One organization license. Every team builds.
Bring every team onto one platform with a real backend under every app, environments with role-based promotion, and an AI control surface that is governed by design. No tokens. No credits. No meter. You bring the AI subscription you already pay for.
Pricing is quoted per organization, not per seat. Bring your IT or security lead to the first call.
Four things the license buys you
No meter
Nothing is metered while your teams build, debug, or run. One organization license covers every builder, every app, and every environment; your AI subscription stays with your provider.
A real backend
Every app is assembled from governed platform primitives — objects backed by real tables, forms, workflows, grids, screens.
Environments and RBAC
Custom frontends move dev → staging → production: one-way, owner-gated into production, with non-destructive rollback and an append-only deployment log. Platform apps publish in one step — working copy to Testing and Production — gated by group permissions rather than a staging approval.
Governed AI
Your agent works through approximately 100 named operations, authenticated on every request, acting with the user's own permissions. Edits are staged, previewable and reversible; a per-solution flag freezes AI writes on demand.
Built for many teams, many tenants
Unlimited builders. Unlimited apps.
The license is the only line item. Add a business unit, an agency team, or a regional office and nothing on the invoice moves; adding a builder is an invitation, not a purchase order. Every app gets its environments included.
One account, many tenants.
One organization account can host many tenants for its own customers, business units, or clients, with row-level data isolation on every table and explicit tenant context on every write. This is shared, governed multi-tenancy — not dedicated instances per customer.
Your identity provider, one identity.
SSO through Auth0, SAML, Google, and Firebase. One identity spans the platform, the MCP control surface, and the custom-frontend deploy chain, so the person prompting is the person authorized.
Only owners promote to production.
Owners and editors deploy to dev and promote to staging; only owners promote to production or roll it back. Rollback creates a new deployment pointing at the last good version — nothing deleted, audit trail intact.
Your AI subscription stays with your provider and never touches our invoice. Custom backend functions are on the roadmap, not shipped. Custom domains are not offered yet — every app gets an HTTPS URL on our domain per environment, and there is no dedicated infrastructure per customer: isolation is row-level inside your account.
The catch, stated plainly: pricing is quoted, not listed, and a platform app is built from primitives that only run here. Take the data out through the documented API whenever you like, keep the custom-frontend repositories you already hold — but the rails under a platform app stay with the platform.
Security, in short
Every request to the control surface carries a bearer token validated on every call; a rejected request receives a 401 and nothing else — no tool list, no schema. The agent acts with the signed-in user's permissions and the platform performs authorization; the AI layer never decides who can do what. Object data isolates per tenant at the row level, artifact storage is closed to the public and served only through signed origin access, and every app URL is HTTPS.
Apps run on managed cloud infrastructure we operate, built primarily on AWS. The backend is not self-hostable. The full posture, with the architecture points behind each claim, is on the security hub; compliance status — including what is not in place — is on its own page and kept honest.
For the buying committee
What you can ask for during evaluation, and where it lives.
- Architecture overview — on request; a walk through the control surface, the primitives, the environments and the hosting model.
- Security overview — the security hub in writing, plus a review session with your team.
- Data Processing Agreement — on request during procurement.
- Subprocessors and compliance status — published on the compliance page, including items still being finalized for launch.
- References — a live reference call, arranged during evaluation. The stories on customers are illustrative examples and are labelled as such; the reference is a real conversation with a customer running on the platform.
- Ownership and exit — what leaves with you and what does not: object data is real tables you export through a documented API, custom frontends are ordinary Vite/React repositories, platform apps run on the platform. Read the trade.
Built by Knomatic
CodeMonster.ai is built by Knomatic, on a backend that has carried enterprise workloads for twelve years: customers ship CRM-like apps, field-service and inspection apps, and workflow automation on it today. The AI-native control surface is the new part; the platform it drives is not. Reliability comes from the platform's history; speed comes from letting your agent operate it through named, governed operations.
Onboarding and support
Onboarding starts with a 30-minute pilot call: one real use case, your builder building it, your IT or security lead in the room. Support channels and response targets are being finalized for launch and are confirmed in your agreement alongside the organization license — ask and we will send the current version in writing before you sign.
We do not publish support hours or an uptime commitment today; we will publish them when we can stand behind them contractually. How incident notices reach your administrative contacts in the meantime is on the status page.
Questions the buying committee asks
Where does our data live?
On managed cloud infrastructure we operate, built primarily on AWS. Object data sits in real tables with row-level tenant isolation, file storage uses signed URLs, and every app URL is served over HTTPS. A specific region commitment is not promised until it is confirmed in writing; ask us on the call. The backend is not self-hostable.
Do you support single sign-on?
Yes. The platform supports SSO through Auth0, SAML, Google, or Firebase. Roles on custom frontends are owner, editor, and viewer; platform apps gate screens, actions, and grids by group, evaluated server-side. Automated user provisioning (SCIM) is not something we claim today.
How long has this platform been around, and who stands behind it?
Knomatic — the company that built the platform, operates it, and signs your agreement. The track record is in “Built by Knomatic” above, and about has the detail. Customer references are available on request during evaluation.
What stops the AI from doing something it should not?
It works through named operations, never raw backend access, and it acts with the signed-in user's permissions rather than its own. Edits are staged, previewable as an entity-level diff, and committed as one reversible save. A per-solution flag freezes AI writes entirely during human-only windows, and every operation is authenticated and recorded.
What does the procurement path look like?
It starts with the 30-minute pilot call above. From there: the security overview and architecture overview on request, a DPA on request, the subprocessors list from the compliance page, and an organization license quoted for your shape — teams, tenants, and environments, not prompts.