BUSFACTOR.TECH
The brutally honest engineering verdict

Your engineering org is a black box. We turn the lights on.

Every expensive problem in your org - the problems, the price, the fix.

Connects withGitHubGitLabBitbucketAzure DevOpsLinearSentryJiraSlackRead-only · self-serve · minutes to first verdict
Organization HealthYour org grades C
Closed, never merged31 PRs closed unmerged, paid for≈ €4.9k
Bus factor 1payments - one living maintainer1 owner
Idle AI seats6 seats idle 30 days, unused€114/mo
Paid twiceauth.ts re-fixed 7× in 30 days
Recovered 3 dormant AI seats closed - €57/mo back
Won cross-team dependency removed - one less silo
Fix first
  • Sweep the closed-unmerged 31 - decide early, cut the write-offs.
  • Second owner onto payments.
The whole read, in one screen

See what we’d find in yours.

The scoreboard, the money already sunk, the risk if you ignore it - every number with a receipt.

Every blind spot, priced or proven

Six truths you can’t see today.

Counted from your own repos - sunk money, hard risk, receipts. Live on your data in minutes.

review - 46% of every cycle
Delivery

Where the weeks actually die.

The stage eating your cycle time - named, with the slow PRs as receipts. Pickup, review, merge, deploy: we tell you which one is costing you the week, in hours.

≈ €4.9k
paid for 31 PRs that never merged · this quarter
at your assumptions ↗
Money

The work that shipped nowhere.

Closed-unmerged and stalled PRs - payroll demonstrably spent, delivered never. Counted from your repos, priced at your cost model.

IF the one owner leaves → ≈ €29k-€101k to rebuild
Risk

The invoice for ignoring it.

One-owner areas, the fire drill, and the rebuild bill if the owner walks - with the seconding plan, not just the scare.

Load-bearing
Riley Chenguess → reveal
carries 31% of all reviews
People

Who’s carrying it - and who’s drowning.

Load, coasting, judged overwork - guarded and receipt-backed. Never a shame board.

Not ready - yet
9 idle seats€171/mo cash
AI

Is the AI spend even landing?

Adoption, landing rate - and the paid seats nobody uses. Subscription cash, not vibes.

18%
14 PRs · the same 6 files · ≈ €2.9k twice-paid
Quality

You paid for this twice.

The same files fixed, re-fixed, and fixed again - rework counted from your own commits, with the second bill attached.

Free · no account · the file is never stored

Count the strangers who can publish into your build.

Drop a lockfile. Ten seconds later you have the packages a single account can ship straight into your next install, and how far each one reaches.

Drop one of these here

  • package-lock.json
  • pnpm-lock.yaml
  • go.mod
  • Cargo.lock
  • Gemfile.lock
  • composer.lock
Or paste it

Parsed in memory, then gone. There is no database column that could hold your file.

Real scana real package.json

5 of 18 dependencies can be published by a single account.

4accounts hold those rights
~2.1 billiondownloads a month ride on them
  • zod975M downloads/30done account can publish it
  • @types/react559.2Mone account (DefinitelyTyped)
  • @types/react-dom455.7Mthe same account
  • bcryptjs49.7Mone account
  • postgres48.7Mone account

Run 2026-07-29. None of those accounts are on that team’s payroll - and in 2024 one trusted maintainer account shipped a backdoor into xz (CVE-2024-3094).

The money facet, in detail

Watches the whole payroll.
Costs a rounding error of it.

1% recovered is the floor, not the promise - itemized on the right, receipts attached.

Do the math on your own org

€1.4Myour engineering + AI cost / yr
€35kof which, AI spend / yr
€14kwhat just 1% of it is worth / yr
300/moBusfactor Pro at €20/dev - €4k/yr
€330/moa typical rival seat, same headcount (~€22/dev)
3.8×paid for itself, if it recovers just 1%

Recover just 1% of that engineering + AI spend - a fraction of what the product itemizes - and it has paid for itself 3.8× over. 1% is the floor, not the promise. We don’t promise a percentage - we show you exactly where a much bigger one is leaking, receipts attached. You do the math.

Per seat, against the category: a comparable tool at this headcount (~€22/dev/mo - a published rate in this category, and the cheaper end of that vendor’s own list) runs €330/mo. Busfactor Pro is €20/dev/mo on annual billing, so the same team costs €300/mo - that’s €30/mo you keep. No seat cap, and every tier runs the same product.

Kill work that’s already dead

Zombie PRs and stale WIP - paid-for work rotting in a branch.

