Preqora — Build right before you buildPreqora — Build right before you build Build right before you build
Agile for AI agents AI development governance

Your agents work only after they've proven they read the docs — and scanned the code.

Preqora is a local governance gate for AI dev agents: a mandatory orientation compiled from your own repo, a qualification check with verifiable answers, tools that stay locked until it passes, a code-reality scan that attests what the repo actually is — not just what the docs say — and a completion verifier that accepts work only against its contracted definition of done. Docs plus code add up to receipts: every ruling cites real text, “verified” means evidence in hand, and handovers compile from the record — not the agent’s memory. Attestations expire when the docs — or the code they cover — drift; only the delta re-runs.

No newsletter, no spam — just the launch note. Local-first product; this waitlist is the only thing that touches a server.

You're on the list — we'll be in touch.

Couldn't reach the list — please try again in a minute.

The problem

Products don’t die of a fatal defect. They die of undefined done.

Without measurement, “finished” isn’t a state you’re approaching — it’s a state that doesn’t exist.

The gap between here and shippable goes unmeasured, so it feels infinite. Scope grows faster than completion. Motivation collapses somewhere in the fog. Projects rarely fail at the end — they fail to have an end.

AI makes this worse, not better. Generation is nearly free while verification stays expensive, so the world fills with 80%-done artifacts at machine speed — and the missing 20% is precisely the measured part: edge cases, trust, quality, proof. Coding agents multiplied output. Nothing multiplied finished.

A measured product is the only kind that ever gets finished. Every agent that says “should work now” is making an unmeasured completion claim. Preqora refuses that as a currency.

The frame

Your agents hold real privileges. Govern them that way.

Your security team already knows how to govern powerful actors: identity, scoped permissions, accountability boundaries, audit trails, re-certification. An agent that can read your repo and change your code is exactly that kind of actor — a holder of privileges, not a tool.

Preqora gives your AI dev agents the same treatment, locally: who this agent is, what it is authorized to do, what it has attested, when its clearance expires, and a receipt for every claim it makes — oversight you can hand to an auditor, not assert in a meeting.

A policy describes governance. A gate performs it. An AI policy that cannot govern an agent that acts is a wall poster. Preqora is the database version.

What it blocks

The failures that burn your week aren't in the code.

skipped boot docsuncited rulingsno prior-art search "verified" without evidencelost handoversout-of-sequence buildspremature execution rebuilding what already existsdocs that outran the code
How it works

Three moves, all on your machine.

1 — orient

Point it at your repo

Your docs and standards compile into a short course — brief, architecture tour, the rules with the incidents that earned them, the current plan. Your code is indexed alongside them: modules, signatures, and the contracts written in your own headers.

2 — attest

The agent earns its tools

A qualification check with verifiable answer keys — drawn from the code as well as the docs: which module owns what, what already exists. Pass writes an attestation and unlocks tools. Change a doc or the code and only the delta re-runs.

3 — enforce

Everything leaves receipts

Rulings must cite real doc text or a real module contract. Building something new requires asking whether it already exists. Claims need evidence in hand, and session handovers compile from the ledger — not the agent's memory.

The disciplines

Build right before you build.

Done means seen.

Every automated gate can pass while the screen is still broken. So nothing that touches what a user sees is finished until the rendered result has been looked at — in every theme, logged with the build. A green check is not a look.

Measured against named standards, not a mood.

Quality here isn't taste. Accessibility is gated today: WCAG 2.2 AA on every tracked page, in three browser engines and both colour schemes. Nielsen's usability heuristics and OWASP's application-security standard come next, each on a dated row of the register — the shelf below prints the date. Every standard lives as a named, versioned pack — sealed, dated, checkable — and when a gold standard moves, the pack moves with it: rules against a superseded standard expire, exactly like rules against a changed doc. You choose when to upgrade. The two prior versions stay live, and nothing is ever forced — the bar rises with the field, on your schedule, and every choice lands in the record. The bank is built to grow — Google PWA practices, HIPAA- and NIST-aligned controls — and for licensed regimes you connect your own licensed copy; nobody's text gets redistributed. Aligned means checked, with receipts. It never means "certified" — no tool can honestly say that, so this one doesn't.

Nothing of value lives only in a chat.

One platform action can erase every artifact in a conversation, permanently. Preqora treats work as unfinished until a hash-verified copy sits in a store you own — checked at close-out, never assumed.

Receipts, not recollections.

Every action and every accepted change lands in a tamper-evident, hash-chained record on your own machine — nothing phones home, and nobody can edit history. When it matters, you don't reconstruct. You produce the record. The limit is a test, not a sentence in our documentation. UPDATE and DELETE on the ledger abort at the database. Remove the trigger, rewrite a row, and the chain reads BREAK-HASH.

The bank, generated from the standards register: one pack live at the gate, three arriving on dated rows, two coming soon and two as provision for your own licence.
Your tracker holds the intent and the future; your repository holds what landed.

Proof before code.

