BUSFACTOR.TECH
The full catalog

Everything Busfactor does.

81 features, one promise: the truth about your engineering org - judged, priced, fixable.

Connects withGitHubGitLabBitbucketAzure DevOpsLinearSentryJiraSlackRead-only · self-serve · minutes to first verdict
The assessment7Delivery & flow12Code health4Knowledge & risk4Reviews2People, guarded9Teams4AI5Money10Meetings6Always on7Data honesty5Free tools2Share & open source4
The assessment

Not a dashboard. A verdict.

Sixty seconds to the two things that matter - judged, priced, linked.

ind.
≈ elite < 25h - you’d sit in “good”
LinearB 2026 · published, not your peers ↗
silently sharpens to your peer cohort - never an empty state, never invented

Industry benchmark reference bands

The published bar, beside your own number.

  • LinearB 2026, DORA 2024, GitClear, DX, METR
  • Labeled “industry reference - not your peers”
How it works
  • A static, versioned, cited dataset - config, never fetched at runtime, so the figures render byte-identically.
  • Drawn as a neutral reference line on the metric it maps to, never in a good/watch/bad verdict color.
  • An ≈ marks every band whose definition differs from ours.
  • The published band is always the comparison. An opt-in cross-org pool can only SILENTLY UPGRADE the label to “your peer cohort (N orgs)” - it can never downgrade a judged surface to an empty state.
  • That pool is default off, stores an opaque contributor hash with no org identity and no person data, and computes a deterministic percentile.
Busfactor Overview: organization health and sub-scores
Real product screenshot - names anonymized.
Delivery & flow

See where the weeks actually die.

From “it feels slow” to the exact stage, the exact wait, the exact PRs.

Checkout v2initiative
22 / 39 done
webapimobileon track ▲
one initiative, 3 teams · target Sep 30 - progress quoted, not the tracker’s %

Initiative tracking

One business initiative across every team, progress counted from your own linked tickets.

  • On-track or at-risk from your real throughput, never the tracker’s %
How it works
  • Read-only ingestion of Linear projects, initiatives and their nesting.
  • Progress = linked tickets by state category, with canceled excluded from the denominator.
  • Forecast versus target reuses the SAME shipped forecast engine the delivery page quotes.
  • Too few linked items shows counts only; no target date abstains from the on-track verdict rather than inventing an ETA.
  • No effort €: we ingest no person-hours source, and wall-clock span would overstate the cost, so it quotes activity receipts instead.

Roadmap ledger

What your tracker calls in flight, checked against what your git history says moved.

“Your tracker says 31 projects are in flight. 12 moved in the last 60 days. 8 have no work attached at all.”

  • Projects and initiatives, one definition of quiet
  • The review agenda, on your clipboard

Instead ofA stale-initiative filter that leaves the conclusion to you.

Delivery → Roadmap Ledger

How it works
  • Quiet = nothing in a project or initiative moved for N days: no ticket transition, no pull request opened or merged.
  • Scope is the same linked-ticket set the initiative rollup counts, so the two surfaces can never quote different numbers.
  • A project nobody ever attached work to is counted neither dead nor alive - it is listed separately, with the door to link it.
  • The window, which states mean in-flight, and your own state vocabulary are org settings, not our assumptions.
  • The verdict lands on the project and on how the org closes things. No row names a person, and nothing here claims the work was wasted.
≈ 4-9 weekstypical-worst-case
quoted from your own weeks · nearest-rank, no simulation ↗

Delivery forecast

A p50-p90 range from your own throughput, and the lever that pulls the date in.

  • Nearest-rank percentiles, no Monte-Carlo, no seed

Instead ofA black-box “87% confident by the 14th” you cannot audit.

How it works
  • Percentiles over your trailing weekly throughput buckets - the same series the Stats page draws.
  • Scope changes are quoted BESIDE the range, never folded into the math.
  • The lever is the dominant cycle-anatomy stage, quoted from the same engine, at org grain so it is the pipeline you fix.
  • Same weeks in, same range and same lever out.
PROJ-418webhook retries
reopened twice after Done - thrash, not progress

Ticket loops

Tickets that thrash instead of progressing: reopened after Done, or yo-yoing back.

