The independent control and evidence layer for AI-generated software change.
01 / what NEO is
What NEO is
AI now generates more change than teams can safely review. NEO is the independent layer that bounds what an agent may touch, proves what actually happened, and keeps a human in authority over what ships — making AI-generated change defensible and reversible.
02 / control surfaces
Six control surfaces
NEO gives AI-generated change a controlled surface area: bounded authority, independent evidence, and a human decision at the edge.
Scope & path control
Every change is bounded before it starts: approved intent, allowed paths, and protected files and secrets an agent may never touch.
Connects to: Protected execution, Rollback & human authority
Scope & path control
Every change is bounded before it starts: approved intent, allowed paths, and protected files and secrets an agent may never touch.
Connects to: Protected execution, Rollback & human authority
Open ->Protected execution
Work runs inside enforced boundaries — write mediation and snapshots before any destructive step, nothing beyond the approved surface.
Connects to: Scope & path control, Evidence custody
Protected execution
Work runs inside enforced boundaries — write mediation and snapshots before any destructive step, nothing beyond the approved surface.
Connects to: Scope & path control, Evidence custody
Open ->Frozen acceptance criteria
Acceptance tests are authored and frozen before implementation, so the bar can't move to fit the result; judges are checked for vacuity.
Connects to: Independent audit, Evidence custody
Frozen acceptance criteria
Acceptance tests are authored and frozen before implementation, so the bar can't move to fit the result; judges are checked for vacuity.
Connects to: Independent audit, Evidence custody
Open ->Independent audit
A cold, context-isolated channel re-runs the evidence — not the builder's narrative — and recommends keep, remediate, or reject.
Connects to: Frozen acceptance criteria, Evidence custody, Rollback & human authority
Independent audit
A cold, context-isolated channel re-runs the evidence — not the builder's narrative — and recommends keep, remediate, or reject.
Connects to: Frozen acceptance criteria, Evidence custody, Rollback & human authority
Open ->Evidence custody
Hashes, diffs, test output, residue checks, and decisions form a re-auditable record held independently of the agent that made the change.
Connects to: Independent audit, Protected execution, Rollback & human authority
Evidence custody
Hashes, diffs, test output, residue checks, and decisions form a re-auditable record held independently of the agent that made the change.
Connects to: Independent audit, Protected execution, Rollback & human authority
Open ->Rollback & human authority
Every change is reversible, and a human holds the final keep/iterate/reject decision. Authority is never delegated to agent confidence.
Connects to: Scope & path control, Independent audit, Evidence custody
Rollback & human authority
Every change is reversible, and a human holds the final keep/iterate/reject decision. Authority is never delegated to agent confidence.
Connects to: Scope & path control, Independent audit, Evidence custody
Open ->03 / how it works
Governed change moves through a fixed path
authorize
Authorize the change
Intent, authority, paths, protected files, budget, and risk are approved before execution begins.
execute
Execute under policy
The change runs inside the approved surface, with custody boundaries and snapshots preserved as it moves.
review
Review the evidence
A separate review path produces findings, rerun output, diffs, and a re-auditable acceptance packet.
decide
Keep, iterate, or reject
A human makes the final call. The decision can keep, remediate, reject, or roll back the change.
04 / principles
Principles
evidence-over-confidence
Evidence over confidence
A convincing summary is not a result. What ships is judged by reproducible artifacts — tests, diffs, residue — not by how sure an agent sounds.
separation-of-powers
Separation of powers
The party that writes a change never grades it. Building, judging, and auditing are different seats, so no one can move the bar to fit their own work.
bounded-authority
Bounded, reversible authority
Every change is scoped before it starts and reversible after it lands. Authority to accept stays with a human; nothing consequential ships on autopilot.
honest-maturity
Honest about maturity
We label what is proven and what is not. NEO is proven in founder-operated development today; commercial proof is earned through paid evidence, not claimed in advance.
05 / why independent
Why independent governance
Separation of powers
The party that writes a change never grades it. Builder, judge, and auditor are different seats.
Independent evidence custody
The acceptance record is held apart from the agent that made the change, so it can be re-audited later.
Human authority
A person makes the final keep/iterate/reject call; agent confidence is never evidence.
Portable policy
Scope, controls, and evidence travel across repositories, agents, and model providers, rather than living inside one platform.
These are the properties NEO is built to provide; whether teams will pay for independence over bundled controls is what our first paid evaluations are testing.
06 / the long view
As AI writes more of our software, the scarce thing is no longer code — it is acceptance you can defend.
About the company ->edge · start a governed audit
Start with a governed audit.
The first step is a bounded evaluation: an independent audit of one high-consequence change in a real repository, producing a re-auditable acceptance packet and a keep, remediate, reject, or rollback decision you can defend.
Early engagements run as hands-on, paid design partnerships - one supported stack, direct access to the people building NEO, and honest limitations stated up front.