dkod — the governed build pipeline for AI-built internal apps.
Across organizations, employees are vibe-coding internal tools that ship with no git, no auth, and secrets sitting in .env files. IT cannot see them, so IT cannot govern them. DKOD finds those apps, scores the risk, and rebuilds the ones that qualify from approved templates, in your own cloud.
Three parts. Find the apps first, then rebuild the ones worth keeping.
• dkod-signals — one static Rust binary, pushed by MDM to every macOS, Windows and Linux device. It runs once at low priority, inventories the apps built by Claude Code, Codex, Cursor and other agents, scores each for risk, and writes one metrics-only JSON report. It never uploads, never phones home, and never executes what it finds. Available today.
• Aggregation and reporting — rolls the per-device reports into an org-wide picture of AI-app risk. Coming.
• The governed build pipeline — rebuilds qualifying apps from hardened templates, with deterministic gates and human approval by risk tier. Anything outside the envelope gets a named blocker instead of a silent skip. Early access.
Nothing leaves your infrastructure without consent. Metrics-only by default.
15+ years building platforms at scale — AdTech, cloud infrastructure, Kubernetes, CI/CD, and high-throughput data pipelines. Currently at Start.io.
Rewrote a production Java platform in Rust in 2.5 days, with AI doing the coding autonomously. What stuck with me afterwards was not the speed. It was realising how much software gets built this way now, by people who are not engineers, with nothing checking it and nobody keeping a list. That is what DKOD is for.
I write about AI-assisted engineering, platform architecture, and building with AI agents at scale.
• Vantage Academy — AI engineering blog
• dkod Blog — AI-app governance and the agentic SDLC



