Skip to main content
Design · Govern · Deploy

The AI Infrastructure Platform that can't ignore your rules.

Describe what you need. DevPlus researches your real cloud, designs from your governed catalog with a citation for every choice, and deploys through plan, cost, and policy gates you approve.

AI without your opinions is just an LLM with connectors.

Cited
every design shows its evidence and the rules it follows
0 keys
stored with keyless cloud connectors
2 gates
cost estimate and policy check before any apply
Isolated
infrastructure, data, and identity, isolated per tenant
DevPlus
Ask
Design
Govern
Live
Architecture planProposed
payments-api
Production EKS Cluster
catalog · v2.3.1
orders-db
Postgres (RDS Multi-AZ)
catalog · v1.8.0
event-stream
No catalog item yet
author · provide · skip
Catalog-only · hardNo serverless · hardShared ALB · advisory
CitedYou already run 2 EKS clusters in us-east-1, so the design reuses the orchestrator.
Edits are re-validated before anything runs.Approve & deploy
  • OpenTofu
  • Terraform modules
  • Cedar policy
  • AWS
  • Azure
  • Kubernetes
  • GitHub
  • Keyless access
  • Enterprise SSO
  • Cost estimates
  • Encrypted state
  • Audit log
The Platform

Everyone else sells you the kit. DevPlus is the platform, already assembled.

Catalog, private registry, encrypted state, isolated execution, policy engine, cost engine, and identity. One product, one tenant, zero pipelines to build.

A team of agents. Every write behind a card.

A supervisor plans; specialist agents deploy, price, debug, update, and delete real infrastructure from plain language. Nothing that creates or destroys infrastructure happens without an interactive approval card, and every approval is hashed into a durable audit log.

Deploy, cost, health, update, delete, catalog, and architect agents
Parameter forms pre-filled from your discovered resources
Each agent acts under its own least-privilege policy
Explore the feature set
DevPlus AIAgent team
You ask → Agent → Approval card
"Deploy an EKS cluster"
deploy_agent
Parameter form → approve
"What would this cost?"
cost_agent
Plan-only preview · $312/mo
"Why did it fail?"
health_agent
Logs + error lines
"Design infra for our API"
architect_agent
deploy_agent
Cited design · principles applied
How it works

From cloud account to governed infrastructure, in seven chapters.

By the end of this section you'll know how DevPlus actually works, not just what it claims.

  1. 01

    Connect

    Connect your cloud environments and your source control. With keyless access there are no stored cloud keys, and every action shows up in your cloud's own audit log.

    keyless connectors · short-lived credentials · fully attributed
  2. 02

    Discover

    A read-only scan inventories everything you run across your clouds and flags anything exposed to the internet. The AI reads these facts; it never invents them.

    read-only · every region · facts, not guesses
  3. 03

    Set your rules

    Write your rules once: Architecture Principles that shape every AI design, and policies that set cost limits and guardrails for every action.

    your rules · always applied · deny by default
  4. 04

    Ask

    “Design the infrastructure for our payments API.” The Architect studies your environment first, then proposes one clear design. Prefer forms to prompts? The same catalog deploys with a click.

    research first · grounded in your cloud
  5. 05

    Review

    The design shows its work: why each piece was chosen, what it reuses, and which of your rules it follows. Edit it, then approve it; nothing runs before you do.

    cited choices · your approval required
  6. 06

    Approve and deploy

    Each component rolls out through the governed pipeline: plan, cost estimate, policy check, then apply, with logs streaming live.

    plan → cost → policy gate → apply
  7. 07

    Extend

    Missing a building block? The Architect authors it: writes the module, validates it, and publishes it to your catalog, with every file behind a review you approve.

    authored · validated · approved by you
The Enforcement Loop

Deterministic where it matters. Intelligent where it helps.

The LLM interprets intent. Deterministic code does everything that touches your cloud: a chain of custody that closes into a loop.

Evidence In
Environment facts
your discovered estate, computed by code
Decision playbooks
ECS vs EKS, ALB vs NLB, VPC topology…
Your catalog
the building blocks designs may use
Architecture Principles
your rules: always injected, never optional
One pass through the loop
1
Intent
A plain-language ask, or a catalog form. Interpreting it is the LLM's only job.
2
Cited design
Every component carries its evidence: facts, sources, principles.
3
Deterministic validation
Code, not the model, checks the design. Hard violations fail closed.
4
Hashed approval
You edit, you approve; the payload is hashed into the audit log.
5
Governed execution
Plan → cost → policy gate → apply, in an isolated run.
6
Back to facts
Rescan, and the new infrastructure grounds the next design. The loop closes.
What You Can Prove
Blocked means told

Named denials

every block names the policy that fired
Approval is evidence

Hashed

what ran matches what a human approved
Attribution

CloudTrail

every AWS call on the keyless path traces to a deployment
Not scanned means blind spot, never evidence of absence: the AI can't assert what it hasn't seen.
Platform Capabilities

Twelve capabilities. One policy engine they all answer to.

A governed catalog, an AI team that follows your rules, and an isolated execution engine, with policy and cost checks built into every path.

01

The Architect Agent

Describe what you're building; get a reviewable design grounded in your real environment, with a citation for every choice, then deploy it in dependency order.

architecture planproposed
orders-apicatalog · v2.3.1
billing-queueauthor · provide · skip
citedreuses your 2 existing EKS clusters in us-east-1
02

Architecture Principles

Your rules, written once and applied to every AI design: deny-lists, catalog-only, and directives, all visibly cited on every plan.

Catalog-only · hardNo serverless · hardShared ALB · advisory
03

Cedar Governance

Deny-by-default policy on every request, plus a gate between plan and apply that sees cost and blast radius before anything runs.

04

An AI Team, Not a Chatbot

Specialist agents deploy, price, debug, update, and delete from plain language, every write behind an approval card, every approval hashed and logged.

05

Deterministic Discovery

Read-only scans inventory your estate and flag internet exposure. The AI consumes structured facts about your cloud, it never produces them.

06

Governed Catalog

Curated templates with pinned versions and admin-controlled parameters: self-service with the blast radius you choose.

07

Private Module Registry

Import modules from GitHub or the public registry into a private registry of your own, with every version analyzed and validated.

08

Cost Before Apply

A cost estimate on every plan and actuals after apply. Cost is policy context, so a change that plans over budget never applies.

09

Keyless Cloud Access

Keyless connectors issue short-lived credentials per deployment and attribute every cloud call in your audit log. No stored keys on the keyless path.

10

Secrets as Pointers

Secret values stay in your cloud's secret manager, are resolved only at deploy time, and never appear in forms or logs.

11

Self-Destructing Environments

Put a TTL on any deployment and it tears itself down when time runs out: load-test environments that clean up after themselves.

12

Hard Multi-Tenancy

Every tenant is fully isolated: its own infrastructure, database, identity, and encryption scope, with enterprise SSO built in.

The AI never holds the keys and never gets the last word.
How DevPlus protects your clouds, your credentials, and your tenants.
Read the security page
Ready to see it on your stack?

Opinionated by you, not by the model

Watch the Architect design under your principles, see a plan clear the cost and policy gates, and deploy it live, in about 30 minutes.

Live product, not slides
Your cloud, your scenarios
Security questions welcome