How it works
  • A deterministic replay of each ticket’s status history - zero new ingestion.
  • Reopen = Done to a non-terminal state. Backslide = in-progress to not-started.
  • The fork stays honest: some are real rolling containers. The card asks whether anyone decided that.
APPstrained+43% mid-sprint
40 committed24 shipped16 carried
commit 40, ship 24, carry the rest - every sprint

Sprint / cycle health

What a team committed against what it shipped, with the carryover and the scope creep.

“APP commits 40 points, ships 24, carries the rest - and adds 43% more mid-flight.”

  • Team grain only, never a person velocity rank
How it works
  • Start-of-cycle membership is reconstructed by folding your tracker’s own scope-change history in time order - no new ingestion.
  • Anything first added after start is scope creep, not commitment.
  • Below a minimum ended-cycle and committed-item sample a team reads below-sample, with no verdict; a team with no cycles never appears.
  • Same cycles in, byte-identical verdict out.

PRs that struggled

The PRs that fought their way in, ranked, one click from where they stuck.

  • Long open, many rounds, heavy threads, re-dos, a stalled wait

Instead of“Review time is up 20%” with no idea which PRs, or why.

How it works
  • Five deterministic signals, each judged against your own org’s recent percentiles rather than a number pulled from nowhere.
  • Two firing together - or one wildly over - puts a PR on the list.
  • The verdict is on the system: unclear scope, an oversized diff, a reviewer pool of one. Never on whoever wrote it.
Change failure · measureddeploys × incidents
Change fail60%measured
Restore p504.2hmeasured
3 of 5 deploys triggered an incident within 2h

Measured reliability

Connect an incident source and change-failure-rate stops being a proxy.

“3 of your last 5 deploys triggered a Sentry spike within 2h.”

  • The canonical DORA definition of CFR, and time-to-restore, measured
How it works
  • A normalized incident store - Sentry today, PagerDuty and Datadog extensible with no migration.
  • Each incident attributes to the single latest deploy inside your window: default 2h, org-editable over the settings write path.
  • CFR = distinct failed deploys ÷ deploys in window. MTTR is a nearest-rank p50.
  • Min-sample guards on both, and with no incident source connected the surface stays honestly on the proxy.
  • Org grain, never a person. Same deploys and incidents in, byte-identical out.
Busfactor Flow: cycle time anatomy by stage
Real product screenshot - names anonymized.
Code health

What keeps breaking - and whether it is getting better.

Rework judged fairly: polishing in flight is healthy, delivered-then-broken is not.

18%
redo rate - the same files, again
Bronzebilling-svc49tests 0%no docs
Silverapi-gateway72+8 to Gold
Goldweb-app91no gaps ✓
worst-first · the exact gaps to level up

Repo readiness board

Bronze, Silver or Gold for every repository, worst first, with the gaps to close.

“Reach Bronze by: add a second reviewer to these three PRs, add tests to billing-svc.”

  • Zero manual rubric
  • A grade on a repo, never on a person
How it works
  • The grade is a weighted average of REAL judged stat scores, computed from each repo’s own rows - a self-merged repo stays low beside a fully-reviewed sibling.
  • Below the sample floor, or with too few judgeable signals, a repo is UNGRADED with the reason - never a fabricated grade.
  • The cuts, the stat set and the weights are org config over the same settings write path.
  • Zero person ids on the surface: receipts are PR number, title and commit sha.
every merge waits38 min
38 min×1,240 runs/mo=785 h
× your loaded cost≈ €51k/mo

Tests & CI burn

Test presence where it matters, and every CI minute priced in your currency.

Busfactor Code Quality: hotspots, regressions and rework
Real product screenshot - names anonymized.
Knowledge & risk

See who you cannot afford to lose.

The literal bus factor - measured, mapped, and priced in consequences.

2 people out → 8 areas orphan. Here is which.

Documentation health

The written map against where the traffic actually is.

  • The undocumented active areas, named
  • AI-context coverage
How it works
  • One deterministic pass over commit history: presence plus git touch-dates per area, never prose quality.
  • Judged against the same size-band bar the AI-readiness Documentation factor quotes.
Busfactor Knowledge: ownership treemap colored by bus-factor
Real product screenshot - names anonymized.
Reviews

The review queue, X-rayed.