Fix the stage that eats lead time

Pickup, review, merge, or deploy - the real bottleneck named.

De-risk the one-person areas

Two people out, eight areas orphan. A pairing plan before it costs you.

Point the payroll at the roadmap

New vs improvements vs KTLO vs unplanned - judged against healthy ranges, priced.

Verify the AI line item

AI-assisted work tracked to merge. Renew the seats that land.

Everything it does

Get a firm grip on your engineering org.

Two dozen surfaces on one deterministic engine - browse the full feature catalog →

The real thing runs on your own repos, tickets, and incidents.

The scoreboard

Overview

The 60-second health read - one index, four judged sub-scores.

Findings & praise

Stories

Every finding is a card: the headline, both readings, the fix - praise gets its own.

Cycle time (typical)71h
Review wait (typical)40h
PR size (median)210 loc
Deploy frequency3.1/day
graded against expert bands - healthy · watch · bad
Judged stats

Metrics

Not a wall of numbers - each stat graded against expert bands: healthy, watch, or bad.

ind.
≈ elite < 25h - you’d sit in “good”
LinearB 2026 · published, not your peers ↗
silently sharpens to your peer cohort - never an empty state, never invented
The published bar

Industry benchmarks

Judged against published research - DORA, LinearB, GitClear - cited and honestly labeled “not your peers”, never invented. When enough orgs opt in, the same band silently sharpens to your anonymized peer cohort - never an empty “not enough peers” state.

Force-push detecteddeploy-web
2 commits vanishedquarantined ✓
history was rewritten - so your numbers didn’t lie
It flags its own dirt

Data honesty

Force-push detection quarantines the commits a rebase erased, canonical identity stops one human counting as four, and a stale sync says so - the tool that tells you when its own data is dirty.

MCPget_org_statsread-only
prs_merged644
review_coverage68%
cycle_p5071h
quoted from your resolvers · no LLM - it can’t hallucinate
Ask from any AI client

MCP server

Query your engineering data from Claude, Cursor, or any MCP client - and every number in the answer is quoted from your data, read-only. Busfactor runs no model of its own, so the tool can only hand over figures your data already contains. Your AI client still writes the sentence around them: safer by construction, not magic.

pickup 14%review 46%merge 12%deploy 28%
Cycle anatomy

Flow

Where the weeks go - pickup, review, merge, deploy, with the stage that eats lead time.

≈ 4-9 weekstypical-worst-case
the lever: review wait - 46% of delivery, speed it and the date pulls in
When does it land - and the lever

Delivery forecast

A completion range (p50-p90) quoted from your own weekly throughput - not a black-box Monte-Carlo - that ends in a door: the ONE delivery stage that, if you speed it up, pulls the date in. LinearB predicts a date; we predict a date and hand you the lever.

Checkout v2initiative
22 / 39 done
webapimobileon track ▲
one initiative, 3 teams · target Sep 30 - progress quoted, not the tracker’s %
One initiative, every team

Initiative tracking

Track a business initiative across teams - progress counted from your own linked tickets (never the tracker’s %), the teams involved, and an on-track-vs-target read from your real throughput. Drawn on the delivery trace - people lanes and typed waits - nobody else has.

One ticket, one axis

Trace

A single ticket across board, code, review, and deploy - the dead wait made visible.

Board hygiene

Tickets

Zombies, silent intake, and board-vs-git drift - the rot no standup surfaces.

APPstrained+43% mid-sprint
40 committed24 shipped16 carried
commit 40, ship 24, carry the rest - every sprint
Commitment vs reality

Sprint health

Commitment accuracy, carryover, and scope creep - per team, quoted with receipts. “You commit 40 points, finish 24, carry the rest - every sprint.” Team grain only: never a person velocity stack-rank.

PROJ-418webhook retries
reopened twice after Done - thrash, not progress
Running in circles

Ticket loops

Tickets that thrash instead of progressing - reopened after Done, or yo-yoing back to In Progress. Thrash, made visible.

For managers

PRs that struggled

Long open, many rounds, heavy comments, re-dos, a stalled wait - the PRs that fought their way in, receipt-backed, one click from the trace.

one person fields 31% of all reviews
The review network

Reviews

Who reviews whom - the hub everything routes through, the load no roadmap named.

DORA, honest

Deploy / DORA

The four keys - and an open admission of the one it can’t yet see.

