A governed route
Local models by default, free lanes within budgets and breakers, frontier spend capped at $0 unless raised.
Home / Karta · In internal evaluation — not released
Karta is the AI coding agent we are building for teams that need control: it works inside the permissions a task allows, on a cost-governed route, stops for a person where it should, and keeps a record of every step.

01 / 08
Before any work, a request takes a governed route: our own GPU mesh first, in an order people set and checked for health; vetted free hosted lanes only if the mesh is down, each checked for credentials, remaining daily budget and a tripped breaker; frontier models behind a gate whose spend cap is $0 by default. It is a governed order with live checks, not a live auction for the cheapest answer.

02 / 08
Karta sees the repository as a city of files. A task comes with a grant — the parts it may change — and a fence round protected paths: deployment, its own safety tooling, the rules it works by.

03 / 08
It reads, plans and proposes a change as a diff — here, adding input validation to a form handler in a sample repository (a fictional task).

04 / 08
Touching a protected path stops the work until a person approves; the approval fails closed and cannot be replayed. Then the project's own checks and tests decide whether it is done — a failing test sends it back to revise.

05 / 08
Every step is written to a record. Older steps are compacted, yet each can be expanded back into its detail when needed. Security-relevant events go to a separate, hash-linked chain that can be verified end to end.

06 / 08
Long histories fold without losing their errors — failure lines are always kept. What Karta learns is stored as a lesson only after the task that produced it passes its gates.

07 / 08
Karta can propose improvements to itself, built apart from the running version: a test that fails before and passes after, a person's approval, a shadow run and a way back. Changes to its safety controls are never promoted on their own, and nothing here runs unattended In development

08 / 08
A console will show it all in one place — health, budgets, approvals waiting, the verified record. Today the only interface is a terminal; the web app is in development In development
The parts running in our internal testing today.
Local models by default, free lanes within budgets and breakers, frontier spend capped at $0 unless raised.
A grant for each task; protected paths it cannot change without a person.
A pending approval is bound to what it approves and cannot be used twice.
Linting, type checks, the project's tests and a safety suite it cannot edit.
Every step recorded; security events in a hash-linked chain that detects tampering.
Commands run isolated, with the network off and credentials kept out, by default.
| Step | How it decides |
|---|---|
| Our GPU mesh | First, always: models in an order people set, each checked for health; the first healthy one runs |
| Free hosted lanes | Only when the mesh cannot serve: a vetted order, then live checks of credentials, remaining daily budget and circuit breaker |
| Frontier models | Behind a gate with a monthly spend cap of $0 by default |
| Learning the best route from data | In development |
| A running record of spend | In development |
Illustrative: the checks a Karta task passes through, composed from the controls running in our internal testing. The task is fictional.
Tell us what an AI agent would need to be allowed to touch in your repositories, and what it must never touch. We will show you how Karta keeps to that.