Who carries the queue, which areas have no second reviewer, what the friction is.

one person fields 31% of all reviews
Busfactor Reviews: review network, load and friction
Real product screenshot - names anonymized.
People, guarded

People answers, without the revolt.

The calls you are paid to get right, in guardrails engineers will not sabotage.

Load-bearing
Riley Chenguess → reveal
carries 31% of all reviews
guess → revealprotect
sole owner of payments · 63%carried 22% of reviews
cost of losing them≈ €35k-€137k
Org-average basis - not their salary.

Person & team scorecards

Every person and team: strengths, what breaks if they vanish, what losing them costs.

  • A disclosed org-average range, never their salary
  • Praise is half of it

Instead ofAttrition tools that hand you a ready-made cut list and call it insight.

How it works
  • Every number is a quoted stored fact or a disclosed range - no generated grade anywhere.
  • The firewall is in the compiler: one subject per card, no sortable column, no compare view.
  • Cost of loss is a {low, high} range computed at render on an org-average basis - per-person salary is never read, never persisted, never exported.
  • Growth areas are double-edged questions with a door, capped and uncountable. Exempt people carry no growth and no price.
  • We price losing your people, never keeping them.
1Yuki Tanaka0.870
2Priya Sharmafuzzy · 9 of 300.640
3Marcus Webb0.410

Standing

Who is carrying this codebase, ordered - with the receipts behind every position.

A staff engineer sitting third on delivery and first on knowledge topology is a fact you act on, not an opinion you argue with.

  • Seven components, each one a switch
  • Every position opens its pull requests

Instead ofA velocity leaderboard built from a number nobody can trace back to a pull request.

How it works
  • Delivery, review participation, knowledge topology, momentum, breadth, lifetime volume and tenure - each weighted, each switchable, and the arithmetic printed under every profile.
  • Switch a component off and the order recomputes against the remaining weights - and the page quotes how far the typical person actually moved.
  • A thin sample is labelled fuzzy with the count and stays out of the distribution, so it never moves anybody else - and where too few clear the floor to form one, the page says so.
  • Unmatched identities are flagged with the link to fix them, and unattributed work is never spread across people who did not do it.
68/ 100DevEx health▲ +4 vs last round
anonymous · aggregated only · N = 14

DevEx surveys

The signal git cannot see: anonymous developer experience, scored beside the objective numbers.

“Merge-wait p50 is 40h” AND “review is the thing we dread” - two hands, one finger.

  • Engineers answer with no account
  • N and response rate disclosed
How it works
  • A round mints one anonymous in-app link you paste wherever your team already talks.
  • Anonymity is structural, not a promise: the response table has no person, user or identity column and no join path to one, so even a full dump cannot attribute an answer.
  • Open-ended quotes stay hidden until enough responses clear a de-anonymization floor.
  • Every score is a mean of real responses, byte-identical for the same rows; too few answers is labeled low-confidence, never asserted.
the regulars - Tue-Thu, 22:00-02:00

Work rhythm

The punchcard: after-hours and weekend creep, visible before it becomes a resignation letter.

Instead ofNobody notices the after-hours pattern until someone burns out.

The guardrails

Every judgement about a person opens the receipts that produced it.

  • A position is a standing inside your own distribution, never a bar we invented
  • A thin sample is labelled, not hidden - and never moves anybody else
  • Exempt people leave every ordering, and their name never renders
  • Everything leaving your org is blurred. Inside it, people are named.
Busfactor People: guarded per-person insight
Real product screenshot - names anonymized.
Teams

How the teams actually depend on each other.

Cross-team hand-offs, judged against the bar - never against each other.

web → mob reviews run one way - 12×

Cross-team dependency map

A team-by-team review-flow matrix, the shared areas, and who files work into whose queue.

  • One-way review streets
  • Single-bridge risks

Instead ofAn org chart that shows who reports to whom, never who is blocking whom.

How it works
  • A deterministic team resolver layers manual overrides, ticket-assignment teams, then co-work inference.
  • Every risky hand-off reads two ways - a deliberate guardrail, or a bottleneck - so it stays a question with receipts, never a verdict on a team.
  • Native teams come from your Linear team keys today.
judged vs the expert bar - no rank, no team score

Team scoreboard

Flow, review, quality and sustainability per team - judged against the bar, never each other.

