← All products
AISDLC governance

Ai.DLC

AI-native SDLC governance for regulated-industry engineering teams.

Ai.DLC governs software delivery end to end — requirements through system docs — so teams building with Claude Code get AI velocity without losing control, audit trail or human sign-off. Every stage of the SDLC runs through the same governed pipeline, and every story is traced automatically from requirement to code to test.

Ai.DLC project backlog
6governed SDLC stages, plus a defect-fix branch
5independent AI expert reviewers
Two-wayClaude Code integration

Overview

At a glance

01

Two-way Claude Code integration

A real Claude Code CLI runs against the project workspace and authenticates back through a token-scoped API.

02

AI + human-in-the-loop governance

Independent AI expert review, then a human committee signature before any stage advances.

03

Automatic requirement-to-test traceability

Every story links to its design, code and tests as work proceeds — with live gap and coverage stats.

04

Configurable, governed SDLC workflow

Six governed stages, Requirements through System Docs, plus a Defect-Fix branch.

Capabilities

What makes it different

Four capabilities that compound — real two-way Claude Code integration, governed AI review and automatic traceability, running underneath every project.

01

Two-Way Claude Code Integration

The platform launches a real Claude Code CLI session against a project’s own workspace folder — headless for routine stage generation, or interactive when a person wants to pair with it — and that session authenticates back through a project-scoped API token to read approved inputs, push backlog items, register artifacts and log trace links. Nothing is simulated.

Why it matters
  • The platform can trigger Claude Code unattended, and a person can open the identical folder and pick up where the run left off
  • A scoped, revocable token — not a shared credential — makes every write attributable and audit-logged
  • A draft-then-push protocol lets people iterate freely before anything registers on the governed record
Two-Way Claude Code Integration
02

AI + Human-in-the-Loop Governance

Every stage gate is reviewed independently by domain-expert AI agents — Architect, Security, QA, Product and Compliance — each seeing only the artifact, not each other’s reasoning. Findings that reach consensus auto-resolve; contested ones go to structured multi-round debate; anything still unresolved escalates to a human committee decision that must be explicitly signed before the stage can advance.

Why it matters
  • Independent-then-debate review avoids one agent’s early conclusion anchoring the rest
  • Human sign-off is enforced server-side as a separate action — no AI code path can mark it signed
  • Every finding, rebuttal and decision is hash-chained into the audit log
AI + Human-in-the-Loop Governance
03

Automatic Requirement-to-Test Traceability

Every story is linked automatically to the design section that specifies it, the code that implements it and the test cases that verify it — written by Claude Code as work proceeds, or added by a person filling a gap through the same trace-link API. A live matrix shows every story’s chain end to end, with gap and untested-story counts computed from real links.

Why it matters
  • Answers “what covers this requirement” and “is anything untested” in real time
  • Traceability is a by-product of doing the work, not a separate documentation task
  • The matrix a SOX or vendor-risk auditor asks for is already live in the product
Automatic Requirement-to-Test Traceability
04

Configurable, Governed SDLC Workflow

A project runs through six governed stages — Requirements, Design, Development, Test Design, Testing and System Docs — plus a dedicated Defect-Fix branch that bounces failed tests back to development without implying the whole project regressed. Every stage runs its own review cycle — generate, team review, governance review, gate — and every epic, feature and story carries a stable key from first draft to final sign-off.

Why it matters
  • Six real stages and a distinct defect-fix loop, not a generic ticket board relabeled for AI
  • Backlog items keep the same external key for life, so re-running a stage never duplicates or renumbers work
  • The same stage-cycle engine powers the standalone Governance Board product
Configurable, Governed SDLC Workflow

Built in

Also built into the platform

Ai.DLC ships the operational infrastructure a regulated-industry deployment needs on day one.

Word (.docx) Twins

Every registered artifact gets a presentation-quality Word twin, stamped with approver names at sign-off.

Change Requests

Requirement-scope changes tracked and routed through the same review discipline.

Audit Trail

Hash-chained log of every AI and human action, race-safe under concurrent review.

Single Sign-On

Real OIDC authorization-code + PKCE flow, per organization.

Two-Factor Authentication

TOTP-based 2FA on every user account.

Portfolio Analytics

Cross-project view of stage, open CRs and open defects.

Who it’s for

Who it’s for

Engineering organizations adopting AI coding tools faster than their governance functions can validate them.

Financial services & insurance vendorsISVs building loan origination, claims and underwriting software who must show a governed, auditable SDLC to bank and insurer customers.
Healthcare software vendorsISVs building clinical, claims and eligibility software subject to HIPAA and payer/provider vendor-risk review.
In-house teams at regulated enterprisesBank, insurer and healthcare technology teams adopting Claude Code first, ahead of their own compliance tooling.
AI-native engineering organizationsTeams going all-in on AI-assisted development and outgrowing spreadsheets and tribal process.

Architecture

Under the hood

How Ai.DLC is built

A governed pipeline with Claude Code wired in both directions — every stage, review and trace link runs through the same auditable core.

01PresentationWorkspace, console, portfolio
Project WorkspaceStage pipeline, backlog, traceability, defects, CRs, audit
Governance ConsoleCommittee review queue, findings, decisions, signed history
Portfolio & AnalyticsCross-project stage, open-CR and open-defect view
02SDLC OrchestrationSix stages plus a defect-fix branch
Stage & Cycle EngineEach stage cycles generate, review, gate
Defect-Fix BranchBounces failed tests back to development
Backlog & TraceabilityEpics, features and stories — keyed, versioned, traced
03Claude Code & GovernanceReal two-way integration
Claude Code RunnerSpawns the real CLI against the project workspace
Agent API & ScaffolderToken-scoped endpoints; token, manifest and CLAUDE.md written at project creation
Governance BoardFive domain-expert agents review independently, then debate
Human Decision GateA distinct, server-enforced signing action
04Data & AuditPostgres-backed
PostgreSQLParameterized query layer, no ORM
Job QueueBackground processing and scheduling
Hash-Chained Audit LogEvery AI and human action, race-safe
05IntegrationFits your identity and docs stack
SSO / Identity ProvidersOIDC per organization
Docx GenerationA Word twin for every artifact at sign-off
Shared Governance CoreThe same engine powers the standalone Governance Board

Talk to us about Ai.DLC.

Get in touch