AI tools generate production code faster than architects can govern it.
rkito continuously enforces design intent on every pull request— keeping AI-generated software conformant before it merges.
Commitment to open source
Free for open source.
Qualifying OSS projects get the full platform, for life.
For everyone else
A free tier, always.
Start now on Starter — no credit card needed.
The challenge
Agents generate at a pace no review process was built for. Left unmanaged at that scale, it threatens business continuity — and three problems become starkly visible.
Engineering leaders are thinking
Today, design intent lives everywhere: READMEs, ADRs, CLAUDE.md/AGENTS.md files, wikis, and design documents. Governance, if it exists at all, relies on review workflows built for a handful of human pull requests each week—not continuous, agentic engineering at scale. Every additional source expands an agent's context, increasing token costs with every prompt. Yet even after paying that cost, the agent is still left to reconcile conflicting or incomplete intent. Without a single source of truth, design conformance degrades and architectural drift compounds with every generation.
Engineering leaders want to accelerate agentic software development—not at the expense of delivery quality. As AI-generated code becomes a larger share of every release, design inconsistencies, review overhead, and architectural drift become increasingly difficult to control. Senior engineers and architects are pulled into reviewing larger and more frequent pull requests, creating a bottleneck that limits scale. Without automated design conformance, organizations cannot confidently increase the autonomy of their engineering agents.
Most delivery pipelines were never built to incorporate agentic engineering, let alone the CI/CD shape it demands. Teams struggle to shift left—catching design intent early, wherever agents or AI-enabled ideation are involved—and struggle just as much to shift right, catching drift at the speed agents now generate. An engineering organization that can't execute both cannot transform for the agentic era.
rkito eliminates the operational friction of governing agentic engineering. From maintaining design intent and steering artifacts to declaring change intent, measuring conformance, auditing architecture, and detecting drift, rkito automates design governance directly within the GitHub pull request workflow—without changing how developers work.
Where design intent is authored — as Concepts, Policies, Best Practices, and Patterns. Every artifact is AI-assisted to write, so design thinking can diverge and converge quickly — but every change still passes a human-only review before it's approved. Each artifact ultimately resolves into Lenses: micro-contexts with a binary, yes/no evaluation outcome — the atomic unit the CDA actually evaluates.
The living, current, approved state of every system, component, and interface in your architecture. Ledger artifacts are authored the same AI-assisted way as Steering artifacts — but they describe what actually exists, not what should be true. This is the baseline every future Change Intention is proposed and audited against.
Ledger artifacts change through exactly one controlled path: a Change Intention (CHI). A developer — or an agent — declares what they want to do; rkito captures it as a CHI and proposes how the Ledger should change as a result. Every CHI goes through Design Review, a human-only gate much like a GitHub pull request. Once approved, it merges into the main branch of design.
Every pull request automatically triggers a Continuous Design Audit.
rkito identifies the applicable design intent, evaluates conformance, explains every violation, and blocks unapproved architectural drift before merge.
The platform property that emerges when intent, change control, and design review work together. Not a process aspiration — a measurable architectural outcome.
When agents generate security-relevant code at scale, shift-left isn't enough. Learn how rkito extends SecDevOps to enforce security architecture at every PR.
No architect can hold all design intent in memory — especially at this pace.
rkito is the institutional memory that never sleeps. Every PR. Every merge. Fully automated.
ADRs, Policies, Lenses — the rules the system must obey.
Syntactically correct. Intent-blind. No awareness of constraints.
Design intent enforced on every PR. Automatically. Before merge.
Conformant. Auditable. Drift caught before it compounds.
The Continuous Design Audit runs on every PR — fully automated, no architect required. Learn what it checks, how it evaluates, and what it produces.
Design intent before the first commit. Design audit at every PR. Together they close the governance loop that no agentic organisation can afford to leave open.
Agentic environments that write and ship production code need a design intent gate. Without it, every design principle violation reaches merge — at AI speed.
Reviewers see rkito's annotated comments inline — design intent context, violations flagged by CDA, and the architectural rationale behind each finding. No tribal knowledge required.
A PR can pass every SonarQube gate, every GitHub Copilot Code Review — and still be an architectural disaster.
rkito is the only platform that operates on design intent conformance. Not structural analysis. Not code quality. Design intent.
No conformance constraints. No architectural boundaries. No design intent. The agent generates code that compiles — and violates everything it cannot see.
The rkito Session Protocol is the mechanism by which agents operate precisely within design intent — retrieving the approved design, staying within CHI scope, and implementing exactly what was decided. Nothing less. Nothing more. The Skills Registry provides the governed instruction layer that makes this possible for any entity in the Architecture Ledger.
Session protocol, Skills Registry, agent bootstrap, and the closed governance loop — fully documented.
Why the governance gap exists, how the session protocol closes it, and what governed agentic engineering actually looks like.
Composite
Teams shipping ≥50% AI-generated code
rkito MCP enabled vs disabled
Composite sample
Teams shipping ≥30% AI-generated code · 2025
No design audit gate in pipeline
rkito introduced 35+ design fidelity metrics — architectural conformance, drift, and governance signals no code quality tool, CI pipeline, or architecture platform measures. This is what Design Continuity, Cognitive Debt, and Architectural Drift look like as numbers your org can trend, not just talk about.
Read the research →OSS projects on rkito publish their lenses, policies and best practices openly. Browse them without an account — adopt them into your org once you sign up.
Four steps. No bespoke tooling. No onboarding engagement. The first design audit on a real PR — the same day you start.
AWS Well-Architected, OWASP Top 10, ISO 27001 and more are pre-built inside rkito. One click adopts them into your org. You have design intent on day one — without writing a single artifact from scratch.
Connect your GitHub repository. rkito reads your codebase, Terraform, Helm, Kubernetes manifests and OpenAPI specs — then automatically populates your Architecture Ledger with every component, boundary and interface it finds.
The scan generates a Change Intention. Architects review it, update what needs updating, and merge. That is your living Architecture Ledger — the verified baseline every future PR is audited against.
One install. The PR webhook is configured automatically — no YAML, no callback setup. The next pull request your team opens gets a full design audit before it reaches code review.
Every PR from this point is audited against your Steering standards and Architecture Ledger — automatically, before it reaches code review.
Import your existing Confluence pages, Word documents, ADR folders, and policy PDFs. rkito's onboarding AI reads them and converts them into structured Steering artifacts and Lenses automatically — so your entire architectural history is in the system from day one, not just what you write going forward.
Compliant, regulated, and air-gapped organisations have non-negotiable constraints. rkito meets them — without compromising the governance model.
Drop in as a single workflow step. No new infrastructure, no agents to manage. Running in your first PR the same afternoon.
Fully managed on AWS. Data residency compliance available — choose your region, your data stays there.
Docker container. Air-gapped. No data leaves your network — designed for regulated industries and government environments.
Every qualifying open source project. All three layers. Unlimited members. The same platform paid teams use — no trial clock, no upgrade pressure.
Recognised open source licence. Public repository. That is the full qualification criteria — nothing else.
Self-service. No sales call. Stays free as long as the project qualifies. No upgrade clock.
Required. The way open source projects help build the category — and how we say thank you.
Five members. The full three-layer platform. No credit card.
If you're on an OSS project, start there instead.
Signing up creates a Starter organization. Steering, Architecture Ledger, Design Reviews, ADRs, and GitHub integration are all included.