  • Zero person ids - receipts are PRs and commits
  • Below sample a cell reads n=X, never a grade

Team streaks

Three healthy weeks on one stat earns a team a badge: bronze, silver, gold.

  • Positive-only, by construction
  • No anti-streak, ever
How it works
  • Composed from the shipped team scoreboard over trailing ISO weeks: each week re-uses the SAME judged cell, so a streak can never contradict the grid.
  • A quiet (below-sample) week pauses a streak, disclosed as a count. Only a judged off-week ends it.
  • No team-versus-team leaderboard beyond the length sort of earned awards.
AI

Is the AI spend landing?

Deterministic attribution and a readiness verdict - not another adoption chart.

Not ready - yet
6 absorption sub-factors, judged
Toolvs baselinerework
Claude Code▲ 18% faster0.20×
GitHub Copilotn=8below floor-
Cursor▼ 9% slower1.6×
Baseline20.0h · 180 ln0.15
per tool, judged against the baseline - quoted, never a person ↗

Per-tool AI comparison

Not just how much AI. Which tool.

  • Cycle, review latency, size, rework per tool
  • Below the floor: n=X and no verdict

Instead ofA blended “AI %” that hides which tool you are paying twice for.

12% measured·est. 12-31%EST
measured floor quoted · band is an estimate, not a measurement ↗

Estimated AI share

Above the measured floor, an opt-in heuristic bands your likely AI share.

  • Always EST-labeled: an estimate, not a measurement
  • Org and team grain only, never a person
How it works
  • The shape signals are session co-occurrence, burst cadence, big-diff percentile and template-shaped messages.
  • Because the low bound is the measured floor, the estimate can never contradict the quoted number.
  • Versioned weights, default off, and never on a shared card.
$1.2k/ mo measuredUSD · unconverted
claude-opus$740
claude-sonnet$460
12 ghost seatsdeclared 40 · 12 emitted zero telemetry
measured via OTLP · “silent in telemetry” ≠ unused

Measured AI cost

Real token and seat spend, summed from the OpenTelemetry your tools already emit.

  • No vendor admin API token needed
  • Power users named as praise

Instead ofA per-seat AI bill you pay in the dark.

How it works
  • The customer points their tool’s OTLP exporter at a per-org endpoint secured by a machine ingest token, managed in Settings and the CLI, never the user session.
  • Tokens and cost are SUMS of the tool’s own data points: cumulative series collapse to max, deltas sum, nothing double-counts.
  • No FX: running vendor-published USD through your org currency would be a generated number.
  • “Emitted zero telemetry” is not “unused” - an exporter may simply not be configured on every seat.
Busfactor AI: attribution, impact and readiness verdict
Real product screenshot - names anonymized.
Money

The payroll, itemized.

Your biggest line item, with the scrutiny your AWS bill already gets.

new 40%improvements 16%ktlo 34%unplanned 10%
KTLO 34% - over its 30% healthy ceiling. Priced in your currency.
•••••• out•••••• outguess → reveal
paymentsauthwebsearchinfraapi
2 out → 2 areas dark≈ €18k-€56k

Consequence Engine + Bus-Factor Fire Drill

Everyone charts the present. We price the counterfactual: what leaving it unfixed costs.

  • Fire Drill: pick who is out, watch the areas orphan
  • A handover checklist per area

Instead ofA bus-factor number that names the risk but never the invoice.

How it works
  • A deterministic what-if layer over signals you already have - no new metric.
  • The shape is always IF this stays unfixed → your quoted quantities → a low-high range.
  • Ranges come from three disclosed methods only: a knob range, your trailing 8-week rate, or a labeled bound-pair. Never a probability-weighted forecast.
  • A shrinking problem renders as praise, never a scare card.
  • The drill reuses the shipped bus-factor cover rule verbatim, so it can never disagree with your knowledge map.
  • Person-touching cards and the drill are leadership-gated; anything shared carries counts and area names, never a person.
paymentswebcritical
F2 no warm startF3 driftF4 correlatedF5 systemic
one bad Tuesday from an orphan≈ €22k-€90k
Door: second an owner, this sprint.

Continuity Watch

Attrition tools score people. We watch continuity at the only safe grain: the area.

