Build

AI to build the solution, reviewed and documented as it goes. The receipts are part of the product.

Claudia: Codie builds, two independent auditors review, and David stands behind the result. Every change is logged, and that log is part of what you buy.

The Workshop at 158 Lab HQ. Codie and David in the Workshop.
Codie and David in the Workshop.

Build with compliance in mind, with receipts

We build with AI coding agents, and nothing they write ships on trust. Every change is reviewed by two independent AI auditors from different labs to the one that wrote it, because a model reviewing its own work is not a review. A human does not read every line, and we will not pretend otherwise. A human stands behind the result. Every write to our systems is logged with who did it and when, so the trail exists whether or not anyone ever asks to see it.

What you actually receive

A working system, the documentation that proves how it was built, and the evidence your own clients may one day ask you for. Half the value of the aircraft is the pallet of service records. Same here.

Not certified, and we say so first

Certification means an accredited third party audits you against a standard and issues a certificate. We have not done that, and we will tell you before you have to ask. What we do instead is build to the published controls, from the Australian Privacy Principles to the OWASP application security standard, and keep the evidence: the control mapping, what each review found, what we changed, and when it shipped. We are also a verified organisation under Anthropic's Cyber Verification Program, which is what lets us run genuine adversarial testing rather than only reason about it. That is an access program, not a security certification, and we would rather say so than let it be mistaken for one.

How we use this on ourselves

Not a case study from someone else. This is what runs our own business today.

  • This website: built by Codie, reviewed by two independent AI auditors from different labs, deployed from a logged pipeline.
  • HQ, our own operations platform, with audit triggers on every table.
  • Our own security standards are a living document with a changelog, including the entries where we downgraded our own compliance ratings after a review found we had overstated them.
  • Client builds this year: two websites and a social studio, each with its own security baseline.