Skip to content
Governance for AI-assisted development

AI writes. Your team decides. Every change leaves evidence.

Rixal governs AI-assisted development: a plan before code, adversarial review by a different provider, and retrievable evidence for every change. It runs on Claude, Cursor, Codex and Grok—and sells you none of them.

In internal use at Real Virtual
RIXAL
Plan · rules · review · evidence · memory
instructionsmetadata and evidence
On your team's machines
Your code
repositories, credentials, your customers' data
The agent
Claude · Cursor · Codex · Grok
with your team's subscription

Code never crosses the boundary. Rixal keeps decisions, identifiers and evidence—not source code.

Metadata onlyManaged servicesEverything in your cloud
The governed cycle

Nine stages. A person decides two of them.

Select a stage to see what it produces and who controls it.

A person decidesAI executes
05Reviewa person decides

A person accepts or returns the plan. Whoever writes the change never approves their own work.

What makes us different

Three architecture decisions, not three features.

01

We do not sell models

Rixal governs Claude, Cursor, Codex and Grok. Since we do not profit from the model you choose, we can select the least expensive one capable of the task.

02

We never see your code

Rixal sits above the model call, not in the middle. Code stays on your team's machines; we keep decisions, identifiers and evidence. This is how it is built, not just a policy promise.

03

Runs on the plans you already pay for

Instead of API keys billed per token, Rixal runs through your team's existing subscriptions and selects by available quota, billing cycle and cost.

The criteria, live
Choose a task type to see how the executor and reviewer are selected. This illustrates the criteria; the actual catalog lives in the system.
Classification
low risk
reversible, limited scope
Capability floor
budget
nothing below this can execute
Executes
budget model
the least expensive with available quota
Reviews
budget, different provider
must not share the author's blind spots
If no available model meets the floor, it stops. It does not downgrade or accept the executor's own judgment.
Capabilities

What it does today.

Every line has a status. An honest table with half its features in development is worth more than a complete list without statuses.

Governance before generation
Domain invariants, known bad patterns, previous decisions and compiled context
Available
Adversarial review across providers
No self-approval, a reviewer from a different provider, runtime-confirmed model and a capability floor: if no model can review properly, it stops
Available
Evidence and traceability
Runs, stage artifacts, diary and branch attestation
Available
Gated team memory
Core and working memory, semantic search, and every write validated, cleared of secrets and approved before entry
Available
System-generated documentation
Repository governance documents generated from the registry, with hash-based staleness detection. Per-change documents and a viewer are in development
Partial
Cost-based routing
Complexity assessment, policy and model catalog
Available
Multi-agent coordination
Governed agent communication, work queue and continuity across providers
Partial
Visibility
Run dashboard, stage timeline, execution queue and resources
Available
Ticket-list orchestrator
A coordinator distributes work among several agents and evaluates every delivery
In development
Subscription quota governance
Plan registry, billing cycles and remaining quota for executor selection
In development
How to get it

Two ways to start.

Neither is a buy button. Rixal governs how your engineering team works: it requires implementation, not just installation. Today one path is available and the other has a waiting list, and we clearly identify each.

Available today

By project, in your organization

We implement Rixal around your operation: repositories, invariants, review rules and the agents your team already pays for. A project with scope, owners and deliverables—not a per-seat license.

Waiting list

As a service

We are preparing a version where your team signs up and starts without an implementation project. It is not ready: customer isolation is still pending, and we will not open it before that is resolved.

  • We email you when it opens, and nothing more
  • No campaigns or sales calls
  • Unsubscribe in one click

Neither option fits? I want to understand how you built it — someone who uses it every day will reply, not a form.

Explore the system

The longer story, when you want it.

The problem we solve, the order in which we are building it, and what changed this week. None of this is required to decide whether to talk.

What we will not do

  • Our own coding agent. Rixal governs the agents you already use. The day we sell our own, we lose the ability to choose the best one for your task.
  • Autonomous execution without a person involved. Human control is not a temporary limitation we will remove as models improve. It is the product.
  • Store your code. This is not a policy we can change later: it is the reason the system is built this way.