  • A priced replacement range
  • Risk that shrinks renders as praise

Instead ofA flight-risk score on a named person that you could never show anyone.

How it works
  • Person-free by construction, stricter than the Fire Drill: the view-model type has no person field, so a name cannot leak because there is nowhere to put one.
  • The correlated-exposure factor carries a count - “shares its owner with 2 other areas” - never who.
  • It composes shipped signals only: bus-factor ownership, fallback-reviewer coverage, area momentum, systemic SPOF, org after-hours pressure. No new metric, no probability, no prediction language.
  • The replacement range uses your org-average loaded cost, disclosed and never summed.
  • Leadership-gated; share and export carry counts, area names and tiers.
Reclaim 9 idle AI seats
€171/mo back
every month · fix ≈ 1h, cancel the seats idle 30 days
at your assumptions ↗

Fix-it ROI

Money Drain prices the leak. This prices the fix, and the payback.

  • A best-payback-first fix queue on the Overview
  • No priceable drain, no payback
How it works
  • The effort catalog is org-editable and deliberately conservative-high.
  • Pure arithmetic over quoted inputs. Rounding is always up, so the quoted payback under-promises.
  • Drain attribution is the single largest line, never a sum.
  • Past twelve months it reads “do it for the hygiene, not the ROI”.
  • Every figure routes through your cost model’s currency; nothing is hardcoded.
Recovered · measured≈ 46h est €2.4k
measured vs your own 12-week baseline - never a relabeled sunk cost ↗

Measured recovery

The honest count of what you got back, against your own baseline, debits included.

  • A worse week debits on the same formula
  • Hours lead, the € is est-labeled

Instead ofROI dashboards that book the money you already sank as “recovered”.

How it works
  • A relabeled sunk cost is never booked as recovery: money you already spent is spent.
  • The weekly trend is retro-computable from your own PR history against a pooled 12-week baseline, credited once per calendar ISO week and frozen the moment it mints.
  • Below a baseline-eligibility floor it stays silent - “your baseline is still accruing” - rather than minting from noise.
  • A vendor-causation claim needs an explicit “we acted on this” marker with a dated before-and-after. Unattributed improvement still shows, as your rate falling, never as our win.
By personcapex-grain@1
A. Sokolova12 PRs141h58% CapEx
B. Lindqvist3 PRs141hshare withheld
billing#4471 Add invoice retry queue2026-06-14 · Billing rewrite · CapEx · 11.8h · ticket_type
ties to the totals ✓every hour lands on one name

Who did what, when, on which project

Your CapEx pack opens by person and by project, down to the pull requests.

  • Unattributed work is its own line, never spread
  • Names in the app and in the export

Finance → Software CapEx

How it works
  • A distribution, not a second engine: each category total is allocated across its pull requests by largest remainder in whole cents and centi-hours, so every dimension sums to the figure it came from.
  • A person, a project, a repository and a receipt row therefore reconcile to the same bucket - exactly, not within rounding.
  • One receipt row per merged pull request, carrying the rule that classified it.
  • The detail carries its OWN content hash, separate from the figures hash, so adding it never moved a number in a period a customer had already closed.
  • Work with no attributable author gets an explicit reconciling line in hours and no money - never smeared pro rata onto people who did not do it.
  • Person-level output is never withheld for imperfect identity matching: the pack states the unattributed share of commit history and links to where a human fixes it.
  • A per-person capitalisable share is withheld below your own minimum-sample setting; the hours and money beside it stay complete, because a payroll reconciliation needs every line.
CapEx restatementIAS 38
v1FY2025 policy€221k
v2Post-acq policyΔ +€49k€270k
KTLO moved OpEx → CapEx - the one rule that changed
finance@1/v2byte-identical ✓labels, not tax advice

CapEx policy versioning + retroactive restatement

Dated policy versions, and any prior period restated under any version, deterministically.

  • IAS 38 / ASC 350-40 / ASC 985-20 framing labels
  • A label, not accounting or tax advice
How it works
  • Composition, not new math: the classification corpus is policy-independent, and only the CapEx/OpEx partition of the buckets changes per version.
  • So a restatement is re-running the SAME stored rows under another ruleset version - byte-identical both times, and that reproducibility IS the audit value.
  • An org that sets no policy versions behaves byte-identically to today.
  • Every version carries its own content hash; the CSV, JSON and Markdown exports ship the active version and the restatement.
Busfactor Investment: allocation and cost rollup
Real product screenshot - names anonymized.
Meetings

The standing meeting, priced.

