/.rathvan/credentials.properties, mode 600, and it warns if the file is readable by others. This is not a secret manager — it is a file with the same protection as your SSH key. A team sharing credentials wants Vault or Secret Manager, both of which the catalogue lists under secrets. Anything exported in your environment wins over the file, and list tells you which is in force.

07
optional

Give it a model, and it generates

Without one the builder still starts, authenticates and reads state — and refuses to generate, naming the missing half rather than failing somewhere unrelated. That refusal is the same fact builderFeature { live } already reported, said at the point it bites.

ANTHROPIC_API_KEY=sk-ant-...   in ~/.rathvan/builder.properties

The adapter lives in service/ and never in the kernel — ports and adapters, no vendor import in core, with a test that walks the kernel source and fails if it ever names the endpoint. Swapping vendors is a constructor argument. Grounding is a separate labelled block rather than glued to the prompt, because retrieved facts and instructions are different kinds of thing and a model that cannot tell them apart will follow text it was only meant to read.

What you get today

The parts that are built, not planned

Everything below runs now. Where something is missing or gated, this page says so — that rule is the reason the rest of the page is worth reading.

Five model vendors, including local

Anthropic, Gemini, Claude-via-Vertex, OpenAI and a local runtime, behind one port. The chain fails over across vendors, and every answer records who served it.

a retired model is an environment change, not an incident

Your keys, held properly

Bring your own model key per user: encrypted at rest, never readable back out, and placed at the head of your chain with the platform's behind it — so a spent key fails over instead of going dark.

no key, no storage — plaintext is never a fallback

Repositories connected per repository

A GitHub App you install on exactly the repositories you choose. Access tokens are minted on demand, live an hour, and are never stored — and a connection cannot be claimed by anyone the flow was not started by.

revoke it from GitHub, and it is revoked

Runs on your own machine

A desktop image with a bundled Java runtime and its own console, or the CLI with nothing installed at all. Documentation you point it at becomes the grounding its answers cite.

nothing leaves the box you run it on

Use cases

Seven tracks, and each reshapes the pipeline

A track is not a label on a project. It decides which stages tighten, which relax, and where the work is allowed to ship — which is why a workspace belongs to exactly one of them.

Build or edit a web app

Create from scratch, or change an existing codebase

ships to production 3 human gates

Create prototypes

Shareable, true to brand and design system

ships nowhere cannot ship

Convert designs to code

stops at a pull request 1 human gate

Manage content

Generate, iterate and optimise pages and headless content

ships to production 1 human gate

Marketing sites

ships to production 2 human gates

E-commerce

ships to production 3 human gates

Personalization

never average across variants — the aggregate hides the losing one

ships to production 2 human gates

Who it is for

Three teams, three entry points

Nobody starts at stage one. Where you enter depends on what you already know.

Platform engineering

You own golden paths and nobody follows them. Ship a scaffold that carries the standards inside it, so conformance is the default rather than a review comment.

enters at ③ architecture

A product team starting something

You need a service with auth, audit, tenancy and migrations before you can write the part that is actually yours. That is a fortnight you can have back.

enters at ① reuse map

A developer ecosystem

Partners integrate without talking to you: dynamic client registration, scoped tokens, and a capability catalogue their agents can consume over MCP.

enters at ④ design

Refusals

What it will not do, structurally

Not policy, not a confirmation dialog. Each is prevented by the shape of the code, which is the difference between a rule and a preference.

Reach production on its own STAGED is the last state. No method expresses the move past it, so no amount of approval gets there without a person.
Ship a prototype The prototype track has its own namespace, no production credentials and an expiry. It cannot quietly become the real thing, because there is nowhere for it to go.
Advance on a simulated build A stub source control reports its checks as NONE, and NONE does not pass. A demo can never produce a staged workflow.
Regenerate on no feedback Rewriting an artifact requires saying what should change. Without that it is rerolling the dice, not reviewing.
Approve what nobody saw Approval is stamped onto the exact version under review, so a later regeneration cannot inherit it.
Lose a decision Every transition writes an audit event naming its actor — including the refusals.

Gates

Three places a human is required

Everything between them can run unattended once the owner has said so for that session. These three cannot, and the colour they are drawn in is used for nothing else on this page.

Gate 1

Agreement, before any code

Problem, criteria, and what is deliberately out of scope. Half the expensive failures were decided here, before a line was written.

Gate 2

Staging, before production

A landed rollout on a known stack, confirmed by a real query against the deployed host rather than by a green pipeline.

Gate 3

Readiness, before it is called live

A flag, a rollback, a runbook, limits, a cost and a named owner. Without them a capability is running, not live.

Where it runs

Your cloud, your repository, your region

Self-hosted, which is one decision with a great many consequences. Data residency is yours to set. Nothing is indexed off-box. There is no exit to negotiate, because the platform is already in a repository you own. It also means there is no hosted SLA — that trade comes as a pair, and it is worth knowing which side you are choosing.

Start with the intake. It costs nothing and installs nothing.

Twenty minutes of questions produces a file that describes your product. What you do with it afterwards is your decision.