Centrally Controlled Agentic Development
Qceptor documents every repository you own and serves it to your coding agents, scoped to what each developer is allowed to see.
- Every repository, not one open file
- Scoped by your directory groups
- Managed or self-hosted
qceptor · searched 4 repositories
Two services consume the retry contract. Both declare the ledger client as a build dependency, so both break.
ledger-corepublishes io.acme:ledger-client
payments-apibuild dependency, high confidence
settlement-jobbuild dependency, high confidence
Serves the tools you already run
- Claude Code
- Cursor
- Copilot
- Zed
- Windsurf
Anything that speaks MCP
The problem
Speed or control. Most teams pick one.
Lock agents down and developers route around it. Open everything and nobody can say what was read.
Lock it down
Agents answer from the one file in front of them, so developers paste context into whatever tool works.
Open it up
Agents read everything and move fast, and nobody can say what they read.
Agents that know the estate
Documentation for every repository, plus the dependency graph between them. Most assistants see one repo.
Access you set, not negotiate
Per repository, default deny, driven by your directory groups. What a developer cannot see never reaches their machine.
Proof after the fact
Every file read and tool run is recorded. Developers can see their own trail too.
How it works
Three steps, then it runs itself
No documentation to write, no per-developer setup.
Qceptor
- 01
Connect your sources
Source control, documentation systems and logging, configured once in the console.
- 02
Install the client on developer endpoints
Pushed through your MDM. Identity comes from device enrolment, so developers never sign in.
- 03
Run the first documentation job
Every repository you imported is documented, then regenerated on each push.
What you get
Built for engineering and security
The same product in every plan. The tiers differ in scale and control.
| Capability | Free | Team | Enterprise |
|---|---|---|---|
| Knowledge the agents get | |||
| Repositories documentedGenerated from source, regenerated on every push | Unlimited | Unlimited | Unlimited |
| Cross-repository dependency graphWith the evidence that proves every edge | ✓ | ✓ | ✓ |
| Works with the tools developers useClaude Code, Cursor, Copilot, Zed, Windsurf | ✓ | ✓ | ✓ |
| Import and exportRead from and write to the documentation platforms you run | — | ✓ | ✓ |
| Speed for developers | |||
| MachinesA laptop, a virtual machine or a build agent | 1 | Per seat | Per seat |
| Zero-latency answersResolved on the device, with no network round trip | ✓ | ✓ | ✓ |
| Zero-touch rolloutDeployed through your MDM. Developers never sign in | — | ✓ | ✓ |
| Fleet consoleCoverage, freshness, version spread, errors | — | ✓ | ✓ |
| Control for security | |||
| Audit trail of agent readsEvery file opened and tool run, per developer | — | ✓ | ✓ |
| Developer self-view of their own trail | — | ✓ | ✓ |
| Single sign-on and directory syncYour identity provider drives access. Never a top-tier upsell | — | ✓ | ✓ |
| Access policy per repositoryDefault deny, driven by your directory groups | — | ✓ | ✓ |
| Audit export to your security toolingStreamed continuously in a standard event format | — | — | ✓ |
| Operations | |||
| Deployment | Managed | Managed or self-hosted | Adds air-gapped |
| Hosting regionChoose where managed data lives | EU or US | EU or US | EU or US |
| Bring your own model providerGeneration runs against an endpoint in your own account | — | ✓ | ✓ |
Deployment
Hosted by us, or entirely by you
Same software, same policy. The only difference is where the console and the documentation live.
Managed
DefaultWe run the console, the storage and the generation. Nothing for you to operate.
- Hosted in the EU or the US, your choice
- Generated documentation held by us, never your source
- Managed generation, or point it at your own model provider
- Move to self-hosted at any time
Self-hosted
Air-gapped capableThe same stack inside your own network, for teams whose code cannot leave it.
- Nothing leaves your infrastructure
- Generation runs against a model endpoint in your own account
- Source read from GitHub, GitLab, Bitbucket or Azure DevOps
- Upgrade on your own schedule
Identity from your directory
Your identity provider decides what each agent can read.
Secrets scrubbed first
Keys, tokens and credentials are redacted before any source reaches a model.
Read-only on the endpoint
The client only reads. It cannot alter documentation or touch your source.
Hosted where you want it
EU or US on the managed service, or run the whole stack yourself.
Integrations
Fits the stack you already run
Documentation goes where your teams read it. Audit events go where your security team already looks.
Documentation
Read from what you already wrote, and publish generated documentation back into it.
- Confluence
- Jira
- Notion
Security and logging
Every agent read is sent to the tooling your team already watches.
- Datadog
- Elastic
- Grafana
All product names and logos are trademarks of their respective owners, shown to indicate compatibility.
Pricing
Choose a plan
Priced per machine. Everything running on it is included, however many agents that turns out to be.
Free
One machine, to try it properly on your own repositories.
Contact us- One machine
- Unlimited repositories documented
- Dependency graph and agent access
- Works with every supported tool
Team
The fleet console, the shared audit trail and single sign-on.
Contact us- Everything in Free
- Priced per machine, agents included
- Fleet console and shared audit trail
- Single sign-on and directory sync
- Access policy per repository
Enterprise
CustomFor organisations that need every access provable in their own systems.
Contact us- Everything in Team
- SIEM export
- Air-gapped deployment
- Security review support
A seat is one machine running the client: a laptop, a virtual machine or a build agent.
Contact us
Interested in a demo?
We will show you a live deployment in our own environment, how it is set up and what it produces.
- A live deploymentOur own environment, running real repositories. Not slides.
- An engineer on the callSomeone who built it, not a qualification script.
- Thirty minutesEnough to see how it works and whether it fits.
Or write to contact@qceptor.com.