Meeting hours against your own loaded cost - per series, per team, per year.

Engineering StandupDaily · 6 people · 30 min
€38,330a year767 h
13%of the working week
4.1 hper person, weekly
titles never stored · the verdict is on the meeting

Meeting cost analytics

A calendar tells you the hours. This tells you the bill, because it knows what an hour costs.

“Engineering Standup costs €38,330 a year - 767 hours of your people’s time, at this rate.”

  • Per series, team, person and week
  • Every figure in your own currency

Instead ofA calendar dashboard that counts your hours and cannot price a single one.

Meeting Cost

How it works
  • Cost per occurrence is arithmetic; the finding is the ANNUALISED cost of a recurring series, because a standing meeting is a decision nobody has revisited.
  • Money runs through the shipped cost basis and your org currency - nothing composed here, nothing hardcoded.
  • Declined is never attendance, and no setting changes that. Unanswered counts, tentative does not, optional does - all three are yours to set.
  • Overlapping meetings charge each minute of a day to exactly one of them, so a person’s counted hours can never exceed their real hours.
  • A series is annualised only once it has run enough times; below that it renders its measured hours and no annual figure.
  • All-day blocks, solo blocks and anything over eight hours are not meetings, so one mislabelled offsite cannot swamp the org total.

A calendar read that cannot leak

Times, durations and attendee responses. Never a title, a description, a location or a link.

  • No such column exists in the schema
  • Titles: never, by default

Instead ofHanding a productivity vendor every private appointment in the company.

How it works
  • The absence is structural rather than a policy: there is no description, location, meeting-link, attachment or attendee-email column to fill in later, and a test asserts it against 21 field names.
  • The one opt-in title exception needs a recurring, non-private, non-1:1 series with at least five invited human attendees - and meeting rooms do not count toward the floor.
  • A 1:1, a performance review, an interview, a medical appointment and a board comp discussion store no title in either mode.
  • Out-of-office, focus time, working location and birthdays are dropped as not-meetings before anything else runs.
Always on

You never have to go looking.

Every day: where you stand, what moved, and what crossed a line.

Today’s movers
“small PRs” agreement climbed back to Aimproved
review wait crossed 24hworsened
api#482 - the day’s liveliest PR, 9 roundstoday
CTO Weekly Brief2026-W29B · ▲ +2 since Mon
ranked by consequence · receipts on every line

CTO Weekly Brief

One page a week: where the org stands, then the problems ranked by consequence.

  • Priced where inaction is computable
  • “Kept our word?” against your own agreements

Instead ofThe Monday exec summary you write by hand from six dashboards.

How it works
  • Pure composition over rows that already exist: zero new metrics, zero new ingestion, no LLM.
  • Ranking is a deterministic key - severity, boosted when the item worsened, crossed a watchdog, or lost momentum - with fixed tie-breaks and ISO weeks in UTC.
  • An empty section says so, never filler. Caps are disclosed with the real total.
2026-Q3Report CardB+ up from C+
graded at quarter close - timed to renewal

Quarterly Report Card

Every quarter closes with a letter-graded report card, timed to renewal.

  • Money recovered, commitments kept, doors still unopened
  • One move for next quarter
How it works
  • Pure composition over already-stored snapshots: letters come straight from the quarter’s score rows, and the +/- from the same config cuts, so a card can never disagree with the dial.
  • The delta narrative renders from a fixed template bank over quoted values - never generated prose.
  • Closed quarters are frozen: the same rows render a byte-identical card years later.
  • The first quarter reads as an honest baseline, not a fabricated delta.
Merge wait, weeklynobody opened this graph
It turned here.3 weeks ago · 29h → 64h

Momentum & trend breaks

Every metric watched for turns: org, area and person trajectory.

Busfactor Pulse: notifications, watchdogs, commitments
Real product screenshot - names anonymized.
Data honesty

It tells you when its own data is dirty.

Most tools trust whatever the API hands back. This one audits its own inputs.

