Point it at your repo. Get a verified map, module by module.
Sphoton reads your codebase and database schema, drafts what each module does — with file:line evidence — and has you confirm every fact.

One module in Sphoton. Every fact on this screen was AI-drafted, human-approved.
Three things worth knowing.
AI drafts. You ratify.
shippedEvery finding arrives as an assertion: a claim, a confidence score, evidence one tap away. Nothing becomes knowledge until a human says so.
It runs on your machine.
zero-knowledgeNo upload, no mirror, no server-side index. Content is encrypted under a per-workspace key before it leaves — the server stores ciphertext it can't read.
And it stays true.
drift-flaggedImport a schema change that touches a certified module and it flips to Stale until re-verified — along with everything derived from it.
Which one are you?
The walk is the same either way — but we'll be honest about the shape Sphoton serves best.
Full salary, every week, while he rebuilds a picture three people already have.
To do
Doing
locale rounding
Done
2 tests
Covers what he remembers to say — not what he knows.
You hired him for the skill and he has it. What he does not have is the map — which part of this system does what.
Forty-one tabs by Thursday. No file tells him which other files care about it.
Change the tax rate here and invoices change too. The code does not say so anywhere.
Written eleven months ago by someone who has left. Half of it is still true. He cannot tell which half.
Three hours for a reply, and the reply is a name. Every answer here is a person, not a place.
You are paying senior rates while he rebuilds a picture the room already has.
Two tests, one review, green. Everyone signs it off.
It also touched Notifications. Nobody told him — and nothing in the repo told him either.
That is not caution. That is a missing map — and the next hire will pay for it again.
Not the files — the system. Which modules talk, what breaks, and why that cache exists at all.
Twenty-one days of notice. Twelve modules only he can explain.
The standard answer. Book the time, record it, take notes.
Not what he knows. Nobody can dictate five years in four and a half hours.
He tells one person, who tells the next. Every hop loses precision, and nobody downstream can tell what was dropped.
The modules are still there. The understanding that made them safe to change is not.
A locale change double-charged 1,900 invoices. Bob would have caught it in review.
Finding it meant learning what Bob knew, under pressure, from the code alone.
And there is no way to know what else walked out until the next thing breaks.
Four people asked her four questions this week. Two were the same question.
Not knowledge transfer — doubt clearing. Questions already answered once, for somebody new each time.
Twenty minutes explaining Payments. It understands — genuinely. The session is excellent.
New chat, empty memory. And overnight five people changed the code, so what it knew was already out of date.
Five impacted modules, re-typed from memory. 91% of the context is gone before the work starts.
Notifications changed last sprint and her summary did not. The agent designs against behaviour that no longer exists.
One wrong assumption, six roles, and the whole cycle runs a second time.
Nobody lacked skill. One fact this team already owned was not where it was needed.
Understanding does not persist. It gets re-learned, re-told and re-typed — and it loses accuracy at every step.
Hired for skill. Stopped by the one thing the repo doesn't contain.
Translation
CertifiedNot a folder — a piece of your system a human would name out loud.
Ranked by confidence, ambiguous calls flagged, not hidden. Include or exclude any of them — the module is yours.
An agentic loop with read-only, sandboxed tools. Watch what's missing from this log: an upload step.
Every claim carries a confidence score and evidence at file:line. One of these five is wrong — that's the point.
Accepted claims become knowledge — attributable, evidence-backed, and re-checkable.
The tax table belongs to Billing. Rejected, permanently: human confirmation outranks AI inference. A later analysis that disagrees raises a conflict, it doesn't overwrite you.
Fidelity lands at 74, not 100. Operations scores 24 because the code is silent there — so the gap is flagged, not filled.
Certified knowledge rolls up into the working views — screens, facets, entry points, diagram, mapped files.
It flips to Stale on the spot, along with everything derived from it. Where knowledge and code disagree, the code is right.
A fresh analysis, three facts re-confirmed, fidelity 78. Certified again — and that is the whole product.

Every module reads at three altitudes. Each layer is a faithful compression of the one below.
One paragraph, three vital signs
~180 tokFive named aspects
~1.2k tokA recursive tree
~9k tokA signed manifest and a mandatory trust stamp per module — so the agent knows exactly what it's allowed to build on.
