Portable execution
Move work between qualified environments without transferring credentials or machine authority.
VerchestraVerified delivery
Verchestra is a verified AI software-delivery harness. It turns discovery, planning, implementation, validation, and human approval into portable, signed, and reviewable delivery work.
In practice: A developer can begin with one AI environment and hand the next developer an executable contract, verified evidence, and the exact next action — without transferring credentials or relying on chat history.
0.0.0-qualificationT77 verified1.0 decision pendingPublic source development and a published qualification package are available. A production release is not.
portable / signed / reviewableThe problem
AI-assisted work disappears into provider sessions, local machines, and undocumented decisions. The next developer inherits a conversation, not an executable contract.
Verchestra makes the durable facts portable while credentials, sessions, and machine authority remain local.
What works today
Human-readable status first, internal task ids second. Each state has one meaning:available — runnable today from a source checkout of the local alpha. qualified — backed by a public validation report; not yet composed into the cli surface. planned — roadmap work with a declared task; no code is claimed.
| Capability | Status | Evidence |
|---|---|---|
| Workspace initialization (init preview and apply) | available | issue #64 slice A/B |
| Evidence signing-key lifecycle (persist, rotate, revoke) | qualified | T68a |
| Cost and duration budget enforcement | qualified | T68b |
| Declared gate repair loop with human escalation | qualified | T68c |
| Policy boundary: declarative tests and signed bundles | qualified | T68d |
| AI driver adapters (Claude Code, Codex, OpenCode/Qwen) | qualified | driver qualification |
| Read-only database probes (7 engines, fixture-qualified) | qualified | database matrix |
| Signed distribution, activation, and rollback (TUF) | qualified | T66-T68 |
| Self-Test trust domain and doctor --deep | qualified | T69-T72 |
| Public regression campaigns and sealed-holdout promotion | qualified | T73-T74 |
| Platform matrix, release candidate, and the 1.0 decision | planned | T75-T77 |
Models can change. The delivery contract, evidence, and accountability do not.
Move work between qualified environments without transferring credentials or machine authority.
Capabilities, approvals, leases, and egress rules are evaluated before external actions.
Bounded database probes expose approved context without creating a hidden writer.
Packages, runs, reports, and release inputs bind their source state by digest and signature.
Independent verification and human acceptance remain explicit workflow states.
Initialization, effects, Git operations, recovery, and handoff converge idempotently.
Example handoff. The receiving developer rebuilds local authority while preserving the signed execution contract.
Read-only data probes
Database discovery runs through bounded plans, explicit capabilities, audit evidence, and read-only credentials. SAP ASE / Sybase is a first-class adapter, not an afterthought.
Explore database discoverymode: read_onlyFoundations through T77 are backed by public validation reports. The declared qualification chain is fully verified. The signed promote-or-reject decision a 1.0 release requires has not been made.
What Verchestra is not
Build the standard with us
Explore the architecture, challenge the design, and help qualify the path to 1.0.