How ArchRails is sold

Architecture governance for regulated engineering teams

ArchRails enforces your architecture at pull-request time and guards every AI coding agent with the same authoritative model. Built for financial-services and regulated platform teams where a missed cross-repo violation is a regulator conversation, not a refactor.

Built on FINOS CALM v1 OSFF London 2026 speaker Patent pending · Filed March 2026 No customer source code stored

How a typical engagement works

Engagements run end-to-end on a defined repo set with your real architecture model. Enforcement, agent guardrails, replayable verdicts, and federation-aware architecture context — validated against your actual change volume, in your cloud.

PR-time enforcement
Architecture rules block non-conforming merges automatically. Reviewers see exactly which CALM node, relationship, or control was violated — no judgment-call architecture discussions left on the PR.
MCP agent guardrails
Claude Code, Cursor, and any MCP-compatible agent query ArchRails for authoritative architecture context before generating code. Not a hint — the same authoritative model that blocks the PR, queried by the agent before code is generated.
Verdicts you can replay
Every PR review captures the rules that ran, the violations raised, and the CALM source each verdict traced back to. The record is reproducible — re-running the same rules against the same diff lands on the same answer. Verdicts are exportable in audit-ready format — the artifact internal audit and regulator inquiry actually ask for.
Federation-aware architecture
Architecture relationships span repositories via the CALM graph — payment-service can't reference an inventory-service interface that isn't declared, regardless of which repo the PR opens against. Cross-repo dependency visibility lives in the dashboard's federated graph view.
Evidence you can check without us
Every governed merge is signed, and the verifier is a public, open CLI your auditor installs themselves. They can validate the evidence offline — no ArchRails account, no API call, no trust in our dashboard. An audit trail you have to log into a vendor to read is a vendor's word. This one stands on its own.
Deploy in your own cloud
For institutions whose policy is that nothing leaves the perimeter, ArchRails is available as a deployment into your own AWS account — architecture files, graphs and audit artifacts in your buckets, under your keys. Scoped and stood up with your platform team during onboarding, which is a conversation worth having early. GCP and Azure on request. Start that conversation →
For regulated institutions

Architecture governance for platform engineering teams.

ArchRails is sold to architecture and platform engineering teams at regulated institutions. Engagements start with a scoping call against your repos and compliance posture; commercial structure is framed inside that call against your footprint.

Deterministic by default, BYOC on request. The same change against the same architecture always produces the same verdict, and the evidence for it is signed and independently verifiable. Run it as a managed service, or deploy it into your own AWS account so nothing crosses your perimeter — scoped with your platform team during onboarding. GCP and Azure on request.

Three modules. Compliance Enforcement, Federation, Release Governance.

Compliance Enforcement

PR-time gates backed by FINOS CALM v1 rule definitions. Every governed merge produces a signed manifest recording the architecture as it stood at that merge, who promoted it, and the commit it landed on — each one chained to the last, so the history is tamper-evident. For institutions where merges into production-bearing branches must produce an auditable approval trail.

Federation

Cross-repo dependency graph. Blast-radius analysis on every proposed change. Federated visualization of how services, contracts, and ownership boundaries fit together. For platform teams operating multi-team or multi-product code estates where dependency clarity is the daily problem.

Architecture Attestation
Shipping today

A signed manifest on every promoted state, produced automatically — nobody has to remember to generate it, which is the only kind of evidence that survives an audit. Each manifest chains to the one before it, so the record is tamper-evident rather than merely stored. And it is verifiable offline, by an auditor who has never heard of us. For release engineering and risk teams that need a portable, cryptographic record of what shipped. Read the technical detail →

Release Governance
On the roadmap

Extending the signed record past the merge commit and on to the deployed artifact, and wiring branch protection directly to CALM definitions rather than maintaining them separately. Today the chain is complete up to the promoted commit; closing the last hop to the build output is the work in front of us. Talk to us if this is on your critical path.

Enterprise

Enterprise is the deployment shape for institutions running ArchRails beyond a single business unit — whether that's two BUs or organization-wide. One rollout, one audit boundary, one set of operational rituals. SLA, named solutions engineer, source code escrow, and custom integrations scoped to the engagement.

Engagement shape, SLA, and operational commitments are framed against your repo footprint, BU count, and compliance posture in the scoping call.

Talk to the architecture team
Evidence bundle
Per governed merge
Change-management trail
Signed, chained, offline-verifiable
FINOS CALM v1
Open standard
Deployment
Managed or BYOC (AWS)
Patent pending
Filed March 2026
OSFF London 2026
Speaking June 25 →
Who you're talking to

ArchRails is built by Marc Daniel Registre — engineering leader with prior tenure at Royal Caribbean, McDonald's, LinkedIn, Chase, and American Express. POC conversations go directly to the founding team.

Talk to the architecture team

Engagements start with a 30-minute scoping call. You walk through your architecture governance pain — cross-repo drift, agent-generated regressions, audit trail gaps. We frame the right engagement shape against your repo footprint and compliance posture.

Direct response from the engineering team. Scoping call typically within two business days.

  • 30-minute scoping call with the founding team
  • Engagement shape framed inside that call
  • Kickoff within two weeks for committed engagements
  • SLA, contract term, and security posture scoped in the kickoff

Request a scoping call

Direct to the founding team. Requests are reviewed within two business days.

Request received. We'll be in touch within one business day.
Something went wrong. Please try again or email pilot@archrails.io.

Use your work email so we can route the request correctly.