marlow

Enterprise

For teams that cannot send code to someone else’s cloud, and agencies holding several clients’ repositories at once.

Built for it

  • Self-hosted

    A Helm chart and a compose file, with nothing durable on local disk.

  • Your own provider keys

    Bring your own key and those calls are invoiced to you directly, recorded here at zero. Per provider — bring one, leave the rest with us.

    How it works
  • Organisations kept apart

    Every secret read is checked against the organisation asking for it, and someone else's secret reads exactly like one that does not exist.

  • A spend ceiling

    An organisation-wide spend ceiling over a rolling window and a concurrency cap keep the total where you put it. Once spend reaches the ceiling, the next model call is refused.

    How it works
  • Approval policy per project

    Each project's merge policy decides: wait for CI, wait for an owner's approval, merge on its own tests and review, or open the pull request and stop.

    How it works
  • An audit log

    One append-only row per mutation: organisation, actor, action, target, payload and time.

In place of a logo wall

What it connects to

Tickets come in from your tracker, forge or chat. Pull requests go out to the repository. One chat app per deployment.

  • GitHub
  • GitLab
  • Bitbucket Cloud
  • Linear
  • Jira
  • Sentry
  • Slack
  • Microsoft Teams
  • Google Chat
  • Webhook

In place of compliance badges

Four more things the code does

  • AES-256-GCM

    Secrets are encrypted at rest

    AES-256-GCM, so a tampered value fails to decrypt rather than reading back wrong. Project variables can come from your own Vault or OpenBao instead.

  • 1 run : 1 box

    Each run gets its own container

    On the sandbox image the project sets, with memory, CPU and process limits. Its volume is discarded with the run.

  • 2 vendors

    A second vendor reviews the diff

    The model that reviews a change always comes from a different vendor than the model that wrote it.

  • SARIF

    Your scanner, not ours

    Name the SARIF scanner the project already trusts — Semgrep, CodeQL, Trivy, gitleaks — and it runs on each change Marlow writes and each pull request it reviews. A scan that leaves no report is never counted as clean.

For agencies and studios

Cost per ticket, not cost per seat

Marlow works a client’s backlog from their tracker and hands back reviewed pull requests — priced per run, with model tokens passed through at the provider’s own rate.

Every run carries its own price
Each model call is priced as it happens and written to the run. What a client's work cost is a number you read, not an invoice you apportion.
Or it leaves your bill entirely
Add your own provider key and those calls are invoiced to you directly, recorded here at zero. Per provider — bring one, leave the rest with us.
Client work stays apart
Each project gets its own sandbox and its own encrypted, scoped secrets. A run for one repository cannot see another's working tree.
For the client whose code cannot leave
A Helm chart and a compose file, running in their network on their infrastructure, with their own provider keys. It is the same product — talk to us about it rather than working it out from the repository.
Not everything you bill for is a feature
Fixing red CI, reviewing every pull request, verifying the build still boots — workflows a project enables. The work a small team never has room for and a client still notices.
A ticket anyone can file
The intake gate asks for what a thin ticket is missing before anything is spent. An account manager can file the work without writing it up like an engineer.

What you hand over

The monthly report writes itself

Pick a project and a period and Marlow mints a read-only link. Your client opens it without an account and sees every run in that month: what changed, whether the tests ran, what the review decided, what merged, and what the period cost.

It names no organisation, project, repository or person, and carries no logs, environment variables, diffs, file paths or links — the same redaction a shared single run goes through.

The period is fixed when you mint it, so a link cannot be widened by whoever holds it, and revoking takes effect on the next request.

A run with no recorded model call is left out of the total rather than counted as free, and the report says when that happened. A total that quietly rounded “we do not know” to zero is not one to invoice against.

Where the edges are

Can I see margin per client in the console?
Not yet. Spend is recorded on every run and the delivery report totals a period — the number you would put in front of a client. A per-project rollup for your own margin analysis runs against your own database on the self-hosted path.
Can each client have its own provider key?
Only by giving each client its own organisation. A provider key is held per organisation and per vendor, so one key covers every project inside it. Separate organisations also separate the ledger, the members and the plan.
Does it work on a repository we did not write?
That is the normal case, and it is what the repository's own AGENTS.md or CLAUDE.md is for — a run reads it before it starts. What it needs is a repository that builds, a test command, and someone who can merge.

Start on Free

Assign it one boring ticket.

Connect a repository and hand Marlow something you have been putting off. Set the gate to “open a pull request and stop” — the worst case is a branch you close.

No card required · nothing to cancel · read the FAQ