We run it. We prove it. You build.
The developer experience, rebuilt around one idea: you review decisions; the platform does the work and writes down what it did. That's what easy to use means here.
Your services, placed and running
Every service placed on the European provider that suits it, inside one perimeter. Nothing leaves that perimeter without a recorded authorization.
Your app, actually run
Scaling, failures, updates, cost. Hosted is not the same as handled.
The questionnaire, already drafted
Audit-ready, literally: answers drawn from the running system, each citing its source. The ones about your own policies stay yours, and the draft says so.
Every answer opens
Click a claim and the record behind it opens: what ran, when, what it produced. Your buyer checks it themselves.
| Service | Placement | Replicas | Status |
|---|---|---|---|
| apighcr.io/hire-loop/api:4f1e3 | EUDE-FSN1Hetzner | 3/3 | Live |
| webghcr.io/hire-loop/web:2c90a | EUDE-FSN1Hetzner | 2/2 | Live |
| db-eu-central-01managed postgres 16 | EUFR-PAR1Scaleway | 1 + standby | Live |
| rank-modelmistral-small · open weights | EUFR-PAR2EU AI endpoint | on demand | Next |
Every drafted answer cites the record it came from. Questions about your own policies are marked as yours, never guessed at.
The parts, with the risk we see in each.
The stack, plainly: Kubernetes on Hetzner compute, managed Postgres on Scaleway, OCI images in, rolling deploys out, one EU perimeter. unhale runs on itself. Here's what each part is, and the risk we write down instead of talking past:
Multi-service deploys to managed EU clusters; our own product is the first workload. Risk: this layer alone is a commodity; it's the entry, never the edge.
What it costs, why it broke, what we did: operational honesty as the product surface. Risk: being transparent about providers we don't own means owning their failures in front of you.
Trust page, subprocessor register, residency history, backup attestations, review answers citing their source. Risk: some buyers still demand the branded certificate; we feed audits, we don't replace them.
Karpenter-class scaling on European iron: the piece the hyperscalers have and Europe doesn't. Risk: EU provider APIs weren't built for it; this is a research project, not a checkbox.
Sees logs, events and deploy history; explains failure in your words, fix drafted, read-only first. Risk: others sell this to experts; our bet is removing the expert, which is the harder promise.
Model calls routed to endpoints under European jurisdiction; open-weight models on EU iron where they're enough. Risk: the frontier models are mostly American, so we name the trade-off per workload instead of hiding it.
If you'd rather read code than adjectives: write to us and we'll talk shop. The risk register is the sales pitch.
What you pay, what we stand behind, and the questions you should ask.
Running is usage-based, with no seat licenses. Proving is one flat monthly price: never per questionnaire, never per deal. You can predict the bill before you deploy.
We answer for the infrastructure we run: where data lives, who touches it, what's encrypted, what's kept. Your own policies stay yours. Our evidence complements a formal audit; it does not replace one.
An EU region on a US provider keeps your data in Europe physically. The operator still answers to US law wherever the server sits (jurisdiction follows the company, not the datacenter), and your buyer's lawyer knows the difference. Our stack is European companies operating European infrastructure, so the answer holds.
Compliance tools collect claims about infrastructure they don't run, then chase you to keep them current. We are the infrastructure, so the record is a by-product of running your app, not a checklist beside it. For SOC 2 or ISO you still want an auditor; our evidence feeds that work.
Your services are containers on standard building blocks (Kubernetes, managed Postgres, object storage) on providers you could contract directly. Our billing units are ours, not theirs, so the bill stays portable and leaving is a migration, not a rewrite. We'd rather earn the staying.
We're early and carry no badge wall. unhale runs on itself, on Hetzner and Scaleway, and our own ISO 27001 path is on the roadmap; we publish where we are on it rather than implying we're further along.
Has a customer's security review ever slowed one of your deals?
Or is keeping production alive eating the hours you would rather spend on the product?
We haven't launched. This is the design-partner phase: what you tell us decides what gets built, and in which order.
A concrete offer: send us the last security review a buyer put in front of you. We'll map it question by question: which answers the platform would draft from the running system, and which stay yours. The map comes back to you, no pitch attached.