TimainTimaintechnical documentation
Technical documentation: for engineers. Accurate about what is built, how it works and where the limits are. Looking for the overview?

Built for the people who have to say yes

Security and platform teams block AI delivery for one reason: nobody can show who verified what. Here, that proof is the product.

A small trusted kernel

The kernel owns authorization and every lifecycle transition and sits outside anything agents can modify. Tenant code cannot acquire platform authority by editing a spec.

Authority from server state

One deterministic authorization decision over platform-owned grants, deny by default. Tokens carry identity, never permissions.

Tenant isolation at the database

Every row carries its tenant and project, enforced by row-level security, so isolation does not depend on application code remembering to filter.

Sandboxed builds

Builds and tests run in containers with no network, a read-only filesystem, a non-root user and hard resource limits.

Signed evidence

Every receipt and certification is signed with a platform key and verified by signature. Images are signed and checked against trusted signers before anything is sealed or deployed.

Disposable environments

Development and test environments are created from scratch and destroyed with the teardown confirmed, so nothing accumulates and nothing leaks.

No secret ever enters a prompt, an artifact, generated source or a log. Identity never comes from a model argument.

Design principles, architecture decisions and the threat model are published with the platform's documentation, and the status of every component is stated as executable or planned.