A runtime for persistent AI organizations

A team of AI agents, run like an organization.

Curule runs role-based agents (a product manager, an architect, developers, QA, security) on your own infrastructure. The runtime enforces who may approve what, every action is recorded and replayable, and the model is billed to you by your own provider.

The demo runs a scripted team on the real runtime: no API key, no account.

  • Self-hostedOne container per team, on your infrastructure and with your model credentials.
  • Nothing phones homeNo telemetry, no analytics, no update check, no licence server.
  • Free to startThe Community plan: one open project, up to eight agents, no licence key.
  • Source-availableBusiness Source License 1.1. Each version becomes Apache 2.0 four years after it is published.
Product view
The Curule dashboard after a scripted team of seven agents has taken a payment-API mission from requirements to a merged, reviewed result: the mission is marked Delivered, all seven mandatory checks are evidenced, and the files the team made are listed under What shipped.
Overview. The demo after its mission: seven checks evidenced, and the files the team made, each one opening in a reader.
The Events view of the same mission, filtered to messages: the append-only log newest first, who messaged whom and about what, and two red lines for things the runtime did not do, one of them a message it would not deliver, each with the reason it gives.
Events. The append-only log as it streams, newest first, here filtered to messages. The red lines are things the runtime refused or did not do, with the reason it gives.
The Designer view: the seven agents of the demo team as seats with arrows for who may contact whom, an inspector for the selected seat, a badge from the live validation reading Valid with two notes, and a bar for saving the configuration.
Designer. The same team as seats and who may contact whom, validated by the engine behind curule validate.

Every capture on this page is of the scripted demo, which makes no model calls.

Why it is not a group chat

A team needs rules, not a longer prompt.

A single agent writes code. A team of them has to know who may approve a design, merge a change, block a release or spend the budget. Curule makes those rules part of the system instead of part of a prompt.

Enforced, not asked

An approval, merge or block that an agent is not allowed to make is refused by the runtime before it becomes an event. A prompt can be argued with; the kernel cannot.

Recorded and replayable

Every action is an event in an append-only log, and every screen is a view of it. Any run can be replayed to any moment and audited afterwards.

Bounded

Budgets per agent, thread and mission, and a host-wide spend ceiling that counts every token class. Usage reports (Team plan and above) show what each project, agent and model consumed.

Yours

One container per team, on your infrastructure, with your own model credentials. No telemetry, no licence server, no markup on the model.

How a mission goes

Three steps, and a person at the end.

  1. Describe the team and the goal

    Roles, what each may do, who may talk to whom, the gates a change must pass, and what “done” means as acceptance criteria. Or start from a shipped example.

  2. The agents work through contracts

    They wake on events they care about, exchange typed messages and versioned artifacts, review each other’s work, and escalate when they disagree or run out of budget.

  3. You steer and you audit

    The human is a seat in the team with the final say. Pause, approve, redirect, reopen. A mission is done when every criterion has evidence, not when an agent says so.

The Graph view of the same mission: who talked to whom among the seven agents (product manager, architect, tech lead, developer, QA, security and explorer). Thicker links are more messages, and the legend says whether a link asked for help, was blocked, updated something or simply messaged.
Graph. Who talked to whom. Thicker links are more messages; the colour says whether a link asked for help, was blocked, updated something or simply messaged.

The console

What you see while it runs.

The console is a set of views of one event log. These are captures of the scripted demo, not mockups.

  • Mission control: the Delivered card with seven of seven checks evidenced, fifteen seconds from creation to delivery, tokens against the two million budget, and the start of the list of files the team made.

    Mission control

    Progress against the acceptance criteria, each with the evidence that satisfied it, and the artifacts the team produced.

  • Live events: the event log newest first with a search box, an agent filter, chips for alerts, activity and routine events with Messages selected, a red line for an agent that could not be woken because the mission was complete, and who messaged whom.

    Live events

    Everything the mesh does, newest first, streamed from the append-only log. Filter down to alerts, and open a line to see what caused it.

  • The per-turn ledger: filter chips for produced, no output, refused, blocked and crashed turns, then one row for each agent turn showing who ran, what it produced or that it wrote nothing, the reason a decision was refused, and the time and tokens each turn took.

    Per-turn ledger

    One row per agent turn: who ran, how long it took, what it produced or refused, and the tokens it used.

  • The team designer: seven seats drawn as cards with arrows for who may contact whom, the product manager at the top, the explorer as a service seat with a dashed outline, and QA and the developer at the bottom.

    Team designer

    Seats, authority, who may contact whom, gates and budgets, drawn as a graph and validated as you edit.

  • Cost by agent: a bar for each agent scaled to the biggest spender, with its tokens, its share of everything spent and its own budget.

    Cost and budgets

    Tokens against the mission budget, by agent and by model. A host-wide spend ceiling parks every open project when its estimate is reached.

  • The Approve or reject panel: a decision (approve, reject or accept), what it is about, an optional reason, the files made recently, and a button to record the decision in the log.

    Approvals

    You are a seat in the team. Record a yes or a no and any gate that listens for it can move: for example, a release that needs your approval.

Try it

Run the demo on your own machine, with no API key.

The demo runs a scripted team on the real runtime, so it needs no model and no credentials. It exists so that you can see the whole flow before you decide anything.