The agent that proposes a change proves it first: it reproduces the failure, shows the fix go green, and hands over the receipts. Your build starts from evidence, not a promise — one gate, not a loop. Where the proving environment differs from the running one, that difference is named in the receipt rather than hidden by it. Build right before you build.Where the agent proposing a change can run your checks, it proves the change before you see it; where it can't, the proof is the first thing your build runs. Either way, never a guess.

Security is a pipeline property, not a purchase.

A security floor comes free in every tier — the rules, gates, hooks, and receipts are ours, and they never depend on any one tool. Your pipeline runs the checks; Preqora verifies they ran on time and holds the line on what they found. An absent scan is a finding, not a pass. Bring your own tools if you have them — their results are recorded as theirs. Checked, with receipts. Never "certified" — no tool can honestly say that, so this one doesn't.

Measured, never guessed.

Every number in a change request is read from a run, not written from a hunch — expected results come from a dry run on a real copy of the code, and the run's output travels with the request. If a value was never measured, it isn't allowed in.

Decisions survive the people who made them.

A ruling, an approval, a defect, a lesson — each is written to the record the moment it happens, not remembered until someone asks. Your tracker holds the intent and the future; your repository holds what landed. Nothing rides in anyone's memory, human or machine.

No rebuilt wheels.

Before an agent creates anything new — a module, a document, a rule — it must show it looked for what already exists. Duplicates don't get to compete with the original; they get refused.

The toolmaker is governed too.

The same rules that govern your agents govern the lane that builds them: every instruction block is linted before a human sees it, every boot is verified against the record, and the lint's own rules are proven to fail before they're trusted to pass. And when the lane that builds this breaks its own rules, the failure is written down where you can read it — including in this page's own history.

A check that cannot fail is not a pass.

A gate that always passes is indistinguishable from one that works, until the week it matters. So every gate here is proven able to go red before it is trusted to go green, and what a gate cannot measure is a finding rather than a skip. Our own accessibility gate reported clean for weeks while silently skipping 668 nodes it could not read — text over gradients, images, overlapping backgrounds — and 123 of them were failing. It measures at the pixels where the letters sit now. We found that on our own pages, and it is written here because a badge you cannot interrogate is worth nothing.

Your tests check what changed. Your users see what didn't.

A check scoped to the diff is blind by construction: it can only fail on what someone already suspected. So verification enumerates the whole artefact — every page, every component, every row — and the change decides only what gets rebuilt, never what gets checked. Earned when two wrong items in an untouched section survived 82 automated checks and 155 named frames, every one of those checks correct about what had changed.

Nothing leaves unaudited against its own claims.

Every artefact answers three questions in its own text before it moves: which command enforces this, which verdict line proves it fired, which fixture proves it can fail. Counts are walked, never derived. Bases are read, never assumed. If the audit cannot run, nothing is delivered — and the executor certifies that it ran, never the author. A lane that grades its own homework is the failure this product was built to stop.

“Works on my machine” scaled to machine speed.

An agent's dry run proves the commands work where they ran. It cannot prove they work where they will run. A CI runner's browser, lacking WebGL, rendered fallback charts our own browser never showed — carrying real contrast failures for any visitor in the same position. So changes are rehearsed in the environment that will execute them, and where that is impossible the gap is declared rather than assumed away.

The work survives the worker.

Sessions end, contexts fill, people change. A handover here is compiled from receipts, checked against a standard, and refused if anything is missing — so the next agent starts from the record, not from what the last one remembered.

A handover here is compiled from receipts, checked against a standard, and refused if anything is missing.
Session rotation

Sessions end. The record doesn't.

When context runs low, Preqora winds the session down and rotates it: the handover is compiled from receipts recorded while the agent was fresh — never recalled from a dying memory — and the successor resumes against a verified hash, inheriting the open threads.

The honest line

Preqora blocks the blockable and surfaces the rest. Qualification checks raise the floor; they don't guarantee understanding — judgment stays human. Every rule carries one of three states, and the file prints the command that reproduces the count: mechanically enforced — naming the check, the verdict line, and the fixture proving it can fail — a declared gap, carrying a date, an owner, what stops the failure today and what we don't do until it closes, or retired. Seventy-five-plus rules govern this product and fewer than a quarter are enforced. Everyone's rule set looks uniformly strong until someone counts. And every claim we make about Preqora comes from its own telemetry, nowhere else. A gate that lies is worse than no gate: we watched one emit zero verdicts across 1,428 dispatches while its own tests stayed green. Everyone ships green dashboards; Preqora ships true ones. Built for architects, product leaders and platform teams running agents against codebases that matter; not for hobby projects, pure autocomplete, or teams unwilling to define done. Indexing your code raises floors — what exists, what it returns, what its header promises, where the docs have drifted — not comprehension.

Bring your own

BYO identity, SIEM, scanners, CI, tracker — we verify, you own.

We verify; you own. Preqora doesn't replace the systems you already trust — it sits below your agents and above your repository, and hands its receipts to the tools you already run.

We verify; you own.
■ one SQLite file, on your machine■ zero cloud, no account ■ Claude Code verified first — any MCP agent connects■ your repo never leaves your laptop ■ code indexed on-device, never uploaded

Everyone sells you speed.
Preqora sells you finished.