shipsuit
Claude Code, run like infrastructure

Same Claude budget. Three times the work.

Your developers already use Claude Code. shipsuit makes it cheaper and consistent — every prompt analysed against your standards, every merge reviewed against your rules, and a fraction of the tokens. No source code ever leaves their machines.

66–86%
fewer tokens per reviewmeasured
~3×
more runs on the same spendat 66%
100%
of merges checked against your rules
0
lines of source that reach usby schema
claude code — shipsuit
$review — before this merges to production
gatesformat · lint · typecheck · tests · build4.2s
rulesyour company's rules, served for this run0.3s
contextrepo guide loaded — no re-explaining the codebase0.1s
!review18 files changed · 2 blockers · 5 warnings1.4s
money handled as a float — violates your rule on amounts
backend entry point missing its server-only guard
NOT READY — 2 blockers must clear before merge
Real output shape. Checks run locally and the model reads these findings, not your diff — which is where the token saving comes from. Run the same scan in CI and those two blockers fail the build.
The situation today

Ten developers, ten Claudes, no shared standard

Spend you can't see

Everyone is on their own subscription. Nobody can tell you who is burning what, on which model, or whether it produced anything.

Standards that live in review

Your rules exist in senior engineers' heads and get applied at PR time — after the code is written, if the right person is looking.

The same context, retyped

Every developer explains the architecture to Claude again. Different explanations, different answers, every day.

Every prompt, analysed

We work one layer below the answer

Every prompt your developers type is classified on their own machine before Claude sees it. When it touches something your company has a rule about, that rule rides along automatically. The developer types normally; Claude answers to your standards.

  1. Developer typesupdate the payout balance logic
  2. Classified locallycode · touches money
  3. Your rule attachedAmounts stay strings end to end. Multi-table writes go in one transaction.
  4. Claude answersto your standards, first try — no review round-trip
Prompt text never leaves the machine. Only the category label is ever recorded.
What your team gets

Six things, working on every repo

A fraction of the tokens

Gates, rule scans and git state run as local scripts. The model reads compact findings, never whole diffs. Measured 66–86% less context than hand-rolled.

Guardrails that can say no

The rules your team argues about — money, transactions, what may touch production — encoded once, served per run. On a developer's machine they're advice. In CI the scan exits non-zero, so a blocker fails the build.

One shared context

Every developer's Claude starts from the same generated repo guide. Nobody re-explains the architecture. New hires inherit it from git on day one.

Skills, not instructions

Pre-merge review, quality gates and a staging-aware PR flow arrive as commands. Add your own as data — no release, no redeploy, nothing for developers to do.

Code never leaves

Scans run locally. We receive counts, durations and versions — enforced by schema, not by promise. No source, no paths, no prompt text.

Leadership can see it

Tokens, cost, sessions, active time and accepted edits — per developer, per team, over 24 hours, 7 days or 30. Even when everyone is on their own subscription.

How it lands

Three steps, then it runs itself

01

We encode your rules

Your house rules and review checklist become a served ruleset. It never lands on a developer's disk.

02

Your lead runs one command

The plugin installs itself and the settings are committed. Every clone and every new hire inherits it from git.

03

It runs on every merge

Gates, rule scan and a judgment review before code reaches production. Wire the same scan into CI and a blocker stops the build — plus a usage picture leadership can act on.

Security & privacy

100% of your code stays on your machines

Not a policy — a property of the design. Every check runs locally, and the only thing that crosses the network is a fixed set of counters.

  • Enforced by schema, not by promise

    The ingest boundary is an allowlist. A field we haven't named cannot be stored, however the payload changes.

  • Prompt text never leaves

    Prompts are classified on the developer's own machine. Only the category label is ever recorded — never the words.

  • Metadata only, and we list it

    Counts, durations, model names, versions. No source, no file paths, no branch names, no free text of any kind.

  • Isolated per company, proven

    Every query is scoped by company at a single choke point, and a test suite that must stay green proves one customer can never see another.

  • Per-developer tokens

    Each person gets their own credential, individually revocable. Offboarding someone kills their access without touching anyone else.

  • Your rules stay yours

    Licensed rulesets are served per run and never written to a developer's disk — they leave with the subscription.

Your team is already paying for Claude

The question is what you get back. Onboard one repo and compare a week of usage against the week before.