The age of software factories
What will your factory ship?
Describe the product. A team of agents plans, builds, tests, and reviews it — inside a budget it cannot exceed. You approve; it ships.
- Runs on Cloudflare's network
- Every build sandboxed
- Hard budget ceilings
- A human approves every change
- 01
Describe it
Plain language is fine. The architect turns your brief into a backlog you can read — and asks when it isn't sure.
- 02
Watch it get built
Engineers work in isolated sandboxes while you watch the plan, the tests, and the spend — live, not a spinner.
- 03
Approve it, and it ships
An independent reviewer checks every change. Approved work merges and deploys to a URL you can open.
Progress you can trust
A factory you can see into.
Every run streams its plan, its checks, and its spend. When something isn't working, Shipyard says so plainly — an unfinished task is a short report, never a surprise bill.
And "done" is decided by your project's own tests — not by a model's opinion of itself.
✓ plan approved — 4 tasks, ceiling $2.50
✓ 1/4 invoice model + migration $0.31 · 9 tests passing
✓ 2/4 QuickBooks export $0.56 · review approved
● 3/4 PDF templates running checks
○ merge → deploy invoice-app.shipyard.dev
Why Shipyard
Prototyping tools make demos.
Factories make products.
v0, Bolt, and Lovable are great for a Friday-afternoon prototype. Shipyard is built for the application your business will still be running in five years.
Security
Bold claims, honestly made.
Letting software write software is a real decision. Here is exactly what protects you — and the one thing we refuse to promise.
Isolated by construction
Every build runs in a fresh sandbox on Cloudflare's infrastructure — created for the run, destroyed after it. Your systems are never in the blast radius.
Your credentials stay out
The sandbox never holds your tokens. Repository access passes through an authenticated proxy outside the box — code inside can't leak a credential it never had.
A budget that cannot be exceeded
Spend ceilings are enforced in the payment path itself, per task and per run. Not a policy someone follows. A precondition the code checks.
Nothing merges itself past you
Every change is a pull request with an audit trail, and your approval rules decide what lands. There is no setting that removes you from the loop entirely.
Communication
Written like a person, because we check.
No confetti. No "I hope this email finds you well." When Shipyard writes to you — a progress note, a pull request description, a question — it's brief, specific, and readable in one pass.
If a message reads like it was churned out by a machine, we treat that as a bug and fix it like one.
Morning —
The QuickBooks export is done and tested: 14 files changed, all checks green.
One thing worth your attention: I renamed tax_rate to
tax_rate_bp (basis points) to avoid float rounding on totals.
PR #12 explains the tradeoff.
— Shipyard · $1.14 spent of your $2.50 ceiling
Questions
Asked and answered.
What does it cost?
You pay for what the factory actually does, under a ceiling you set before any work starts. The ceiling is enforced in code — a run stops itself rather than pass it. Beta pricing goes out with invitations.
Who owns the code?
You do. Work lands in your repository, under your license. If you leave Shipyard tomorrow, you keep everything — including the deployed app.
What happens when the factory gets stuck?
It stops and says so, plainly, with what it tried and what it spent. Unfinished work is a short report, never a surprise bill.
Which stacks do you support?
TypeScript and Node.js applications first, with more stacks during the beta. Tell us what you run — the waitlist brief is the roadmap.
Is my code used to train models?
No.
Be there when the docks open.
The age of software factories is beginning. One email, when it's your turn.
You're in. We'll write when your dock is ready.