Featured now: Start with Jaawac’s free beta, or request access to the AnchorScape pilot.
Try Jaawac Request AnchorScape
03

03 / Governed coding CLI

Plumb

Plumb turns a PRD or coding instruction into formal invariants, orchestrates adversarial engineering roles, locks governing requirements away from the implementation agent, proves completeness and deploys the exact certified artifact with rollback evidence.

LIVE PRODUCT / SANITISED
A real Plumb completeness proof showing the governed build blocked missing authorization and rate limiting while two code-producing controls failed acceptance

Not a concept render

This is the product.

Implemented and tested: governed/resumable orchestration, independent invariant certification, adversarial role separation, sandboxed tools, encrypted secret vaults, provider routing, completeness proof, certified releases, deployment health checks, auto-rollback, durable audit and CLI packaging.

Plumb capabilities

More than the headline feature.

Plumb is a connected product system. These capabilities are implemented in its current architecture, interfaces and operating workflows.

Executable invariants

Formalise requirements as independently certified tests for Vitest, Jest, pytest, Go, Rust and Java—with vacuity checks and runner canaries.

Adversarial engineering seats

Seven named delivery seats plus Professor, Kenzo, Re-engineer, Sentinel and Designer reviewers separate implementation from oversight.

Completeness barrier

Detect missing production obligations before code is accepted. Its offline three-arm proof catches omissions that one-shot and control runs miss.

Locked governance

Shadow Git checkpoints and locked paths stop an agent from rewriting the requirements or tests that govern its own success.

Multi-provider, fail-loud routing

Use OpenAI- and Anthropic-compatible providers with explicit routing, cost attribution and no silent model substitution.

Sandboxed tools and secrets

Docker boundaries, realpath confinement, shell-free argv execution and two encrypted vaults keep tool and secret handling structural.

Byte-exact releases

Certify one artifact, revalidate its bytes and promote the same code hash through dev, QA and production while environment data stays separate.

Deploy, reconcile and roll back

Health checks, crash-safe deployment reconciliation, automatic rollback and durable journals connect coding to an operated release.

Used by Infinovation

The harness can prove why generated code is not enough

Plumb ships a real offline completeness proof. In the captured run, its governed barrier stopped missing per-endpoint authorization and rate limiting before build; a governed control without that barrier and a one-shot implementation both produced code and both failed held-out acceptance.

Real-world comparison / Claude Code, OpenAI Codex, Gemini CLI and GitHub Copilot

Plumb belongs in the actual market conversation.

Compared with Claude Code, OpenAI Codex, Gemini CLI and GitHub Copilot on the work each product is designed to do. This is positioning by architecture and workflow—not a claim that every product serves the same user.

Market axisNamed alternativesPlumb
Interactive codingClaude Code and Codex are frontier coding agents that read repositories, edit files, run commands and complete substantial engineering tasks.Plumb can route capable models but makes the delivery harness—not one model—the authority over requirements, review and release.
Open-source coding agentGemini CLI brings an open-source terminal agent and Google model/tool ecosystem.Plumb adds provider-neutral routing, executable invariants, adversarial seats and a release certification chain.
IDE and repository assistanceGitHub Copilot combines editor assistance, chat and coding agents closely with GitHub workflows.Plumb is built for governed end-to-end delivery, including completeness proof, byte-exact promotion and deployment reconciliation.
Quality controlCoding agents can run tests and follow repository instructions; CI validates the resulting branch.Plumb locks governance paths, independently certifies the tests, challenges omissions and preserves evidence at every oversight boundary.
Read the full Plumb vs Claude Code, Codex, Gemini CLI and GitHub Copilot guide

Common questions

About Plumb

Is Plumb publicly available?

Not as a public hosted service. It is in private access as a production candidate for local and single-tenant use.

What makes it governed?

Its gates, tool boundaries, release checks and audit evidence are implemented in the harness rather than expressed only as instructions to a model.

Can it deploy software?

Yes, through configured shell-free adapters with health checks, promotion controls and automatic rollback behavior.

Start a conversation

Interested in Plumb?

Talk to us about the current access path, product fit and what is coming next.

Discuss private access