Skip to content
About

About Frontal

We're building the tool we wished we had: software development by description, not by typing.

Mission

Software development by description, not by typing.

Frontal Codes exists because the gap between what you want and what you have to type to get it has never been wider. AI coding agents are powerful — but untamed, they're chaos. They forget. They corrupt each other's work. They ship "tests passed" that don't match what you meant.

We're building the orchestration layer that turns raw LLM capability into deterministic software delivery. Describe a goal in plain language. Frontal plans it, decomposes it into atomic tasks, dispatches coding agents to isolated sandboxes, validates the result against your actual acceptance criteria, and merges — with rollback, budgets, and a memory graph that prevents re-discovery.

The user's only job is the single human gate: approve the plan. Everything else is observable, reversible, and audited. That's the product.

Principles · from DECISIONS.md

Six invariants we don't violate.

Each maps to a real architectural decision. They aren't slogans — they're enforced in code and verified by tests.

Local-first

Your code, your machine, your secrets. Self-hosted mode never leaves your host. Cloud is opt-in.

Architectural posture

English Source of Truth

Internal language is English end-to-end. Translation happens only at the locale boundary. Never bake user-locale strings into core logic.

D-003 · Locale boundary

Event Log is Authoritative

HMAC-chained append-only log is the source of truth. ArangoDB memory graph is a rebuildable view. Lose the DB, keep the memory.

D-004 · Rebuildable graph

Gateway-Only Model Access

Provider keys never reach the engine. One local gateway owns every model call, every circuit breaker, every meter.

D-002 · Keys never leak

Task Failures are Contained

One task failing never kills a plan run. Bounded retries, watchdog takeover, Needs-Attention escalation.

D-010 · Failure isolation

Honest AI

Acceptance criteria checked beyond green tests. Live preview the running app. No fake demos, no inflated claims.

Core product principle
Timeline · from PROGRESS.md + DECISIONS.md

What's been built. In order.

Reverse-chronological. Every entry is a real milestone — no aspirational bullets, no roadmap pretending to be history.

  1. D-001 – D-009 · Architectural foundations

    Project kickoff. Pi wire format isolated behind PiAdapter, gateway established, English source-of-truth translation layer, HMAC-chained event log, uv-managed deps, monorepo layout.

  2. D-010 – D-017 · Hardening wave

    Sandbox egress via internal-network proxy sidecar, watchdog ladder, bounded caches, zombie process reaping, MCP secret launcher shim, secrets vault.

  3. Golden Path · End-to-end contract green

    Full scenario passing: create → intake → plan → approve → real Pi engine writes code → sandboxed pytest → acceptance validation → merge → live preview → rollback.

  4. D-018 – D-026 · Frontend compilation

    Workspace Hub, Plan Review, Kanban, dual-layer activity feed, clarifying questions pipeline, interactive task board, per-project chat/session threads.

  5. D-027 – D-036 · Multi-sub-agent observability

    Sub-agent delegation tracking, nested live lanes, clarifying questions with long-poll, cross-project contracts, chat-flow persistence in ArangoDB, rollback-from-point and retry-from-point.

  6. D-037 · Dual-Engine

    Native in-house coding engine alongside Pi, per-task selectable with A/B harness. Backend 403 passed, frontend build clean, Pi untouched and still default.

The team

We're a small team building in the open.

No headshots to show you yet — just a repo full of commits. Every architectural decision is logged in DECISIONS.md. Every step forward is tracked in PROGRESS.md. We're not hiding behind a polished About page; we're shipping.

Read the repo
Values

What we stand for — and what we don't do.

What we value

Honesty over hype

PROGRESS.md is public. We ship when the golden path is green, not when the demo works.

Systems thinking over feature chase

Every component has an invariant. Every invariant has a DECISIONS.md entry.

Security-first, not security-later

Default-deny sandboxes, HMAC audit log, gateway-only keys. The safe path is the easy path.

Empathy for non-coders

The primary user can't read code. Every surface answers "is it working?" in plain language.

Local-first as a posture, not a fallback

Your machine, your keys, your code. Cloud is opt-in and deliberate, never default.

Real tests over inflated demos

Acceptance criteria checked against actual behavior. Live preview. No screenshot-driven marketing.

What we don't do

No GPL dependencies

Commercialization-ready stack. Dependency licenses are checked in CI.

No vendor lock-in

Self-hosted mode. Provider keys stay on your machine.

No telemetry without consent

No analytics, no crash reporting, no usage data sent anywhere. Self-hosted means just that.

No fake testimonials

No stock photos of smiling developers. No fabricated user counts. No "loved by X teams."

No "coming soon" features marked as shipped

Every feature in the docs is in DECISIONS.md. Every DECISIONS.md entry has a test.

Build with us

Read the architecture decisions.

Every invariant is logged. Every test is green. Every next step is tracked in PROGRESS.md.