Force-push detecteddeploy-web
2 commits vanishedquarantined ✓
history was rewritten - so your numbers didn’t lie
MCPget_org_statsread-only
prs_merged644
review_coverage68%
cycle_p5071h
quoted from your resolvers · no LLM - it can’t hallucinate

MCP server

Ask your engineering data from any AI client, and the tool can only quote.

  • Claude, Cursor, Windsurf - read-only
  • Safer by construction, not magic
How it works
  • Each tool is a single pass-through over one deterministic resolver already backing a surface - handlers do no arithmetic, no formatting, no defaulting.
  • So a test can deep-equal the tool’s output to the resolver and prove no number was synthesized.
  • Every result carries an as-of and content-hash stamp; the findings tool returns the same bytes as the download button and the CLI.
  • Person fields are export-grade masked. Auth reuses your existing session token and re-checks org membership on every call.
  • Busfactor runs no model of its own, so nothing on our side can invent a figure. Your client still writes the sentence around the number.

Force-push & vanished-commit detection

A rewritten history cannot silently inflate, erase or reassign anyone’s numbers.

  • Vanished commits quarantined: stamped, not deleted, not counted
  • The affected metrics say so

Instead ofMetrics that swing overnight after a rebase, and no tool that will admit why.

How it works
  • Every ingest reconciles the new commit graph against a stored cursor.
  • Deterministic: the same history yields the same quarantine on every run.
Free tools

Run it on your own code first.

No account, no card, nothing uploaded.

FREE SCANpnpm-lock.yaml
78of 432 have one publisher
116 of 150traced to their repository
34 refusednamed, with the reason for each
the file is parsed and discarded, never stored

Free dependency scan

Drop a lockfile into the scan and get the packages standing on a single pair of hands.

“xz was one trusted account. Count yours.”

  • 19 manifest formats, 8 registries
  • No account, no card
How it works
  • It ranks before it looks, because a cold read of three hundred repositories is hours of queue and a stranger gave you thirty seconds.
  • What your project declares and ships is looked up first, then an even spread through the rest of the tree by a deterministic permutation - the same file always produces the same slice.
  • Your lockfile is parsed in memory and never written down.
  • Registry answers are cached and SHARED: public facts about named packages, never anything about you, which is why the second scan of a React app answers in a fifth of a second.
  • Everything it did not look at stays in the denominator and prints as a count. Resolution failures are disclosed per package, with the reason.
  • Traced, measured across real lockfiles: 99.3% Packagist, 98.7% RubyGems, 98.0% Go, 94.2% PyPI, 93.3% npm - and 45.8% Maven, 32.5% NuGet, which the page tells a Java or .NET reader before they draw a conclusion.
  • Where a registry points at a repository holding several of your packages without saying which directory is which, the scan REFUSES rather than describing the wrong project.
npx busfactor ringsRing one month, width from churnKnot a long branch, absorbedScar a revert-heavy month

Rings

One command turns a repository into a printable tree-trunk cross-section.

“curl: 321 rings, 2 knots - old-growth timber. react: 159 rings, 27 knots - a different species.”

  • Offline, no signup, commit metadata only
  • Byte-identical, run to run

Instead ofA contribution graph that looks the same for every repository on earth.

How it works
  • One ring per month of the repository’s life, width from that month’s churn; top-level directories are wedges, long-lived merged branches are knots, revert-heavy months are scars.
  • The pith ends off-centre because the trunk leans toward whichever subsystem took the work.
  • It reads the commit graph and never opens a source file: git is called through a frozen invocation table, and the package cannot touch the filesystem or the network at all.
  • Author emails are hashed the moment they arrive and commit subjects reduce to one boolean, so the model it draws from contains no address to leak.
  • The cut date is the HEAD commit’s date rather than the day you ran it, so the same repository always cuts the same file.
  • Out: SVG, dark and light plates, A1 and A2 print PDFs with bleed, wallpaper sizes, and the whole model as JSON so anyone can check the picture against the counts.
Share & open source

The read travels. The names never do.

Blur is enforced in one place - so no surface can forget it.

busfactor.tech/share/7fQ2xk…COPY
████████as of 12 Apr
Review is where the week goes
██████ ████carried 62% of it
Unlisted · defaultPublic · admin opt-in
names blurred in both modes · expiry and revoke on every link
Copy linkCopy cardPost
busfactor.tech/oss/…9.4 person-years nobody invoiced
13 years maintained the maintainer’s badge links back to the report

Share bar & badge loop

Copy the link, copy the card, post the read - or take the badge that links back.

