Skip to content
Product Overview

The Data Plane for Software in the AI Era

Crash Override runs inside the build, inspecting and tagging every artifact. Your entire software path, CI to production, becomes visible. No agents. No migration. Five lines of YAML.

Desktop agent · one line of YAML · minutes to value.

Build Visualization clickhouse-dbt · #398
ubuntu 24.04 · #186072bba1b2
#a0f0007 → #eee5946 acme/clickhouse-dbt
Built images /dbt/Dockerfile
ECR us-east-1 3 tags · #40a4ae0e
Services
Dev Prod POC UAT
Packages
Downloads
Full build lineage · commit to production · SLSA L3
01 · Understand

Understand what gets written.

Crayon runs in the developer's native environment, capturing what humans and AI agents write before code reaches the build. Every prompt, every tool call, every edit, every commit — observed and understood at the source. You don't see surveillance; you see provenance start where the code starts.

  • Captures human + AI agent activity in real time
  • Understands every prompt, edit, and commit at the source
  • Works alongside Claude Code, Copilot, Cursor — no IDE plugin required
01 · Understand
now file WRITE src/api/payment-handler.ts claude
2s proc SPAWN node --inspect dist/server.js dev
5s net GET registry.npmjs.org/stripe claude
8s file WRITE package.json (+1 dep) claude
12s git COMMIT fix: update payment retry dev
15s tool OPEN VS Code — 3 extensions dev
18s file READ .env.production (secrets) copilot
22s proc EXEC docker build -t api-gw . dev
2 humans 2 agents 14 file ops 3 network
02 · Inspect

Inspect what gets built.

Once code reaches the build, Chalk runs inside the build system itself. Every dependency resolution, every layer mutation, every file that lands in the final artifact — observed as it happens, not inferred afterward from a scan. Deterministic. No false positives. Build systems don't hallucinate.

  • Inspects builds from inside, not outside
  • Captures dependencies, layers, and build environment
  • Deterministic — no inference, no probabilistic guesses
02 · Inspect
Source
COMMIT_ID a3f7c2d ✓ signed
CODE_OWNERS @platform-team
Build
DOCKER_BASE alpine:3.19
_IMAGE_LAYERS 7 layers inspected
SBOM — actual vs declared
express 4.18.2
lodash 4.17.21 removed by build
node-ipc 11.1.0 added in build
event-stream 4.0.1 ⚠ malicious
... 138 more
03 · Tag

Tag what ships.

Every artifact carries its own provenance. A cryptographic chalk-mark embedded in the artifact records exactly what went into it: source commit, contributors (human and AI), dependency list, build environment. Sign once at the build, verify anywhere downstream. SBOMs that are actually true.

  • Cryptographic signature embedded in the artifact itself
  • SLSA Level 3 attestation, built in
  • SBOMs derived from observed build, not self-declared
03 · Tag
api-gw:v2.4.1 embedding tag...
CHALK_ID 4f8a2c1e-b7d3
SIGNATURE ✓ ed25519
COMMIT a3f7c2d (signed)
SBOM 142 components
SLSA Level 3
BEACON enabled
Tag embedded — artifact carries its own proof
04 · Track

Track what runs.

Tagged artifacts beacon back from every environment they run in — dev, staging, prod, edge, anywhere. Query a container in production and you get the full chain back to the prompt that started it. Drift surfaces the moment it happens. Incident response becomes seconds, not days.

  • Live beacons from every environment
  • Full chain back to the originating prompt or commit
  • Drift detection across the fleet
04 · Track
api-gw us-east-1 3 replicas 8s ago
api-gw eu-west-1 2 replicas 12s ago
worker us-east-1 5 replicas 4s ago
cron-job ap-south-1 1 replica drift
Common Questions

Everything developers ask before they install.


See it in your codebase.

Book 30 minutes with an engineer. We'll run Crash Override against your repository live and show you what we find.