Private coding agents
CLI and IDE workflows for review, tests, refactors, migrations, and docs inside controlled environments.
UK-sovereign AI for sensitive engineering
Modern developer AI for teams that cannot send code, tickets, logs, or architecture into foreign SaaS.
Early-stage product. This site describes our direction, roadmap, and design goals.
$ bastion review --repo internal-controls
context: 14 files retrieved locally
model: UK-hosted open-weight endpoint
egress: blocked unless approved
diff ready: 3 findings, 2 test updates
Repo-scoped context
Approval-gated tools
Audit-ready output
For teams where ordinary copilots are off the table.
The platform
CLI and IDE workflows for review, tests, refactors, migrations, and docs inside controlled environments.
Sandboxed test runs, repo-scoped permissions, egress controls, signed containers, SBOMs, and retention controls.
Built for UK infrastructure, private cloud, on-prem clusters, and future higher-assurance appliances.
Operating model
The roadmap centres on open-weight models, reproducible containers, customer-owned keys, tenant isolation, and approval-gated actions. Final controls depend on each deployment.
UK-hosted inference for sensitive workloads.
Single-tenant deployments for high-trust teams.
Audit trails for prompts, context, diffs, and tool use.
Human approval before writes, commands, or egress.
Assurance path
We are designing the product around the artefacts serious buyers ask for: controls, audit, deployment evidence, and reviewable security posture.
Pilot programme
Good first pilots: code review, legacy migration, test generation, documentation, and controlled refactoring.
founders@bastionworks.aiMeet the founders