  • The post carries the page’s own headline
  • Credit badges lead; exposure never defaults
How it works
  • The card a post unfurls into is the page’s own server-rendered image, and the post text is the page’s own pinned lead - so the two cannot say different things.
  • X and Bluesky only. LinkedIn’s share intent drops prefilled text, and a button that silently loses the hook is worse than no button.
  • The badge shelf opens on what the project earned - reach, years maintained, the bill nobody sent - and an exposure badge is never the pre-selected one.
  • Choosing is the consent: a maintainer campaigning about who holds the ecosystem up still finds their badge, and picks it.
PUBLIC REPORTzloirock/core-js
9.4person-years nobody invoiced
13 yearsof somebody showing up
1 personcan land a change here
read from the public record only · credited, never ranked

Open-source reports

Public fragility reports on the projects everything depends on, read from nothing but the public record: core-js, esbuild and js-yaml.

“9.4 person-years of engineering nobody invoiced. 13 years of somebody continuing to show up. 48% of it after hours.”

  • The people who wrote it, named and credited
  • Nothing ranked, nobody named as a risk
  • Right of reply and takedown on every page
How it works
  • The same deterministic engine as your own read, pointed at a public mirror and pinned to an as-of date.
  • Commits, pull requests and releases - nothing private, and the engine has never had access to those repositories.
  • What makes the pages defensible is what they refuse: “one person can land a change here” is only claimed where merge-commit evidence shows it.
  • Where the merge side is not public, the page says what it did measure - “one person wrote 98% of the changes” - and says out loud that GitHub does not publish write access.
  • Effort figures below a coverage floor are not printed at all, with the reason on the page: a number far under the real one would read as a verdict on what the work was worth.
  • Reach figures carry the source URL and the day we read it. There is no leaderboard and there never will be.
9.4 person-years unpaidbus factor 113 years maintained
[![…](https://busfactor.tech/oss/…/badge/unpaid.svg)](…)COPY
Only the badges the repo earned · every snippet links home

README badges

Every report earns a shelf of badges - only the ones the numbers support.

  • A metric the engine refused simply has no badge
  • One line to paste, linking back
How it works
  • A badge is an SVG served from a path, never a query string, with no font file, no stylesheet, no script and no external reference - so it survives GitHub’s image proxy.
  • It brings its own dark plate rather than asking a maintainer to paste four lines of theme-switching markup: one image reads on a dark README and on a white package page.
  • Text is pinned to real glyph widths, so the same input renders byte-identically everywhere.
  • No bronze/silver/gold tiers, ever: inventing thresholds would be a judgement we generated about somebody else’s unpaid work. A ranking line quotes the project’s measured position in the population we read, never an invented grade.
  • Every snippet wraps the image in a link back to the report. There is no image-only option, and the code cannot produce one.
The fine print, proudly

Built so you can take it to a board.

Deterministic

A zero-LLM metric path. The same rows re-run to the identical byte.

Receipts

Every figure links to the PRs, reviews and issues behind it.

Read-only

Read-scoped tokens that look, and can never touch your repos or boards.

Anonymized sharing

Everything that leaves your org - share links, screenshots, public pages - is blurred. Inside it, people are named.

Nothing paywalled

Every feature on every tier. Tiers differ by capacity, not by capability.

EU / US data residency

You choose where your data lives at onboarding - EU by default.

Enterprise controls

Provisioned on demand under Enterprise agreements.

  • Self-hosted / on-prem
  • Air-gapped deployment
  • SSO / SAML
  • Custom DPA & MSA
  • SCIM provisioning
  • SLA & named support
  • Custom development
  • Procurement & invoicing
  • Security review & DD
On your hardware

On-Prem Full Audit

The full read on your hardware, air-gapped. Your data never leaves your network.

  • Runs on your own infrastructure, air-gapped
  • Unlimited developers, repos, projects and teams
  • Deterministic and receipts-linked, benchmarked against the corpus
  • A one-off engagement, not a subscription

All of it, on your data, in minutes.

Connect read-only, and the first verdict lands before your next standup.