Your agent can't break this backend.
10 verified parts — content-locked in parts.lock and re-verified on every commit. Your AI agent writes the product; it cannot touch the infrastructure.
- 10 parts installed, owned in this repo
- 0 modified — every content-hash matches
parts.lock - 0 behind latest — all current
- attestations valid · earliest in 10d
Read live from parts.lock. Your own dashboard renders exactly this — in your repo, private, fed by the parts you installed.
your data & logic · metered vendors, swappable
Every byte is hashed in parts.lock. ctrlai guard fails CI on a single changed byte — your agent can't slip an edit past review.
Each part is cryptographically attested and re-verified in CI. Earliest expiry in 10 days.
140 tests pin the contracts. The behaviour can't silently drift out from under you.
parts/ is read-only to your AI agent. It writes only the thin seams; the infrastructure is untouchable.
$ ctrlai doctorRe-checks every part is unmodified, wired, and attested — the same verdict above, in CI or on demand.