Auditor Technical details Docs What's New GitHub ↗
Book a call PL
Speedwave · Open source AI-SDLC platform · Built for BFSI

Adopt AI coding assistants safely in regulated software delivery.

Speedwave helps engineering, security and governance teams move from scattered AI usage to an approved, controlled and auditable way of working.

Developers keep the speed of AI. Organisations get the control, visibility and evidence they need.

Works with: Claude Code ★ Cursor VS Code IntelliJ Local LLMs deepest integration with Claude Code
github.com/speednet-software/speedwave · 15-20% delivery velocity · Built by Speednet - 24+ years in banking

AI coding is already happening. The question is whether it is governed.

Developers are using AI coding assistants to move faster. But in regulated engineering, unmanaged AI adoption can expose source code, credentials, sensitive data and delivery workflows to new risks.

Blocking AI creates Shadow AI. Allowing it without controls creates compliance and auditability gaps.

01 Shadow AI usage Developers use unapproved AI tools outside security controls, creating data exposure and compliance blind spots.
02 No visibility into AI-assisted work No audit trail of what the AI read, wrote or executed. No way to reconstruct decisions or attribute changes.
03 Sensitive data in prompts Source code, credentials, PESEL numbers and IBAN values sent to external APIs without tokenisation or logging.
04 Uncontrolled access to tools and repositories AI assistants reach SSH keys, .env files and other projects on the workstation with no boundary enforcement.
05 No audit evidence for security or compliance teams Nothing to show regulators, auditors or your CISO. AI-assisted work leaves no structured evidence trail.

Speedwave gives teams a safer path to AI-assisted delivery.

Control, visibility and evidence - for every role in your organisation.

For developers
Use AI coding assistants inside approved workflows without unnecessary friction. Container isolation keeps credentials and secrets out of reach. 13-agent code review on every commit.
For engineering leaders
Improve delivery speed while reducing unmanaged AI usage across teams and projects. Fleet-wide visibility into AI-assisted work from day one.
For security and governance teams
Set clear boundaries, protect sensitive data and create evidence for review. PII tokenisation, full audit trail, and SIEM-ready event stream.

What Speedwave adds to your AI coding stack

Control, visibility and evidence around the AI tools your teams already want to use.

Full technical details →

Hardened container

AI assistant runs inside an isolated project environment. It cannot reach SSH keys, .env files, secrets, or other projects on the workstation.

Scoped tool gateway

Only approved integrations are exposed to the assistant. Context window stays predictable regardless of how many tools are connected.

PII tokenisation

Sensitive values - PESEL, IBAN, card numbers, email - are tokenised before reaching the model and restored locally. The model never sees real data.

Full audit log

Every AI action logged from the start: read, write, delete, with timestamp and attribution. No configuration required. Ready for your CISO and auditor.

13-agent code review

Every commit reviewed in parallel across security, test coverage, SOLID, duplication, type design, and 8 further dimensions.

Trusted integrations

Maintained integrations for Jira, Redmine, GitLab and more - secured in containers, centrally logged and updated with every release.

Scale Speedwave to your entire engineering organisation - with full board-level visibility.

Once you go past a single team, you need central governance across the fleet, an AI Act-ready system registry, and a compliance documentation pack your CISO and auditor can hand to the regulator. Auditor delivers all three.

Talk to us about Auditor →
SSO + RBAC Microsoft Entra ID, 9 permission areas, fleet-wide central management
AI Registry AI Act Art. 51-52 and ISO 42001. Risk classification and governance workflow
34 metrics DeepEval, RAGAS, Promptfoo - PII Leakage, Prompt Injection, SQL Injection Guard
139 events Full audit trail (Kafka + Debezium CDC). OTLP/HTTP to Splunk, QRadar, Datadog
32 docs Compliance documentation pack, 3 phases, gap analysis with severity classification

Frequently asked questions

Does Speedwave send our code to Speednet servers? +
No. Speedwave is an on-workstation tool. Your code and data stay on your machine. API calls go directly from your workstation to Anthropic (or your chosen LLM provider). Speednet servers are not in the data path.
What happens to our API keys? +
Your API keys are stored locally on the engineer's workstation. They are used to make direct calls to Anthropic. They never pass through Speednet infrastructure. Credential isolation is one of the 11 defense layers.
Is there a risk of prompt injection? +
Yes, the risk exists for all AI tools. Speedwave reduces it through the tool gateway (two-tool model), SecurityCheck (fail-closed gate), and container isolation that limits blast radius. We are the only AI-SDLC platform to publish a dedicated Prompt Injection FAQ.
What is the difference between Speedwave core and Auditor? +
Speedwave core is the per-workstation tool: container, gateway, PII tokenisation, 13-agent code review, audit log. Apache 2.0 open source. Auditor is the enterprise module: central governance, AI System Registry, dashboards, SIEM integration, compliance documentation. Commercial subscription.
Can we use local LLMs instead of cloud APIs? +
Yes. Speedwave supports local LLM backends (Ollama, LM Studio). Recommended for teams that cannot route AI traffic to external services due to network policy or data classification. DORA exit strategy includes local LLM fallback.
What does the AI-SDLC Readiness Workshop include? +
A 2-day on-site or remote workshop led by Speednet engineers. Output: current-state assessment of your SDLC, identification of AI integration points, DORA and AI Act gap analysis, and a concrete implementation roadmap - tailored to your BFSI context.
Do you offer SLA for the open source core? +
The Apache 2.0 core comes without SLA. SLA, priority support, and custom development are available through the Speedwave Team or Enterprise subscription. Community support is available through GitHub Discussions.
Speednet team

Read the code first

Apache 2.0. Public GitHub. Your security team can audit every line before your procurement talks to anyone.

See on GitHub →

Talk to us about Speedwave

30-min scoping call or the AI-SDLC Readiness Workshop. We scope your environment, map the regulatory requirements, and give you a concrete implementation plan.