An AI co-worker your security team can sign off on.

Pragma is an AI co-worker for the whole software delivery cycle: it refines and plans work, builds and tests it, reviews it, modernizes what you inherited, and delivers pull requests your own team merges.

From an item on your board to a pull request your team merges

Label an item and Pragma does what a careful engineer would do, ending at a pull request your own reviewers read and merge.

Story to pull request

Label a story and Pragma refines it, plans the approach, writes and tests the code, and opens a pull request your team reviews and merges.

Workflows you configure

Every stage Pragma runs is a workflow definition your team can read, edit and version, so the way the work is done is yours to set.

Bugs reproduced before they are fixed

Report a bug and Pragma writes and runs a failing test first, finds the change that broke the behaviour, and only then proposes a fix.

A review that is its own run

A separate run reviews the exact revision for quality and for security, and records every finding against that revision.

Reviews on a schedule

Pragma reviews a repository for security, quality and bugs on a schedule, and the findings your team approves become items on your board.

Pull requests that stay mergeable

Pragma keeps the pull requests it opened mergeable, and explains or resolves a conflict when you ask it to.

Modernization, from an unfamiliar system to a plan on your board

Point Pragma at a system nobody wants to touch and it reads it, maps it, and proposes the work in the order it can safely be done.

Assessment at a pinned commit

Pragma takes stock of a repository at one exact commit: its technology stack, its dependencies, the ways into it and how it is laid out.

A plan you approve, pushed to your tracker

What the assessment found becomes epics and stories you review, and the ones you choose are pushed to your tracker as real items.

A map from the business to the code

Pragma names what the business is able to do in the words the people who run it use, and says which parts of the code deliver each capability.

A teammate in the tools your team already uses

Pragma works where your team already talks. It answers, it asks when something is unclear, and it waits for a person rather than guessing.

Answers where you asked

Mention Pragma in a Microsoft Teams or Slack channel, or in a comment on a board item, and the answer arrives where you asked it.

It asks instead of guessing

When a story leaves something open Pragma asks the owner on the item, waits, and carries on from the recorded answer.

A reviewer you can reply to

Reply to Pragma on a pull request and it answers on the thread or makes the change and says what it changed, and on a pull request somebody else opened it reviews and never pushes.

Commands grouped by area

Pragma's chat commands are grouped by area in Microsoft Teams and Slack, so somebody can find what to ask for without learning a syntax.

Scope changes go to the owner

When the work turns out to be larger or different from the item, Pragma puts the scope change to the product owner and records what was decided.

Work that waits for a person

A run that needs a person parks, says who it is waiting for and what it needs, and resumes on command.

Evidence travels with every change

A change arrives with what would otherwise be taken on trust: what was asked, what was tested, what was found, how long it took and what it cost.

Acceptance, criterion by criterion

Each acceptance criterion arrives marked met, partly met or declined, with the tests, the review findings, the wall time and the AI cost that produced it.

Your own CI, recorded

Pragma watches your CI on the branches it owns and records what your pipeline concluded about the change it opened.

Before and after, for anything people look at

A change to a screen arrives with before and after images of what it touched.

It learns your codebase, and cites it

Pragma reads the repositories and documents you connect, so its work is grounded in your system rather than in a guess about it.

A searchable index of your repositories

Pragma builds a searchable index of each repository you connect at one exact commit, so later work can find and cite the code it needs.

Your documents, alongside the code

The documentation you connect, from wiki spaces to the documents in your repositories, is indexed with the code, and each answer can name the page it came from.

Your conventions, not generic code

An approach is shaped from your repository, its conventions and the guidance your team keeps in it, and is posted to the item before anything is built.

Policy, approvals, spend and the record

What Pragma may do is a document your CTO signs. What it did is a record your auditor can read.

One policy document per company

A versioned policy document sets autonomy thresholds, the most a story may be projected to cost before Pragma refuses to start it, how much work a team may have in flight at once, which tools a build may run, data boundaries that limit which repositories and knowledge sources Pragma reads, and quiet hours that hold Pragma's messages while work continues.

Who may approve what

Roles and permissions decide who may approve, run and spend, and the published matrix is generated from the code that enforces it.

Every action attributed

Every action is attributed to the person or the workflow that caused it and kept in an audit record your team can read and export.

Usage and cost, run by run

AI usage and cost are recorded per run, per team and per company, so spend is visible while it happens rather than at the end of the month.

A hold you can set per repository

You can hold Pragma's pull requests on a repository, so nothing is opened where your team is not ready for it.

One published sizing standard

Pragma sizes work against one published standard and names the risk that sizing carries, so an estimate means the same thing every time.

Connected to the systems you already govern

Your tracker, your source host, your chat, your identity provider and your AI provider, each connected under credentials you hold.

Your trackers and source hosts

Jira for work, GitHub and Bitbucket for code, Confluence for documents, Microsoft Teams and Slack for conversation, and Microsoft Entra ID for identity.

Your AI provider, your key

Pragma runs on the provider and the model you choose, under a key you hold and can revoke, and the agreement with that provider stays yours.

Endpoint policy set by the platform

Which AI endpoints may be reached is set by platform policy while the key stays yours, so a model nobody approved is never called.

Setup that asks only what applies

Setting up a company asks only the questions its own answers make relevant, commits each section as it is filled in, and leaves every value editable in settings afterwards.

Security and governance architecture

Written for the person who has to sign this off. Mechanisms, not adjectives, and the assurance we actually hold.

Assurance

Pragma has not yet been audited.

Each job in its own container

Each job runs in its own short-lived container, your code is cloned into it, and the container is destroyed when the job ends.

A second sandbox for builds and tests

Builds and tests of that code run in a second, locked-down sandbox with no route to the internet and no credentials inside it.

Where your content goes, and where it does not

Reasoning and code generation go through your own provider key by platform policy, while the search index of your code and documents is built by an embedding model Pragma hosts itself, so that content is not sent to a third-party model for indexing, and Pragma trains no model on your content.

What the index keeps

The index keeps excerpts of your code and documents and their vectors, the excerpts encrypted under your company's own key, and it is deleted with your company's data.

The working copy does not outlive the job

The working copy of your repository is destroyed with the job's container.

One key and one boundary per company

Each company's stored content is encrypted under that company's own key, with row-level isolation in the database and retention that deletes working data after a story ends while keeping the evidence.

Isolation the database enforces, tested every release

Isolation is enforced by the database, not by application code remembering a filter, and each release is tested with two separate test tenants, each attempting to reach the other's rows. No customer data is used in testing.

Nothing merges without your own review rules

Every action is attributed and audited, approvals and spend limits are policy, and nothing merges without your own review rules.

Request a pilot. A pilot runs against a staging copy or a fork with your own provider key, so no production access is needed to evaluate it.