Change failure · measureddeploys × incidents
Change fail60%measured
Restore p504.2hmeasured
3 of 5 deploys triggered an incident within 2h
Proxy → measured

Measured reliability

When you connect an incident source, change-failure-rate and time-to-restore stop being a proxy and become measured: each deploy correlated to the incidents it triggered. “3 of your last 5 deploys triggered a Sentry spike within 2h” - the canonical DORA definition, with the failed deploys as receipts.

new 40%improvements 16%ktlo 34%unplanned 10%
KTLO 34% - over its 30% healthy ceiling. Priced in your currency.
Where the payroll went

Investment

New vs improvements vs KTLO vs unplanned - judged against healthy ranges, priced.

Engineering StandupDaily · 6 people · 30 min
€38,330a year767 h
13%of the working week
4.1 hper person, weekly
titles never stored · the verdict is on the meeting
The standing meeting, priced

Meeting cost

Paste a calendar address and every recurring meeting is priced at your loaded cost, annualised: a daily 30-minute standup with 6 people is 767 hours and €38,330 a year. Times, durations and attendee counts only, never titles, and the verdict lands on the meeting, never the person.

•••••• out•••••• outguess → reveal
paymentsauthwebsearchinfraapi
2 out → 2 areas dark≈ €18k-€56k
We price the counterfactual

Consequences & Fire Drill

The invoice for ignoring your bus factor. Pick who’s out - or let the engine pick worst-case - watch the areas orphan, and walk away with the handover checklist. Run the drill before life runs it for you.

paymentswebcritical
F2 no warm startF3 driftF4 correlatedF5 systemic
one bad Tuesday from an orphan≈ €22k-€90k
Door: second an owner, this sprint.
Attrition tools score people. We refuse.

Continuity Watch

The early-warning that watches your org’s continuity - at the only safe grain, the AREA. Each solo-owned area carries a disclosed risk tier, every input quoted, and a priced replacement range. Never a flight-risk score, never a name on a risk card. The fix arrives before the bad Tuesday does.

Reclaim 9 idle AI seats
€171/mo back
every month · fix ≈ 1h, cancel the seats idle 30 days
at your assumptions ↗
Every fix has a payback

Fix-it ROI

Every recommendation carries a payback period - fix cost ÷ the monthly drain it addresses. “Clean the branch necropolis: ≈ 4h, payback ≈ 4 days.” The read becomes a capital-allocation memo your CFO will sign. Numbers quoted, assumptions disclosed and editable.

Recovered · measured≈ 46h est €2.4k
measured vs your own 12-week baseline - never a relabeled sunk cost ↗
Recovery, only ever measured

Measured recovery

The one recovered-money number that isn’t a relabeled sunk cost: waste-rate reduction vs your own baseline and recurring spend you verifiably stopped paying - symmetric, so a worse week subtracts. Hours first, an est € second, never a fabricated win.

18%
redo rate - the same files, again
Rework & regressions

Quality

The same files breaking, fixed, and breaking again - rework rate, with receipts.

Bronzebilling-svc49tests 0%no docs
Silverapi-gateway72+8 to Gold
Goldweb-app91no gaps ✓
worst-first · the exact gaps to level up
Bronze · Silver · Gold, per repo

Repo readiness

A readiness grade for every repository, worst-first - review-covered, tested, documented, shipping small - with the exact judged-stat gaps to level up. The Cortex/OpsLevel scorecard, computed from your git and review history, zero manual rubric. A grade on a repo, never on a person.

Not ready - yet
6 absorption sub-factors, judged
Readiness, not adoption

AI

A verdict on whether your org can absorb AI volume - six sub-factors, judged.

12% measured·est. 12-31%EST
measured floor quoted · band is an estimate, not a measurement ↗
The disclosed estimate

Estimated AI share

Trailers and bots only see AI that signs its work. Beyond that measured floor, a heuristic estimate bands your likely AI-assisted share from commit shape - always EST-labeled, “an estimate, not a measurement”, with the low bound pinned to the quoted floor so it can never contradict the fact. Org grain only, never a person.

Toolvs baselinerework
Claude Code▲ 18% faster0.20×
GitHub Copilotn=8below floor-
Cursor▼ 9% slower1.6×
Baseline20.0h · 180 ln0.15
per tool, judged against the baseline - quoted, never a person ↗
Per-tool, judged

AI tool comparison

Not just “how much AI” - which tool. Each tool’s merged-PR cohort compared to the baseline on cycle, review latency, size, and rework; the share of PRs an AI bot reviewed; and the depth-1 areas where AI churn concentrates. Below the sample floor a tool states n=X and gets no verdict - quoted, never guessed, never per person.

