For developers
Run the agent you already use through Selko.
- one line, no agent changes
- free · local · yours
- baseline first, then only the diff
Every file it touched, every command it ran, every connection it made — one signed record, from a witness the agent can't see.
selko run <agent>
Agents take shortcuts — a skipped check, a hard-coded value, a connection to production. Whatever gets the task done. Afterwards, this is the entire record:
"Fixed the failing auth test. 34 passing, no unrelated changes. Done."
The report may even be true. But it's the agent grading its own work — the only witness is the suspect. Claims, not evidence.
One line. The agent doesn't know Selko is there.
While the agent works, Selko watches from outside: files, commands, connections. When the run ends — one signed Behaviour Commit.
The first run is your baseline. Every run after shows only what changed.
selko run <agent>
Selko, watching from outside
src/auth.tsnpm testprod-db:5432signed by the witness
baseline first, then only changes · capture quality stated in every record
The agent's log said the tests passed. Selko saw the connection.
Selko knows. When the work demands it, Rauha contains the run inside a boundary you declare, and Vartio remembers what changed across every agent your teams run.
A Behaviour Commit binds three things: what the agent was told, what the run journaled, what the witness saw. Signed, content-addressed, and history is append-only.
Every record states its own capture quality. On Linux, Selko can watch from inside the kernel. Elsewhere it records at the level the platform allows — and says so.
openatexecveconnect — seen where the agent can't reach
correlates the stream, signs the Behaviour Commit
eBPF on Linux · platform APIs elsewhere · the capture level is stated in every record
Two runs that can't be compared fairly get one answer: can't compare. Selko never guesses.
Copilot on one team, Claude Code on another, Codex on a third — and each vendor's tool governs only itself. The organization owns the harness instead: any agent runs inside it, recording always on, every run producing the same Behaviour Commit.
Then one rule, enforced by the CI already in place: no Behaviour Commit, no merge.
When the auditor asks what the agents did, the answer is a query, not an investigation.
regardless of agent vendor
one signed record per run
every Behaviour Commit feeds both controls and memory
no Behaviour Commit, no merge
shared baselines · what changed across the fleet
Selko can also hold the agent's claims against what the witness saw: the claimed action nobody observed, the observed action nobody claimed.
Run the agent you already use through Selko.
Bring one question about a mixed-agent fleet.
Occasional product updates and early-access invitations.
Unsubscribe at any time. Submissions are processed by FormSubmit.
You're on the list. Product updates will arrive by email.