Intent, not schema
The bootstrap scoper asks what you are actually building, in plain language, and extracts a typed brief as a working document the team edits — not an LLM one-shot.
The orchestration layer you do not have to build.
27 tRPC routers, 90 tables, a workflow engine with 20 template variables, discussions that verify file paths before the answer reaches your screen, six-phase self-repair with Ipcha-gated autonomy, Axiom RAG with authority tiers, BYOK across four providers, fail-closed multi-tenant RLS. All the boring infrastructure you keep almost-building, already built.
Subsystems / the how behind the claim
Orchestration, durable context and specialised product workflows. The system underneath the systems — each subsystem does one boring thing properly, and the compound piece is how they talk.
The bootstrap scoper asks what you are actually building, in plain language, and extracts a typed brief as a working document the team edits — not an LLM one-shot.
Single, parallel, or consensus rounds across four providers. Every answer claiming to cite a file is verified server-side against the repository; truncated replies carry a flag downstream steps cannot ignore.
An AsyncGenerator engine that streams events the instant they happen. Twenty template variables pull context from repos, database, axiom and memory — prompts stop being strings and become compositions.
Review steps surface findings; humans approve or edit them; approved points persist with embeddings and flow back into the next workflow via hybrid search — a closed learning loop.
Mandatory, guideline, informational — three authority tiers. When the 80 k context budget gets tight, informational chunks drop first, guidelines second, mandatory never.
Tenant keys encrypted with AES-256-GCM, decrypted per request, tenant-scoped. Usage logged down to time-to-first-token and USD cost — billing, budgets and forensics from the same table.
Self-repair / six phases, tiered autonomy
Enumerate targets in the chosen branch; CKB structural analysis runs first when an index is ready.
LLM detection proposes findings grounded in CKB context — severity, file range, evidence.
Ipcha validation red-teams every proposed finding; scores below threshold get dropped.
Bounded fixes — never the Prisma schema, never auth middleware — re-validated against CKB.
Every surviving fix lands as a PR with audit breadcrumbs. Low severity plus high score may auto-merge; humans gate the rest.
Why teams run it
nyxCore avoids exotic dependencies. Postgres is Postgres, Redis is Redis, Next.js is Next.js. The compound piece is how the layers talk — streaming, fail-closed, audit-logged, tenant-scoped.
Fail-closed multi-tenancy.
Row-Level Security on every tenant-scoped table. If the app layer forgets to filter, the database still does; requests without a valid tenant never see any rows.
Audit logs that answer auditors.
Every admin action — tenant switch, role change, key rotation, compliance export — is logged with user, IP and payload, queryable via the audit router.
Usage logs deep enough to bill from.
Every LLM call lands as a log row with provider, model, tokens, latency, time-to-first-token and cost in USD. Billing and quota run from the same source.
Provenance on every finding.
Action points, insights and audit runs link back to the discussion, review or scan that produced them. Open a compliance finding and follow the trail to the paragraph that caused it.
“The orchestration layer. Not another dashboard.”
nyxCore — the working claim
One deployable, one backup, one door
No microservice fan-out, no hosted control plane, no out-of-band cron box. Workflows, discussions, self-repair, billing, audit, MCP — one Next.js standalone server behind one Traefik router, next to one Postgres and one Redis. If the database walks out on a USB stick, your nyxCore installation walks with it.
nyxCore assumes you want audit logs, roles, RLS, BYOK vaults, and a shared context that survives vacation. If your operating mode is a single user editing production at 2 a.m. with no review gate, the ceremony will slow you down — and speeding you up is the product. A solo-reader free tier ships mid-2026; until then the sign-up form is the waiting list.
Today's only door is self-host. Production assumes PostgreSQL 16 + pgvector, Redis 7, a Node 20 runtime, Traefik-grade TLS termination, and an Anthropic / OpenAI / Google / Ollama key. The managed SaaS tier is on the Q3 2026 roadmap. If you cannot own the stack and cannot wait, shop something already managed.
Aristaeus, Ipcha Mistabra, Harmonia, Metis — these are not neutral templates. They carry a specific way of thinking about review, shipping, and honesty. Adopting nyxCore means adopting the vocabulary before you can remix it. Teams that want fully neutral templates will feel railroaded; you cannot strip the opinion without stripping the product.
Open the dashboard if you are already a tenant. Otherwise tell us what you want to build — the access form routes through our own mailserver, no third-party email provider in the loop.