$1.2k/ mo measuredUSD · unconverted
claude-opus$740
claude-sonnet$460
12 ghost seatsdeclared 40 · 12 emitted zero telemetry
measured via OTLP · “silent in telemetry” ≠ unused
Measured, not declared

Measured AI cost

Real AI token and seat spend, summed from OpenTelemetry (OTLP) the tool emits natively - no vendor admin token - with per-model cost and ghost-seat detection: “declared 40 seats · 12 emitted zero telemetry.” Cost in USD, unconverted; “silent in telemetry” is a count, never a claim you’re wasting money.

payments - bus factor 1
Bus factor

Knowledge

The ownership map, colored by risk - the quiet single point of failure before it walks.

The map vs the road

Documentation health

Which active areas have no doc at all, which docs went stale over moving code - and whether your repos are wired for AI agents. Dated, linked, judged.

one module touches 62% of the import graph
Coupling

Codebase Map

The import graph’s hub - the one module everything leans on, and the SPOF it hides.

Load-bearing
Riley Chenguess → reveal
carries 31% of all reviews
Guarded scorecards

People

Who’s load-bearing, who’s drowning - receipt-backed, name blurred, never a shame board.

68/ 100DevEx health▲ +4 vs last round
anonymous · aggregated only · N = 14
The signal git can’t see

DevEx surveys

Anonymous developer-experience surveys → a DevEx health score, per-dimension breakdown, and a trend, sitting beside the objective signals. Your own questions; responses carry no identity by construction, so a low score is a system to fix, never a person to blame.

guess → revealprotect
sole owner of payments · 63%carried 22% of reviews
cost of losing them≈ €35k-€137k
Org-average basis - not their salary.
Protect first

Person & team scorecards

An honest profile of every person and team - strengths, what breaks if they vanish, and what LOSING them costs (a disclosed org-average range, never their salary). Retention direction, with the receipts under every line.

1Yuki Tanaka0.870
2Priya Sharmafuzzy · 9 of 300.640
3Marcus Webb0.410
Who is carrying this codebase

Standing

Your engineers, ordered on delivery, review, knowledge topology and momentum - and every position opens the receipts that built it, down to the pull requests. Turn a component off and the order recomputes in front of you. A thin sample is labelled fuzzy, and unmatched identities come with the link to fix them.

Riley Chenweek 29
Mon
merged api#4822 reviews
Tue
merged web#301
Thu
merged web#318+3 more
what actually shipped - receipts, not recollection
What shipped

Work log

Every merge and review, per person and day - the standup answer with receipts instead of recollection.

Who is who

Directory

Tenure, expertise, and what each person owns - the org chart that actually knows who could be paged at 2am.

web → mob reviews run one way - 12×
Cross-team

Dependency map

Which team depends on which - the one-way review streets and shared-ownership areas, each a question with receipts, never a verdict on a team.

judged vs the expert bar - no rank, no team score
Team scoreboard

Team compare

Every team’s flow, review, quality, and sustainability - judged against the expert bar, never against each other. No rank, no team score.

Positive-only

Team streaks

The good weeks, stacking up - a team on a run of ≥3 healthy weeks on one stat earns a receipt-backed badge. A quiet week pauses it; only a judged off-week ends it. Earned awards, never a team-vs-team race.

Today’s movers
“small PRs” agreement climbed back to Aimproved
review wait crossed 24hworsened
api#482 - the day’s liveliest PR, 9 roundstoday
Never stale

Daily Pulse

Where you stand today, plus what moved since yesterday - the top problems persist, the movers refresh daily, so it’s never the same stale list.

2026-Q3Report CardB+ up from C+
graded at quarter close - timed to renewal
Your quarter, graded

Quarterly Report Card

Every quarter closes with a letter-graded report card - overall and eight organ sub-grades, a delta narrative vs last quarter, the money recovered, and one move for next. A graded season review, timed to renewal.

CTO Weekly Brief2026-W29B · ▲ +2 since Mon
ranked by consequence · receipts on every line
What needs YOUR attention

CTO Weekly Brief

One page a week: where the org stands entering the week, then the problems ranked by consequence - priced where the cost of inaction is computable, each with a why-it-ranked tag and a door - plus what improved. When a section is empty it says so; it never manufactures filler.

Finance-grade

Exports your CFO will accept

Deterministic CSV/JSON with an audit-grade CapEx split - rule-version and run-id stamped on every figure.

