GovernCode
Put your AI coding crew to work. Keep the keys.
Pick one AI tool to lead and talk to it in plain words. It hands bounded jobs to the others, cloud or local, and every one of them works inside a sandbox the operating system enforces. You choose how often they ask, the risky steps always wait for you, and their changes can be undone. The AI writes code faster than ever; GovernCode makes sure you are still the one steering.
- free forever (MIT)
- runs on your machine
- no account, no telemetry
- Linux now · macOS + Windows together, next
Terminal: gov ask has the Controller add a function and a test. A Gate shows the exact command npm test; the user allows it for the rest of the turn, the sandbox still applies, and the tests pass. Then the Controller hands a README job to a local model, qwen3.5:9b in Ollama, which finishes in 6 seconds; the change waits for review with gov diff.
What it does
Your tools, your rules, one crew
GovernCode doesn't replace your AI coding tools. It hires them, fences them in, keeps the receipts, and hands you the undo button.
-
Controller + Runners
works todayOne AI leads, the others take jobs. The Controller keeps the big picture and hands bounded jobs (Specs) to Runners: a brief, a scope, a budget, and what "done" means. Each Runner works in its own copy of your project, so nobody trips over anybody.
Controller · Claude Code or Codex
Runners · Codex, or a model on your own machine -
Gates
works todayYou pick how often it asks: Relaxed, Balanced or Strict. When it asks, you see exactly what will run, byte for byte, not a friendly summary. Say yes once, for the rest of this turn, or for this project. The fence never moves; you just stop being asked about
npm testforty times.Relaxed, Balanced or Strict: you pick how often.
rm, sudo, git changes, installs, network, paid AI: always ask. -
Sandbox
works todayDeny by default, and the OS means it. Landlock and seccomp fence every AI tool: a filesystem allowlist, outbound HTTPS only, and no way to reach the daemon to approve its own Gates. If your machine can't enforce it, GovernCode refuses to start. There is no "just this once" switch.
govern-sup selftest· must pass, or nothing runs -
Checkpoints
works todayCtrl-Z for your whole crew. In a git project every change is snapshotted before and after (files over 100 MB excepted, and it tells you if a snapshot fails), so you can diff it and put it back exactly. Undo refuses if you have edited those files since: it will never "restore" over your own work. Everything lands in the Trace, an append-only history.
gov undo T-12· restored 2 files -
Limits
works todayYour quota's bodyguard. Each provider keeps the reserve you set, measured before a job starts and while it runs. Unknown usage counts as "no". Paid overage is never switched on for you. Local models get a machine limit instead: how many at once, how many minutes each.
gov reserve codex weekly 15 -
Local models
works todaySmall jobs, zero quota. Point a Spec at a model running in Ollama on your own machine. It gets no tools and runs no commands: it proposes whole files, GovernCode checks every path against the job's scope, and you review it like anyone else's work.
qwen3.5:9b wrote a README section in 6 s
no cloud quota was harmed
What we stand for
Nine things we won't budge on
The short version. The long version is in the repo, and every one of them is backed by code, a test, or both.
You ship it, you own it.
GovernCode exists to make building software with AI more approachable: fewer surprises, clearer reviews, an easy undo. It doesn't make anyone less responsible. Whatever you accept is yours, so read the diff, understand the code, run the tests, and know what you're shipping before you ship it.
The AI can write it. Only you can answer for it.
- 1You hold the controls.
AI does the work; you make the calls. You choose how often it asks; risky steps always wait for your yes, and changes can be undone.
- 3Deny by default, fail closed.
Enforced by the operating system, not by asking the AI nicely.
- 4Any model can lead.
Claude, Codex, Gemini, Grok, or the one on your own GPU. No favourite vendor in the design.
- 5Honest about limits.
We say what we measure, how, and where the edges are. Especially the edges.
- 6Free and open, forever.
MIT. No paid tier, no telemetry, no account. Your code stays on your machine.
- 7Built with AI, openly.
AI writes a lot of GovernCode, and we say exactly which AI did what.
- 8Small, boring, verifiable.
Plain code and a test for every rule that matters. Boring beats clever.
- 9Respect, always.
Love AI or distrust it, any OS, any tool: all welcome. Critique the code, never the people.
Free, actually free
Free and open source
Free and open source (MIT). Always will be. No "pro" tier lurking behind the next release.
It runs on your machine, uses the AI subscriptions you already have, and keeps your code, keys and history local. There's no hosted service to sign up for, because there's no hosted service.
Oh, by the way. If GovernCode saves you an afternoon and you feel like saying thanks, you can buy Dave a coffee. The crew runs on tokens; Dave runs on coffee. Only one of them has a button. Zero pressure: the code is yours either way.
tar xzf governcode-*-linux-x86_64.tar.gz cd governcode-*-linux-x86_64 ./install.sh --service # under ~/.local, no root gov demo
Download the latest release candidate from Releases (Linux x86_64). Needs Linux 6.12+ (Landlock ABI 6), Node 22.18+ and git, plus Claude Code or Codex logged in. gov demo walks you through a real task in about five minutes; the Dashboard is in your app launcher.
Release channels
Debate, Motion, Decree
One repository, three channels, named the way a good parliament works: argue first, vote second, then it's the law.
Debate
branch debate · where work happensIdeas argue it out here. It's where the newest things land first, and occasionally where they get voted down.
Motion
tags vX.Y.Z-motion.N · release candidatesSeconded, not yet passed. Try it, poke it, tell us what broke. The first one is 0.1.0-motion.1.
Decree
tags vX.Y.Z · stablePassed into law. Boring, dependable, and exactly what we said it would be.
Roadmap
Where it stands
Built in the open, in this order. Linux first, while the foundations set. Then macOS and Windows arrive together, with the same priority: neither waits for the other, because GovernCode should work for as many people as want it (and three platforms find more bugs than one).
-
phase 0 done
Foundation
Daemon, sandbox + self-test, CLI, Claude Code driver, the Trace.
-
phase 1 done
The crew
Delegation and Specs, measured and local Runners, Limits, Checkpoints + undo.
-
phase 2 now
Dashboard
The desktop app: review queue, Gates, Limits, Settings. Then macOS + Windows, together.
-
phase 3
Pager
Phone app, Android first: pairing and phone-signed Gates.
-
phase 4
Modules
Plugins and the Registry that publishes them.
-
phase 5
Launch
iOS, driver Modules, and a Decree worth the name.