Local-first
Your code, your machine, your secrets. Self-hosted mode never leaves your host. Cloud is opt-in.
Architectural postureWe're building the tool we wished we had: software development by description, not by typing.
Frontal Codes exists because the gap between what you want and what you have to type to get it has never been wider. AI coding agents are powerful — but untamed, they're chaos. They forget. They corrupt each other's work. They ship "tests passed" that don't match what you meant.
We're building the orchestration layer that turns raw LLM capability into deterministic software delivery. Describe a goal in plain language. Frontal plans it, decomposes it into atomic tasks, dispatches coding agents to isolated sandboxes, validates the result against your actual acceptance criteria, and merges — with rollback, budgets, and a memory graph that prevents re-discovery.
The user's only job is the single human gate: approve the plan. Everything else is observable, reversible, and audited. That's the product.
Each maps to a real architectural decision. They aren't slogans — they're enforced in code and verified by tests.
Your code, your machine, your secrets. Self-hosted mode never leaves your host. Cloud is opt-in.
Architectural postureInternal language is English end-to-end. Translation happens only at the locale boundary. Never bake user-locale strings into core logic.
D-003 · Locale boundaryHMAC-chained append-only log is the source of truth. ArangoDB memory graph is a rebuildable view. Lose the DB, keep the memory.
D-004 · Rebuildable graphProvider keys never reach the engine. One local gateway owns every model call, every circuit breaker, every meter.
D-002 · Keys never leakOne task failing never kills a plan run. Bounded retries, watchdog takeover, Needs-Attention escalation.
D-010 · Failure isolationAcceptance criteria checked beyond green tests. Live preview the running app. No fake demos, no inflated claims.
Core product principleReverse-chronological. Every entry is a real milestone — no aspirational bullets, no roadmap pretending to be history.
Project kickoff. Pi wire format isolated behind PiAdapter, gateway established, English source-of-truth translation layer, HMAC-chained event log, uv-managed deps, monorepo layout.
Sandbox egress via internal-network proxy sidecar, watchdog ladder, bounded caches, zombie process reaping, MCP secret launcher shim, secrets vault.
Full scenario passing: create → intake → plan → approve → real Pi engine writes code → sandboxed pytest → acceptance validation → merge → live preview → rollback.
Workspace Hub, Plan Review, Kanban, dual-layer activity feed, clarifying questions pipeline, interactive task board, per-project chat/session threads.
Sub-agent delegation tracking, nested live lanes, clarifying questions with long-poll, cross-project contracts, chat-flow persistence in ArangoDB, rollback-from-point and retry-from-point.
Native in-house coding engine alongside Pi, per-task selectable with A/B harness. Backend 403 passed, frontend build clean, Pi untouched and still default.
No headshots to show you yet — just a repo full of commits. Every architectural decision is logged in DECISIONS.md. Every step forward is tracked in PROGRESS.md. We're not hiding behind a polished About page; we're shipping.
PROGRESS.md is public. We ship when the golden path is green, not when the demo works.
Every component has an invariant. Every invariant has a DECISIONS.md entry.
Default-deny sandboxes, HMAC audit log, gateway-only keys. The safe path is the easy path.
The primary user can't read code. Every surface answers "is it working?" in plain language.
Your machine, your keys, your code. Cloud is opt-in and deliberate, never default.
Acceptance criteria checked against actual behavior. Live preview. No screenshot-driven marketing.
Commercialization-ready stack. Dependency licenses are checked in CI.
Self-hosted mode. Provider keys stay on your machine.
No analytics, no crash reporting, no usage data sent anywhere. Self-hosted means just that.
No stock photos of smiling developers. No fabricated user counts. No "loved by X teams."
Every feature in the docs is in DECISIONS.md. Every DECISIONS.md entry has a test.
Every invariant is logged. Every test is green. Every next step is tracked in PROGRESS.md.