You need Docker and git. The first command uses openssl; any random string of 32 or more characters will do as the token.

There is no published container image yet, so the second step builds it from the source. Tagged releases will publish one.

Deploying: Docker Compose, Helm and TLS

  1. Make a token, and keep it

    The container refuses to start without one. You will paste it into the sign-in page.

    export MESH_API_TOKEN="$(openssl rand -hex 32)"
    echo "$MESH_API_TOKEN"
  2. Build the image from the source

    git clone https://github.com/salitaba/agent-mesh.git curule
    cd curule
    docker build -t curule .
  3. Start the demo

    docker run --rm -p 127.0.0.1:7420:7420 -v mesh-demo:/data \
      -e MESH_API_TOKEN="$MESH_API_TOKEN" \
      curule demo
  4. Open it and press Start mission

    Go to http://127.0.0.1:7420 and sign in with the token. Open the demo-stub project and press Start mission. Seven agents take a payment-API mission from requirements to a merged, reviewed, verified result, and QA blocks it once so you can see conflict handling.

    With your own credentials the same seats are real: add ANTHROPIC_API_KEY (or Bedrock, Vertex or Foundry credentials), then curule init a project.

Security

Security, stated plainly.

What it protects, what leaves your environment, and what it does not do. The agents run commands, so this is the part to read before you promise anything to anyone.

What it does

Refuses to listen on a network address without a strong token. Guards against cross-site and rebinding attacks. Sandboxes agent-written pages. Keeps the operator’s secrets out of the agents’ environment. Runs unprivileged with a read-only root, and ships a network policy for Kubernetes. Every control is pinned by a test.

What leaves your environment

Only the agents’ calls to the model provider you chose, with your credentials. Nothing goes to us: no telemetry, no analytics, no update check, no licence server.

What it does not do

One shared operator token: single sign-on and per-operator identity are planned, not included. No third-party audit, penetration test or SOC 2. The container is the boundary: narrow its network, and give each instance its own provider key with a spend limit.

Read the whole of it

Pricing

You pay for the runtime.

Model usage is separate and goes to your own provider, at your own rates. Prices are in US dollars and exclude taxes.

  • Community

    Free

    no licence key, no expiry

    1 project open, 8 agents per mesh, 4 concurrent turns

  • Team

    $149

    per month, or $124 billed annually

    5 projects open, 12 agents per mesh, 8 concurrent turns

  • Business

    $599

    per month, or $499 billed annually

    25 projects open, 30 agents per mesh, 24 concurrent turns

  • Enterprise

    Let’s talk

    quoted for your terms

    No limit on projects, agents or concurrent turns

Compare the plansHow licences work

There is no checkout and no account: a paid plan starts with an email, and the licence key is issued by hand.

Questions

Questions, answered plainly.

Do I need an Anthropic account?

No. You need credentials for a model provider that you own. The native runtime takes any provider that offers an OpenAI-compatible endpoint or the Anthropic API, and Claude Code takes an Anthropic API key or Amazon Bedrock, Google Cloud (Vertex) or Microsoft Foundry credentials. The agents use them and your provider bills you. A self-hosted Curule never sees them and does not resell model usage.

Does it send my code to you?

No. It runs on your infrastructure and sends nothing to us. Your code goes to your model provider, because the agents cannot work without it, under your agreement with them.

What is the free plan?

Community: one open project of up to eight agents, with the full runtime, dashboard, designer and command line. It needs no licence and never expires.

Is it open source?

No, it is source-available. The code is public under the Business Source License 1.1: you can read, build, modify and run it, and real work on the free plan is free. Running more than the free plan allows, or offering it to others as a hosted service or inside your own product, needs a commercial licence. Each version becomes Apache 2.0 four years after it is published.

How do I buy a paid plan?

There is no checkout and no account. Write to us with the plan you want and the name the licence should carry; we agree the terms with you and issue a licence key by hand. You install it with curule license install <key>, and it is checked on your machine.

What happens when a licence expires?

Nothing stops and nothing is lost. The plan’s limits stay in force for a grace period (14 days by default); after it the instance is on the free plan. We cannot disable anything remotely, and your data is yours.

Can it run without internet access?

Yes. A licence is verified on your machine. The agents need a route to your model provider, which can be a private endpoint.

Can you host it for us?

Not today. It is software you run, one instance per team; the repository has a Compose file, a Helm chart and a provisioning script for that.

Does it work with models other than Claude?

Yes. The native runtime calls the model itself through OpenAI-compatible chat completions or the Anthropic Messages API, so it works with providers and local model servers that offer either, and curule providers check proves a provider and a model before a mission runs. A model has to be able to call tools. Everything measured on this site ran on Claude Haiku through Claude Code; we have not measured the quality of other models and do not claim it is equivalent.

How reliable are the results?

We have measured one mission class: five agents built a small library in 31 minutes for $5.52 of model usage, and an independent check scored it 99.6%. One run is not a rate, and a mesh may do worse than a single agent on some work. Try it on your own task in a pilot.

Run the demo, then bring your own credentials.

The scripted team needs no API key. The same seats run on model credentials you own (any OpenAI-compatible provider, the Anthropic API, Bedrock, Vertex or Foundry), on your infrastructure.