Solumbe · how it works

Models generate the change. Solumbe proves whether it is safe to merge.

A local-first, deterministic trust layer that runs beside Claude Code, Codex, Cursor and Gemini. It builds context before the agent edits, measures how far the change reached, gates the exact staged tree, and leaves a record after the merge. No server, no account, and no code leaves the machine.

Three ways in

Pick one; the evidence is identical.

  1. 01

    Know the repository

    solumbe · reads the checkout

    Shape, symbols, commands and ownership, from the code rather than from a rules file. Cached per user; the repository itself is never written to.

  2. 02

    Before the edit

    solumbe · deterministic, with one optional advisory read

    What the request actually touches, what it will cost an agent, and how much model it deserves. All of it is computed before a token is spent on the change.

  3. 03

    The edit

    the model · through its own harness

    Solumbe does not generate code. The agent writes the change in Claude Code, Codex, Cursor, Gemini or any MCP host, calling the tools above through MCP or the CLI.

  4. 04

    Before the merge

    solumbe · from the diff and the repository, never from the model

    Did the intent happen, did only the intent happen, and is the exact staged tree safe to merge? The verdict recomputes to the same value on any checkout.

  5. 05

    After the merge

    CI · solumbe attest

    Every merge to main leaves a hash-chained record of what shipped and under which verdict, in your own repository, verifiable by anyone.

  6. 06

    Over time

    solumbe · graded against the repository's own history

    The risk flags and the router are measured against what this repository actually needed to fix, and decline to answer when the sample is too small.

What comes out

Durable, recomputable, and readable without solumbe installed.

What never happens

The gate never consults a model

PASS, WARN and FAIL are computed from repository state. The one model read solumbe can make, for a tier or a context pack, is advisory and has no path into the verdict.

Nothing leaves the machine by default

The core commands and every MCP tool open no socket. --pr reads GitHub through your own gh login; route sends the request text to Jev only on your own key.

Same inputs, same output

Run anything twice and get the same answer. Receipts and ledger records are timestamp-free hashes anyone can regenerate from the same checkout.

Evidence, not approval

A passing local gate is never an automatic merge. Hosted CI, GitHub review, CODEOWNERS and the human release decision remain separate authorities.