Build software with AI without giving up sovereignty
Circuit is the AI build-platform for all of you that care where data goes. Describe what you want; AI agents plan and build it as governed tasks, inside your sovereign Stackship instance, on the models and providers you choose. You decide where inference runs, and policy enforces it.
- Your choice of model and provider
- Human-in-the-loop on every sensitive step
- Signed, auditable evidence trail

Circuit · overview
Circuit runs on Stackship
Circuit is the AI build layer. Stackship is the sovereign control plane underneath. Circuit produces code, infrastructure and reviews; Stackship governs them with policy, audit, RBAC and compliance.
Circuit: the AI build layer
Owns the conversation, planning and agent runs. Turns intent into governed tasks and a reviewable, evidence-grade result.
Stackship: the sovereign platform
Platform as a Service primitives, policy engine, audit ledger, identity, deploy and local LLM inference. Where everything runs and where the rules live.
Platform capabilities like policy, compliance and the audit log live in Stackship. Circuit surfaces them as live views that deep-link into the platform.
From a need to a system that lasts
Four phases, one cycle. The same loop maintains the system afterwards.
- 1
01 · Explore
The business owner describes the need in plain language and gets a clickable prototype in minutes. When it is submitted, the prototype and the need description are frozen as the stable basis for shaping.
- 2
02 · Shape
A technical lead works with AI to turn the prototype into a specification: architecture pre-filled from your technology policy, exact platform cost from the price list, an agent contract, and epics with executable acceptance criteria.
- 3
03 · Build
Agents implement against the spec in ephemeral environments on your own Stackship. They write, deploy, test, read the failures and fix, under budgets for time, model cost and iterations. Nothing merges without a named human review.
- 4
04 · Operate
Live systems stay in Circuit. CVEs, dependency updates and Sentinel findings become maintenance items with proposed fixes. Operations breeds new needs, and the cycle starts over in Explore.
See Circuit work
From a need to a system in operation, through the four phases.
A need becomes a clickable prototype in minutes
The business owner describes the problem in plain language. No ticket writing, no requirements template. Circuit generates a prototype to react to and iterates in conversation. Submitting freezes the current version as the basis for shaping, with the whole prompt history preserved.
- Guidance instead of rules: describe the kind of data the system will handle, not the data itself
- A discreet line shows which model the words go to and where it runs
- The prototype is intent, not a codebase. It becomes the brief the agents implement against
Questions in business language, costs before any code
Shaping always raises questions. Circuit phrases them in business language, such as approval steps and who may book, and the business owner answers them in the same view. The cost picture is there from the start: exact platform cost from the price list, a build estimate as a range with stated assumptions, and the expected operations effort.
- Questions are notified, listed and answerable in place
- Platform cost is exact, since the resource manifest maps to Stackship's price list
- The build estimate is a range and is recalibrated against real outcomes during the build
The spec is the agent's boundaries, pre-filled by your policy
The technical lead shapes with AI. Architecture decisions are pre-filled from the organisation's technology policy, so only the genuinely open choices remain. The output is binding: an agent contract, a resource manifest priced from the list, and epics with executable acceptance criteria. The repository is created at the decision, and the spec, the decisions and the contract land there as markdown you own.
- Deviations from policy require a justification and are logged in the decision record
- The acceptance criteria are the real specification. The tests define done
- Durable artifacts live in your repository, process state in Circuit
Agents drive themselves to green, under budgets that stop well
Each task runs in an ephemeral environment on your Stackship: write, deploy, test, read the failures, fix. Budgets for wall clock, model cost and iterations set the limits, and progress is measured beyond consumption: failing tests trending down, no oscillation between attempts, no files outside the task. At 75 percent the agent assesses whether it will finish, and a blocked task stops itself with a readable handover instead of burning the budget.
- The inner loop always runs on Stackship, private and ephemeral. Your own pipeline decides the merge
- Small diffs by design, decomposed for reviewability
- Test files from Shape are never changed without human approval. The tests are the spec
Live is where systems spend their lives
The business owner sees what matters: the system is healthy, security updates are handled continuously with human approval, and the running cost is what shaping promised. When operations breeds a new need, the cycle starts over in Explore with everything about the system already known.