CapEx restatementIAS 38
v1FY2025 policy€221k
v2Post-acq policyΔ +€49k€270k
KTLO moved OpEx → CapEx - the one rule that changed
finance@1/v2byte-identical ✓labels, not tax advice
Audit-grade, IAS 38 framed

CapEx policy versioning

Version your software-capitalization policy and restate prior periods on a policy change or acquisition - deterministically. See the same period under each version, the Δ, and the exact bucket rule that moved, framed to IAS 38 / ASC 350-40 (a label, not tax advice). Byte-identical on every re-run - that reproducibility is the audit value.

By personcapex-grain@1
A. Sokolova12 PRs141h58% CapEx
B. Lindqvist3 PRs141hshare withheld
billing#4471 Add invoice retry queue2026-06-14 · Billing rewrite · CapEx · 11.8h · ticket_type
ties to the totals ✓every hour lands on one name
Sampled by an auditor

Who did what, on which project

Your capitalisation pack opens by person and by project, down to the individual pull requests - merge date, link, and the rule that classified each one. Every row reconciles to the bucket totals exactly, and unattributed work gets its own line instead of being spread across people who did not do it.

Work agreements

Targets, graded every week

Set a team target - small PRs, fast reviews - and the engine grades it automatically, every week, with receipts.

the regulars - Tue-Thu, 22:00-02:00
Work rhythm

The regulars

When work really happens - late-night streaks and weekend spikes read as a system signal, never a scorecard.

Shareable

Badges worth screenshotting

Earned, not awarded - achievement badges and share cards that make the good weeks travel.

busfactor.tech/share/7fQ2xk…COPY
████████as of 12 Apr
Review is where the week goes
██████ ████carried 62% of it
Unlisted · defaultPublic · admin opt-in
names blurred in both modes · expiry and revoke on every link
Send the read, not the names

Share links

One finding, one scorecard, or the whole scoreboard on an unguessable link your board opens without an account. Unlisted by default, public only if an admin opts in, with an expiry and a revoke on every link. Person names are blurred in both modes, enforced in the one resolver that can build a shared page at all - so there is no real name in the payload to reveal.

FREE SCANpnpm-lock.yaml
78of 432 have one publisher
116 of 150traced to their repository
34 refusednamed, with the reason for each
the file is parsed and discarded, never stored
Free, no account

Dependency risk scan

Drop in a lockfile and see which of your dependencies are one pair of hands. 19 manifest formats, 8 registries, every package traced to the repository that produces it - and the ones we cannot trace are named with the reason rather than quietly dropped. Your file is parsed and discarded, never stored. Then ask the harder question about the code you did write.

PUBLIC REPORTzloirock/core-js
9.4person-years nobody invoiced
13 yearsof somebody showing up
1 personcan land a change here
read from the public record only · credited, never ranked
We do it to strangers first

Open-source reports

Public fragility reports on projects the internet runs on, read from nothing but the public git history. On core-js: 9.4 person-years of engineering nobody invoiced, and one person who can land a change. Maintainers are credited by name, figures the engine cannot support are refused out loud, and every page carries a right of reply. It has never had access to those repos. Ask what it says about yours.

9.4 person-years unpaidbus factor 113 years maintained
[![…](https://busfactor.tech/oss/…/badge/unpaid.svg)](…)COPY
Only the badges the repo earned · every snippet links home
The maintainer picks the badge

README badge

Every report earns a shelf of badges, and only the ones the numbers support - a metric the engine refused simply has no badge. Take the slim chip for the badge gutter or the big framed card for the top of the README. The maintainer picks the one worth showing off and pastes a single line. Choosing is the consent, and the badge links back to the report that explains it.

Copy linkCopy cardPost
busfactor.tech/oss/…9.4 person-years nobody invoiced
13 years maintained the maintainer’s badge links back to the report
The read travels on its own

Share bar & badge loop

Copy the link, copy the card image, or post the read in one click - and the post carries the page’s own headline, not a marketing line. Beside it sits the maintainer’s door: pick a badge, paste one line.

npx busfactor ringsRing one month, width from churnKnot a long branch, absorbedScar a revert-heavy month
Free tool, runs offline

Rings

One command on any repository, and it cuts open like a tree: a printable cross-section of the whole life of the code, one ring per month. It reads commit metadata and never opens a source file, so it runs offline inside your own network. Same repository, same cut, every time.

See the full feature catalogEvery surface - Directory, work log, watchdogs and more - described in detail, with real product screenshots.
How the read gets made

From raw signal to a verdict you can act on.

