Public trust surface

Audit-ready evidence for AI-assisted pull requests.

Gilded Code is building devOS: a governance layer for teams adopting AI coding agents. It turns pull request activity into reviewable evidence packs that show who approved the work, which controls ran, and what changed.

The audit questions

What reviewers, buyers and regulators will ask.

1

Who changed it?

Connect code changes to the human owner, AI agent and delivery system involved.

2

Was it governed?

Show the controls, permissions and review gates that were active for the work.

3

What evidence exists?

Produce signed artifacts that can be inspected after the pull request has moved on.

4

Can it be reused?

Produce evidence that security, compliance and platform teams can consume.

devOS

A policy-to-evidence chain for AI-assisted delivery.

devOS focuses on the evidence around delivery, not on replacing source control, CI or identity platforms. It is designed to sit beside GitHub, CI systems and enterprise controls as the governance record for software change.

Pull request input

Collects PR metadata, review decisions, checks and agent attribution.

Governance verdict

Maps the work against delivery controls and flags missing evidence.

Evidence record

Stores a compact evidence pack that survives branch cleanup and tool churn.

Buyer-ready surface

Gives platform, security and compliance teams a shared record to inspect.

Trust posture

Continuous review for governed AI-assisted delivery.

Evidence-led posture

Gilded Code demonstrates a practical evidence workflow for governed AI-assisted delivery.

Agent governance first

The product narrative is grounded in identity, permission boundaries, review gates and durable proof of agent-assisted work.

Integration-friendly

The workflow is intentionally GitHub-native while keeping the evidence contract usable by identity, ticketing and compliance systems.

Evidence pack

What a PR evidence record contains.

The PR evidence workflow gives customers a clear record of review decisions, policy checks and supporting artifacts for AI-assisted software delivery.

Field Purpose
Attribution Connects human and agent activity to the PR.
Controls Shows which governance checks ran and whether they passed.
Artifacts Records evidence, hashes and generated review outputs.
Verdict Summarizes whether the PR is ready for review, escalation or remediation.

Design partners

Help shape the PR evidence workflow.

We are looking for teams adopting AI coding agents who need a defensible way to show review, attribution and governance evidence around software change.

hello@gildedcode.com