- No surprises: the running cost was known before the build started
- Changes that don't affect the business stay out of the way
- A new need is one click back to Explore, with full context
Maintenance is the same loop, and where procurements are won
CVEs, deprecated resource versions and Sentinel findings become items in a maintenance queue. The agent updates, runs the whole test suite green in an ephemeral environment and opens an MR, and a human approves. Vulnerability status and remediation times are a report view, which the EU Cyber Resilience Act makes compliance rather than convenience. Cost shows both the month and the contract period, because lifecycle cost is what the deal is decided on.
- Sentinel watches production and Circuit acts. Nothing merges without a named approval
- Operational data is masked before it leaves the platform and runs on a local model per policy
- A CRA report per system shows vulnerability status and time to fix
Everything regulated delivery needs
Traceability, policy and human approval are woven through the whole product.
Conversational planning
Describe what you want and a read-only planning agent turns it into a concrete plan of tasks. Nothing is built until you say so.
Tasks run as governed ephemeral workers
Every task compiles to an ephemeral agent worker that only pulls in what is needed to execute the task at hand, using your chosen model.
Live agent runs
Watch every step stream in real time: plan, policy, edit, tool. Pause, or answer the agent's blocking questions mid-run.
“What the AI saw”
Inspect the exact prompt and context behind any model call. PII and secrets are masked by PII_GUARD before they ever reach the model.
Review cockpit
File-by-file diff with line comments and the policy verdict. A human merges in your own source code provider. Circuit never holds merge rights.
Signed evidence packages
Every task yields a hash-chained, exportable evidence package (SHA-256) mapped to NIS2, GDPR and ISO 27001 controls.
Built sovereign by design
The six principles Circuit never compromises.
Sovereignty
You choose the models and providers. Policy decides which endpoints agents may reach, so you can keep inference fully inside your boundary or point it at a sovereign provider you trust. You stay in control of where data goes.
Human-in-the-loop
Agents can't complete sensitive actions like merging or changing production infra without human approval. Multi-step approval with quorum and separation of duties.
Total traceability
Every action by a human, agent or policy is written to an immutable audit log. Each task can produce a signed evidence package for audit.
Compliance built-in
NIS2, GDPR and ISO 27001 are first-class objects: framework → control → evidence, traceable in real time.
Full-stack
Build complete systems, from frontend and backend to database and infrastructure, all provisioned through Stackship primitives.
No lock-in
Open standards throughout: any OpenAI-compatible model, your own Git provider, your own infrastructure. Nothing proprietary holds you hostage, so you can take your code and leave whenever you want.
Made for regulated environments
Framework → control → evidence, traceable in real time.
Questions
The things regulated buyers ask first.
Where you decide. Circuit is model- and provider-agnostic: you pick the OpenAI-compatible endpoints, and policy controls which ones agents may reach. Lock it down to models inside your boundary for zero egress, or allow a sovereign provider you trust. Either way it's your choice, enforced by policy and recorded in the audit log.
Join the Circuit early-access pilot
We're working with a small group of public-sector and regulated organisations to shape Circuit before general availability.
Who it's for
- Public-sector bodies: agencies, regions, municipalities
- Regulated industries with sovereignty or NIS2/GDPR requirements
- Teams that want AI-assisted delivery on models and infrastructure they control
- Organisations already running Stackship, or planning to
What you get
- Hands-on access to Circuit on a sovereign Stackship boundary
- A direct line to the team building it, so your feedback shapes the roadmap
- Help mapping your compliance frameworks (NIS2/GDPR/ISO 27001) to evidence
- Early-access pricing
Circuit is in active development. Pilot scope and availability are agreed per organisation.
Request early access
Tell us what you’d like to explore and leave your email, and we’ll be in touch about early access.
What are you interested in?
Circuit runs on Stackship, so it’s included automatically.
No commitment, just a conversation and a walkthrough.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.