GovernCode
pre-alpha · release candidates are out

GovernCode

Put your AI coding crew to work. Keep the keys.

Pick one AI tool to lead and talk to it in plain words. It hands bounded jobs to the others, cloud or local, and every one of them works inside a sandbox the operating system enforces. You choose how often they ask, the risky steps always wait for you, and their changes can be undone. The AI writes code faster than ever; GovernCode makes sure you are still the one steering.

  • free forever (MIT)
  • runs on your machine
  • no account, no telemetry
  • Linux now · macOS + Windows together, next

Terminal: gov ask has the Controller add a function and a test. A Gate shows the exact command npm test; the user allows it for the rest of the turn, the sandbox still applies, and the tests pass. Then the Controller hands a README job to a local model, qwen3.5:9b in Ollama, which finishes in 6 seconds; the change waits for review with gov diff.

A real session, trimmed. The Gate shows exactly what will run; "t" skips the question for the rest of the turn, never the sandbox.

What it does

Your tools, your rules, one crew

GovernCode doesn't replace your AI coding tools. It hires them, fences them in, keeps the receipts, and hands you the undo button.

  • Controller + Runners

    works today

    One AI leads, the others take jobs. The Controller keeps the big picture and hands bounded jobs (Specs) to Runners: a brief, a scope, a budget, and what "done" means. Each Runner works in its own copy of your project, so nobody trips over anybody.

    Controller · Claude Code or Codex
    Runners · Codex, or a model on your own machine

  • Gates

    works today

    You pick how often it asks: Relaxed, Balanced or Strict. When it asks, you see exactly what will run, byte for byte, not a friendly summary. Say yes once, for the rest of this turn, or for this project. The fence never moves; you just stop being asked about npm test forty times.

    Relaxed, Balanced or Strict: you pick how often.
    rm, sudo, git changes, installs, network, paid AI: always ask.

  • Sandbox

    works today

    Deny by default, and the OS means it. Landlock and seccomp fence every AI tool: a filesystem allowlist, outbound HTTPS only, and no way to reach the daemon to approve its own Gates. If your machine can't enforce it, GovernCode refuses to start. There is no "just this once" switch.

    govern-sup selftest · must pass, or nothing runs

  • Checkpoints

    works today

    Ctrl-Z for your whole crew. In a git project every change is snapshotted before and after (files over 100 MB excepted, and it tells you if a snapshot fails), so you can diff it and put it back exactly. Undo refuses if you have edited those files since: it will never "restore" over your own work. Everything lands in the Trace, an append-only history.

    gov undo T-12 · restored 2 files

  • Limits

    works today

    Your quota's bodyguard. Each provider keeps the reserve you set, measured before a job starts and while it runs. Unknown usage counts as "no". Paid overage is never switched on for you. Local models get a machine limit instead: how many at once, how many minutes each.

    gov reserve codex weekly 15

  • Local models

    works today

    Small jobs, zero quota. Point a Spec at a model running in Ollama on your own machine. It gets no tools and runs no commands: it proposes whole files, GovernCode checks every path against the job's scope, and you review it like anyone else's work.

    qwen3.5:9b wrote a README section in 6 s
    no cloud quota was harmed

What we stand for

Nine things we won't budge on

The short version. The long version is in the repo, and every one of them is backed by code, a test, or both.

You ship it, you own it.

GovernCode exists to make building software with AI more approachable: fewer surprises, clearer reviews, an easy undo. It doesn't make anyone less responsible. Whatever you accept is yours, so read the diff, understand the code, run the tests, and know what you're shipping before you ship it.

The AI can write it. Only you can answer for it.

  • 1You hold the controls.

    AI does the work; you make the calls. You choose how often it asks; risky steps always wait for your yes, and changes can be undone.

  • 3Deny by default, fail closed.

    Enforced by the operating system, not by asking the AI nicely.

  • 4Any model can lead.

    Claude, Codex, Gemini, Grok, or the one on your own GPU. No favourite vendor in the design.

  • 5Honest about limits.

    We say what we measure, how, and where the edges are. Especially the edges.

  • 6Free and open, forever.

    MIT. No paid tier, no telemetry, no account. Your code stays on your machine.

  • 7Built with AI, openly.

    AI writes a lot of GovernCode, and we say exactly which AI did what.

  • 8Small, boring, verifiable.

    Plain code and a test for every rule that matters. Boring beats clever.

  • 9Respect, always.

    Love AI or distrust it, any OS, any tool: all welcome. Critique the code, never the people.

Free, actually free

Free and open source

Free and open source (MIT). Always will be. No "pro" tier lurking behind the next release.

It runs on your machine, uses the AI subscriptions you already have, and keeps your code, keys and history local. There's no hosted service to sign up for, because there's no hosted service.

Oh, by the way. If GovernCode saves you an afternoon and you feel like saying thanks, you can buy Dave a coffee. The crew runs on tokens; Dave runs on coffee. Only one of them has a button. Zero pressure: the code is yours either way.

try it (Linux, release candidate)
tar xzf governcode-*-linux-x86_64.tar.gz
cd governcode-*-linux-x86_64
./install.sh --service   # under ~/.local, no root
gov demo

Download the latest release candidate from Releases (Linux x86_64). Needs Linux 6.12+ (Landlock ABI 6), Node 22.18+ and git, plus Claude Code or Codex logged in. gov demo walks you through a real task in about five minutes; the Dashboard is in your app launcher.

Release channels

Debate, Motion, Decree

One repository, three channels, named the way a good parliament works: argue first, vote second, then it's the law.

  • Debate

    branch debate · where work happens

    Ideas argue it out here. It's where the newest things land first, and occasionally where they get voted down.

  • Motion

    tags vX.Y.Z-motion.N · release candidates

    Seconded, not yet passed. Try it, poke it, tell us what broke. The first one is 0.1.0-motion.1.

  • Decree

    tags vX.Y.Z · stable

    Passed into law. Boring, dependable, and exactly what we said it would be.

Roadmap

Where it stands

Built in the open, in this order. Linux first, while the foundations set. Then macOS and Windows arrive together, with the same priority: neither waits for the other, because GovernCode should work for as many people as want it (and three platforms find more bugs than one).

  1. phase 0 done

    Foundation

    Daemon, sandbox + self-test, CLI, Claude Code driver, the Trace.

  2. phase 1 done

    The crew

    Delegation and Specs, measured and local Runners, Limits, Checkpoints + undo.

  3. phase 2 now

    Dashboard

    The desktop app: review queue, Gates, Limits, Settings. Then macOS + Windows, together.

  4. phase 3

    Pager

    Phone app, Android first: pairing and phone-signed Gates.

  5. phase 4

    Modules

    Plugins and the Registry that publishes them.

  6. phase 5

    Launch

    iOS, driver Modules, and a Decree worth the name.