Three stages. The signal you already generate, refined into a priced, receipt-backed read - with the fix on the end.

  1. 01

    Signals + receipts

    Every PR, review and ticket, measured. No guessing, no LLM in the path.

  2. 02

    Judged vs the world

    Scored against expert and peer bands.

  3. 03

    The read, and the fix

    Findings priced, risk named, every one ending in a door.

That’s why you can take it to a board: every number carries its receipt, and every problem arrives with the fix.

The part nobody else dares ship

People intel,
without the revolt.

Who’s load-bearing, who’s overloaded - answered with receipts, wrapped in guardrails your engineers won’t revolt against.

And the one every founder feels but can’t answer: which two or three people, if they walked, would orphan half your codebase? We show you where the knowledge is concentrated - and hand you the plan to spread it. Every name comes with the pull requests that put it there.

Receipts before rhetoric

No claim about anyone lands without the PRs behind it - two readings, a stance you can check.

Praise is half the product

Good work is surfaced with the same machinery as problems. The tool credits people.

No ranked leaderboards. Ever.

No stack rank to weaponize. Consequence framing: what breaks, what orphans, what it costs.

A blur toggle on every surface

Anonymize names org-wide or per view; anything shared is always blurred.

Minutes, not a rollout project

Connect three tools. Get the verdict.

01

Connect, read-only

Paste a read-scoped token for your code host, then Linear and Sentry. No CSVs, no data team.

02

The engine reads everything

Deterministic metrics over PRs, reviews, issues, and deploys.

03

The verdict lands in minutes

The two things that matter, the receipts, and the fix.

Pricing

One price. Everything included.

One subscription, priced per active engineer. No capacity tiers, no repo quotas, and nothing behind a paywall - not even your history.

Annual billing saves 33%. Cancel any time; you keep the period you paid for.

No card
Trial

For the engineering lead who wants the read on their own repos before anyone signs anything.

Free

14 days, no card, no demo call.

  • The whole product on your real repositories, not a sandbox.
  • Your first finding before the analysis finishes.
  • Nothing to cancel, because there is nothing to enter.
Start the trial
Active engineers only
Pro

For the CTO who needs the same read every week, with receipts a board will accept.

€20/ active engineer / month

You pay for engineers who actually contributed in the window. Dormant seats cost nothing.

  • Every repo, near-live. Nothing metered, nothing throttled.
  • Deterministic and LLM-free: your code is never sent to a model.
  • Full history, back to the first commit. Never capped by calendar.
  • Not per seat, not per repo, not per feature. One price, everything in it.
  • Every number links to the commit, PR or review behind it.
  • An immutable period close, so last quarter cannot be rewritten.
Start the trial
Runs on your hardware
On-Prem Full Audit

For the org whose code cannot leave the building, and who needs one answer this quarter.

from €4,000

One-off engagement.

  • The full €4,000 credits against your first year of Pro.
  • Air-gapped on your own infrastructure. Your code never leaves your network.
  • Unlimited developers, repos, projects and teams.
  • Deterministic and LLM-free, benchmarked against the open-source corpus.
Talk to us
Your perimeter
Enterprise

For the org that has to run it themselves, under their own security review.

Talk to us
  • Everything in Pro, plus:
  • Self-hosted or air-gapped, inside your own network.
  • Deterministic and LLM-free, so nothing leaves your perimeter.
  • A security review with real answers: the control set and a data-flow walkthrough.
Talk to us

Founding customers get 20% off, on top of annual, locked for life - €16 per active engineer, per month. It compounds with annual billing rather than replacing it. See what is included.

We hold no security certification today. SOC 2 and ISO 27001 are on the roadmap and not started, and we would rather you know that now than three calls in.

Straight answers

The questions you were about to ask.

“Isn’t this surveillance?”

No leaderboards, receipts required, praise built in - anything shared is blurred.

“Is the AI making numbers up?”

It can’t - a zero-LLM metric path, byte-identical on every rerun. Plenty of tools put a model in the scoring path, or rank people. We do neither.

“Another dashboard nobody opens?”

No - the verdict comes to you: two things that matter, priced, with the fix.

“We already have a metrics tool.”

Dashboards show. Busfactor judges - a stance, a fix, flat fee. Run both a month.

Turn the lights on.

Connect in minutes. First verdict before your next standup - every blind spot lit, priced, and fixable.

Busfactor - The Brutally Honest Engineering Verdict