Skip to content
idappt is a foundation in pre-incubation · September 2026
idx / tech transparency
Transparency

Tech Transparency

Last updated: 3 October 2026

idappt is run by self-taught system thinkers, not by trained software engineers. We want to be upfront about what that means.

Who runs this

None of us holds a degree in software engineering. We have built websites in the past, but we have never worked as professional developers, architects, analysts or testers. What we do have is a working knowledge of system design, software development environments and workflows, DevOps engineering, Git and GitHub version control, security practices, and most of today's frontier models behind the AI coding agents. We use our own understanding to direct, review and question what they produce. We also create AI agents, not just to build, but to analyse (business, requirements), architect, review and test iterations and finalised MVPs.

idappt respects human software engineers

AI agents can produce working software. They cannot replace the people who know why it works. Human analysts, architects, developers and testers will always be needed to turn a working prototype into clean, maintainable, safe code, and to spot the problems that an agent, or a founder reviewing an agent, will miss. We don't see this as a limitation to work around. It's the next stage of the project. We are looking for technical co-founders who want to take these MVPs and rebuild them into production-ready products, with the authority to change what needs changing.

What the software is and is not

The applications mentioned in the project section on this site are real, working software, but they are MVPs, not finished products. They exist to prove that the idea works, not to carry production traffic or hold regulated data.

Where AI-built software fails

AI-assisted building has well-documented failure modes: architectural inconsistencies, security vulnerabilities and growing maintenance overhead that pile up as a prototype moves toward MVP maturity. Independent audits of AI-built apps regularly find disabled database access controls, missing webhook validation, exposed API keys and authentication that can be bypassed by direct API calls. We take that seriously, and we do not claim to be immune. Code we did not write by hand is code we have to understand harder, not less.

What we do about it

  • We use AI to review code built by agents: we have created specialised AI analyst, architect and engineer agents to review and test both business logic and code. We are looking at tools on the market to improve and refine this effort.
  • Everything lives in version control with a readable commit history, so decisions can be traced.
  • Security findings are logged and tracked; we treat them as blocking until resolved.
  • We run automated tests / dependency and static-analysis scans before changes land.
  • Secrets stay out of the repository; access control is on by default, not added later.
  • We record which model and prompt produced significant pieces of code, so provenance can be audited.
  • We review the architecture against what a production system would need, and we document where the gap is rather than pretend it isn't there.
  • We document every session we have with agents, for two reasons: to reverse-engineer bugs when they occur, and to analyse session data for reusable workflows, i.e. to record how the agents work.