Your machines. Your code. Their tokens, on your terms.

GRIDLINE runs coding agents and local models across the machines on your private network, has every piece of work reviewed by a different model that never saw the author's reasoning, and refuses — on measured evidence — what it cannot prove.

NODE ≥ 20 · ZERO RUNTIME DEPENDENCIES · BINDS LOOPBACK · TAILSCALE FOR REMOTE
19×
less author time: three 4–8B models matched one 30B on defect recall (0.708 on 72 cases)
11 → 1
classes of material; exactly one may leave the fleet, and anything unlisted is refused
0
local judges admitted — the admission test refused every model it measured, and that is the design working
0
packages at runtime; a never-run clone served the dashboard in seconds

Six places it says no

Trust is not produced by a confident model. It is produced by a system that refuses, on evidence, and records why.

RefusesWhen
a modelit is larger than the node's measured budget — not its nameplate
a judgeit cannot tell a real defect from a false one
a writeit falls outside the task contract's declared paths
a sandboxit could escape its container
a callit would exceed its per-task, daily, or fleet spend cap
a payloadit carries material classed as unable to leave

Cloud without compromise

A provider may be used. It may never receive material classed as private. Enforced at one chokepoint, not by the caller's good intentions.

what the agent wants to send            what GRIDLINE does with it
"here is the code, review it"     ──▶   repository-source   may NOT leave · refused
"here is a retrieved chunk"       ──▶   rag-chunk           may NOT leave · refused
"here is the finding to check"    ──▶   finding             may NOT leave · refused
"here is the review instruction"  ──▶   public-instruction  may leave · sent
"here is a prompt I assembled"    ──▶   assembled-prompt    mixed by construction · refused whole
anything nobody classified        ──▶   default private     refused
two-valuedThere is no "usually fine" class. Material that is sometimes safe is two classes with two names, or it is refused.
constructedThe gate never inspects a prompt and guesses. It assembles what leaves from parts it classified individually; one private part refuses the whole call.
attributedEvery refusal names the task and the class, in the same event log as the task's runs. "What almost left" is a query, not a forensic exercise.
Today a cloud call can carry only instruction text this project already published. Not a byte of your repository can reach a provider. One provider is declared and switched off, twelve staged attacks on the gate held, and the first live call is the next step. It lands behind that gate rather than beside it.

Local without compromise

A fleet with no provider configured behaves exactly as it does with one: same routing, same defaults, same latency. Cloud is an addition, never a migration. There is no degraded tier and nothing behind a login.

What the measurements said

Every claim on this site links to the record that produced it. Half of the records say something did not work. Those are the ones worth reading.

measured · negative

Every judge panel scored below its best member

0.972 alone against 0.924 for the best three-member vote. A member below chance outvotes a good judge whenever two agree. The adjudicator is a cascade of one.

measured · negative

A keyword scan beat the embedder 6–4

On the memory fixture, weighted word presence found the labelled location in six of ten cases; the embedding search found four. Recall stays on, unchanged.

measured · negative

9% of the corpus was unreachable

The chunker truncated long sections for the life of the index and nothing could say so. Fixed; the index now reports drift.

measured

Three small models matched one 30B

Equal recall, 19× less author time — and the two arms found different defects. Diversity pays when pooling candidates and costs when pooling decisions.

Every figure above is measured. Each links to its record in the repository — published with the release.

Where it sits

NVIDIA's PAIR gives your GPUs one address. OpenShell keeps an agent in a box. GRIDLINE sits above both and decides what they are allowed to do.

            ┌──────────────────────────────────────────────────────┐
            │  GRIDLINE — the control plane                        │
            │  what work is admitted · who reviews it · what it    │
            │  may cost · what may leave · what may be written     │
            └───────────────┬──────────────────┬───────────────────┘
                            │                  │
      ┌─────────────────────▼───┐    ┌─────────▼──────────────────┐
      │ agent runtimes          │    │ inference substrate        │
      │ Claude Code · Codex ·   │    │ Ollama on your nodes       │
      │ Hermes (in a sandbox)   │    │ (a router can sit here)    │
      └─────────────────────────┘    └────────────────────────────┘

What it is not

Where it stands

The honest state, not the pitch. Shipped is measured here; in progress is building; not proven is named so its absence is not read as a claim.

shipped · proven

The refusals

Measured-budget routing, cross-model review with a context cut, the egress boundary, write-scope contracts, the sandbox, and the spend caps — each with a record.

in progress

The cloud path

The gate, the ledger and the call chain are built and one provider is declared and switched off. The first live call is the next step, behind the gate.

not proven yet

The admitted judge

No local model has passed judge admission — the test refused every one it measured. Verified approval stays closed until a judge earns it. That refusal is the design working.

Early access

One update a week, sourced from a measurement. The release the day it ships. Nothing else.

Email hello@gridline.run

One line back is all it takes. No form, no tracker, no list broker.