Shrink it to 4k and the pack drops a layer — it never hands the agent half a sentence.
The loop you just watched. Modules anchored to real tables, verified fact by fact, served in layers — plus a repo-grounded Ask chat that answers with citations.
Describe a big change in conversation. A deterministic probe grounds every artifact against the real module graph at zero model tokens — impact is computed, not guessed. Then export an agent-ready brief through a gate that refuses until every impact row is grounded.
A drillable ERD where every column carries a human-verified reason to exist. New in beta: connect a live SQL Server and browse its real structure — metadata only, introspected on your device.
Honestly a wheel slot and a promise. It ships after live release, shaped by what beta users ask for. We list it because you'll see it in the app — not because you can use it.
Every guarantee, then its limit.
Each card shows what we guarantee — then turns itself over to show what we won't claim.
Our servers can't read your knowledge.
Every content field is AES-256-GCM encrypted on your machine under a per-workspace key before it leaves.
turns over…What we won't claim
"Nothing reaches our servers" would be a lie. Ciphertext and governance metadata — emails, branch names, scores, timestamps — do. So we say: nothing we can read.
the limitYour repo never leaves your machine for us.
No upload, no mirror, no server-side index. Analysis runs locally with read-only, sandboxed tools.
turns over…What we won't claim
During analysis, requested code slices go to Anthropic under your key and their terms. That is the honest shape of BYOK.
the limitBYOK, literally.
Your key lives in your OS keychain and calls api.anthropic.com from your machine. Never sent to us, never logged.
turns over…What we won't claim
You pay Anthropic directly — no token markup. A fair-use daily AI budget applies per tier: governance, not a meter we bill.
the limitTeam sharing is cryptography, not a checkbox.
Adding a teammate wraps the workspace key to their RSA-4096 public key; invites show fingerprints you can verify out-of-band.
turns over…What we won't claim
Workspace-key rotation when a member leaves is designed and on the roadmap. Today, removal revokes access server-side.
the limitRecovery without custody.
A one-time recovery-key ceremony. We can't reset what we can't read.
turns over…What we won't claim
Zero-knowledge cuts both ways: lose that key and the workspace is unrecoverable. Guard it like a root credential.
the limitDrift gets flagged.
A schema import that touches a certified module flips it Certified → Stale on the spot, and evidence links re-locate live so they can't rot.
turns over…What we won't claim
It is event-driven: it fires on schema import and re-checks, not a live file-watcher. "Personal" visibility is an access filter, not extra encryption.
the limitWe're closed source today with no published audit, so don't take "no decrypt path" on faith — verify what you can: watch the traffic; analysis calls go only to api.anthropic.com, and your key sits in your OS keychain. 500+ backend tests stay green behind the crypto core.
Capture and immortalize the verified understanding of every system.
A world where system knowledge never walks out the door.
Why I'm building this.
"I can understand anything accurately, in real depth — I just can't remember all of it. Neither can the AI. That is the whole problem: the understanding is real, and then it's gone, or quietly out of date.
So the persistence of that understanding, its accuracy, and its freshness — that's exactly what this application manages. Not AI-inferred; human-validated, evidence-backed, refreshed when the code moves.
If that's your world, the beta is for you: tell me what breaks. I read every reply."
LinkedIn →Free to know your own codebase.
Every tier is BYOK — your own key, your direct bill, no token markup.
Shared living knowledge under shared-key cryptography — the shape most product teams need.
- Roles: owner / senior / dev / viewer
- Live co-editing locks
- Two-signature certification
- Team Gateway beta
One repo, the full living-knowledge engine. Not a trial.
- One repository
- Verification & layered modules
- Drift flagging
The full toolkit for one serious builder.
- Unlimited repositories
- Blueprint & Traverse
- Personal Gateway beta
Self-hosted Gateway, enterprise controls, guided rollout.
- Self-hosted Gateway
- Prototype → pilot → org-wide
- Enterprise controls
swipe the cards · Team leads, for a reason
No download, no card, no demo call — the waitlist is the whole funnel, on purpose. Founding users keep these prices for life.