Evidence-First Architecture Governance

Measure architecture.
Govern change.

Rigoryn analyzes the architecture of your codebase — not its style. A deterministic engine parses five languages into one model, builds the dependency graph, and gates every pull request on evidence you can verify.

Self-hosted · deterministic · your code never leaves your infrastructure

The problem

Linters see lines. Architecture decays between them.

God classes, coupling hotspots, dependency cycles and N+1 query paths are not style problems — they are structural, they span files and layers, and they accumulate one approved pull request at a time. Most tools either miss them or report a single number nobody can check.

STRUCTURE

Graph, not grep

Dependencies are resolved into a class and package graph with a resolution ledger, so cycles and fan-in/fan-out come from edges that were actually resolved.

EVIDENCE

Every finding is checkable

Each violation carries its metrics, thresholds and source location. No finding depends on a model's opinion.

GOVERNANCE

Gate the change, not the past

A new-code ratchet gate blocks regressions on the lines a pull request touches, without demanding a rewrite of legacy code first.


How it works

One deterministic pipeline. An optional explanation layer.

The same code always produces the same report — every analysis carries a reproducible fingerprint, so results are CI-gateable and comparable over time.

01

Parse

Native parsers per language normalize into one unified class model with shared metrics: WMC, LCOM, CBO, RFC, cyclomatic complexity.

02

Graph

Build-aware dependency resolution, layer and framework detection, cycle detection over resolved internal edges.

03

Rules & gates

A calibrated rule engine, duplication analysis, SARIF and coverage ingestion, and quality gates for your CI.

04

Explain

Optional: Rigoryn Explain turns findings into prioritized refactoring guidance, validated against the metrics.

Java · Eclipse JDT Kotlin · compiler PSI C# · Roslyn Python · ast TypeScript · SWC

Principles

The measurement state is the product.

A score that hides what it did not measure is worse than no score. Rigoryn reports, for every axis, how much evidence it rests on — and says so plainly when the answer is "not enough".

  • FULL, PARTIAL or UNMEASURED. Every score axis states its measurement state, evidence coverage, confidence, and the inputs it is missing.
  • Deterministic first. The engine is AST, graph and rules. No token budget, no model drift, no different answer on Tuesday.
  • Aggregate real scanners. Security evidence comes from the tools your team already trusts — Semgrep, Trivy, Grype — via SARIF, routed to the right axis.
  • Precision is reviewed, not assumed. Every rule's findings have been hand-labelled for false positives, and rules that do not yet earn a "violation" are reported as hotspots instead.
  • Behaviour over time. Git-history analysis — change hotspots, temporal coupling, ownership — tells you which findings to fix first.

Rigoryn Explain

Rigoryn finds the evidence.
Rigoryn Explain interprets it.

The optional LLM layer turns deterministic findings into prioritized, human-readable refactoring plans. It is grounded in the engine's metrics, and its output is validated against them before it is shown — anything that contradicts the evidence is retried or replaced with a deterministic fallback.

Bring your own model: Anthropic Claude, OpenAI, Gemini, or a fully local model through Ollama or llama.cpp. Or run with no LLM at all — the engine never needs one.


Where it runs

From the IDE to the merge button.

CI / CD

Scanner & quality gates

Docker scanner, GitHub Action, GitLab CI and Jenkins templates. Fail on new criticals, health-drop budgets or new cycles.

SERVER

Self-hosted dashboard

Analysis history, violations explorer, dependency graph, trends, report diffs and what-if refactoring impact.

DEVELOPER

IDE plugins

IntelliJ IDEA and VS Code: inline diagnostics, gutter markers and one-click analysis where the code is written.


Editions

Open core. On-prem first.

Both editions run on your own infrastructure. Enterprise licenses verify offline — no license server, no phone-home, air-gap friendly. No telemetry is collected.

Community Apache-2.0

  • Full deterministic engine, all five language parsers, all rules
  • Scanner CLI, Docker image and CI templates
  • Self-hosted server and dashboard for a single project
  • Rigoryn Explain with your own LLM
  • IntelliJ and VS Code plugins

Enterprise commercial

  • Multi-project portfolio views
  • Trend governance and org-level report diffs
  • Managed pull-request quality-gate automation
  • Slack, Microsoft Teams and Zoom integrations
  • SSO and priority support
Design partners

We are onboarding a small number of pilot teams.

If you own a Java, Kotlin, C#, Python or TypeScript codebase that is large enough to have architecture problems — and you want them measured honestly — we would like to hear from you.

[email protected]