Sanad is a requirements and engineering governance platform built on Engineering AI Harness principles.
Traceability, criticality-scaled rigour, and audit evidence that regenerates byte-identically from a named commit — shipped and working today. AI participation capabilities are under development within the Engineering AI Harness architecture. We built the governance foundation first.
Sanad (E-REW), the requirements workbench, is available now.
Why we exist
Engineering knowledge should be a living asset, not static documentation.
Engineering organizations do not fail for lack of tools. They fail because knowledge fragments — across code, requirements, architecture, models, tests, certification evidence, wikis, and the people who happen to remember why.
As a programme runs, reality drifts from intent. Architecture erodes. Traceability breaks. The reasoning behind a decision leaves with the engineer who made it — and the organization pays to rediscover it, usually during an audit.
Ejadah exists to end that decay: to make engineering knowledge something that is compiled, verified and compounding, without asking anyone to abandon the tools they already use.
The problem
Engineering breaks the same way in every industry.
- Fragmentation
- Ten systems hold the truth. None of them understands the others, and every synchronisation is manual.
- Drift
- Implementation diverges from intent silently, between reviews — where it is cheapest to catch and never is.
- Lost rationale
- The decision survives in a document. The reasoning behind it retires with the engineer.
- Hand-built evidence
- Certification packages assembled by hand, defended from memory, rebuilt from scratch each audit.
- Unverifiable claims
- Coverage numbers nobody can reproduce, on dashboards everybody must trust.
- Knowledge that only ages
- Every document is most true the day it is written, and less true every day after.
Why now
Four forces are converging. None of them is reversible.
- Complexity has outrun memory
- Systems have grown past what any engineer — or any team — can hold in their head. The model has to live somewhere better than memory.
- A generation is retiring
- The engineers who carry decades of rationale are leaving the workforce. What they know becomes compiled knowledge now, or archaeology later.
- Software is eating the safety case
- Every product is becoming software-defined, and every safety-critical line must be certified. Hand-built evidence does not scale to that volume.
- AI has arrived — ungoverned
- The same technology that makes Engineering Intelligence possible is already writing text into engineering records. AI will enter engineering governed or ungoverned. There is no third option.
The gap
Three things had to be true at once. They never were.
Storing engineering artifacts was solved decades ago — that is every ALM database and requirements tool ever sold. Storage was never the problem.
Understanding those artifacts semantically, at scale, was impossible before modern AI. And trusting that understanding in regulated engineering is impossible with AI alone — because generative systems produce opinions, and an opinion cannot be entered into an audit.
The missing piece was never a technology. It is an architecture: a deterministic compiler that owns the truth, with AI permitted to propose and never to attest. That is what nobody built — because it requires deciding, from the first line of code, that evidence matters more than fluency.
Why AI alone is not enough
A question has a deterministic answer. A prompt has an opinion.
Generative AI alone
- Produces plausible text
- Different answer every run
- Confidence without provenance
- Cannot be entered into an audit
Engineering Intelligence
- Answers computed from a compiled model
- Byte-identical at a given commit
- Every claim cites the artifacts behind it
- Built to be certification evidence
We use AI where it is strong — proposing, drafting, explaining — and refuse it where it is dangerous: attesting. AI proposes. Only deterministic analysis attests. That single rule is the difference between an assistant and an instrument.
The harness
Engineering AI needs more than automation.
AI can now draft a requirement, map an implementation, and summarise a review in seconds. Capability has stopped being the scarce resource in engineering — trust has not. In domains where software must be certified, an answer nobody can reproduce is not an asset. It is a liability with good grammar.
A harness is not a restraint on power; it is what makes power usable. A safety harness is why work at height is possible. A wiring harness is what turns loose capability into an installable system. The Engineering AI Harness is the same idea applied to AI in engineering: structural controls — evidence, traceability, human decision gates, rigour that scales with criticality — under which AI can participate without anyone surrendering accountability for the result.
Sanad is built on those principles, in a deliberate order. The governance foundation — traceability, byte-identical evidence, human approval gates — is shipped and working today. AI participation capabilities are under development within the Engineering AI Harness architecture. We built the governance foundation first.
The category
What is Engineering Intelligence?
Engineering Intelligence is the compilation of an organization's engineering artifacts — requirements, architecture, code, verification, decisions — into a living model that answers engineering questions with evidence.
Not search, which finds documents. Not generation, which produces text. Answering: What is unproven? What does this change reach? Where has implementation drifted from intent? Why was this decided — and what breaks if we revisit it?
Every answer is computed deterministically from your repository, and every answer cites the artifacts — and the commit — behind it.
Business Intelligence made business data answerable, and no serious company now runs without it. Engineering Intelligence does the same for engineering knowledge — at the standard of proof engineering demands.
- Knowledge
- Compiled from your artifacts into a typed graph — never stored in another silo.
- Reasoning
- Deterministic engines that answer the same question the same way, every run, on any machine.
- Evidence
- Findings that regenerate byte-identically at a commit. That property is what makes them evidence.
- Governance
- Rules and rigour compiled once, enforced uniformly — never re-interpreted at the point of use.
- Memory
- Decisions carry their rationale and their rejected alternatives, so knowledge outlives tenure.
- Traceability & impact
- Every artifact knows what it reaches and what reaches it — across disciplines and across time.
How it is different
Every existing tool does one of these. None does the last.
- AI coding assistants
- Generate plausible text. Unrepeatable between runs. Cannot attest to anything.
- Engineering databases
- Store artifacts faithfully. Understand nothing. One more silo to keep in sync.
- Requirements tools
- Manage a single artifact type while the rest of engineering stays dark.
- Documentation systems
- Record what was written. Never verify that it is still true.
Engineering Intelligence
Understands, verifies, remembers, and proves — from the Git repository you already own.
Trust
Engineering that can prove itself.
In safety-critical and regulated environments, trust cannot be a promise in a slide deck. It has to be a property of the architecture — something the system is structurally unable to violate.
- Evidence, not probability
- Engineering decisions require proof. Every conclusion is computed from your artifacts, not predicted from patterns.
- Traceable to source
- Every finding cites the artifacts, the rule, and the commit that produced it. Why does it say that? always has a mechanical answer.
- AI proposes, never attests
- Suggestions remain suggestions until deterministic verification accepts them. Inferred results are marked, and excluded from evidence.
- Compiled governance
- Policy is resolved once, at load, and enforced identically for everyone — not re-interpreted by whoever runs the check.
- Reproducible from a commit
- One repository state regenerates every report, byte for byte, on any machine. A report that depends on who ran it is not evidence.
- Your knowledge stays yours
- Git-first and file-based. No proprietary database, no export step, no lock-in. Remove us, and everything you built remains.
Safety
The human stays responsible. The architecture makes sure of it.
- 01
AI proposes
drafts, suggestions, candidates
- 02
Analysis attests
deterministic engines verify
- 03
Governance approves
compiled policy, uniformly applied
- 04
A human decides
review is a step, not a setting
- 05
The repository records
ordinary Git edits, in history
Nothing enters engineering memory without review. Nothing becomes certification evidence without deterministic verification. Safety here is architectural, not procedural — the system has no path around it.
Privacy & deployment
Private by design. Deployed on your terms.
- Private by design
- Deterministic analysis runs entirely in your environment. It needs no cloud to function and no account to start.
- You own the data
- Your repository is the source of truth. There is no other store, and no proprietary database.
- AI on your terms
- One gateway, any provider: cloud, local, or customer-hosted models — your endpoint, your credentials, opt-in, and removable.
- Runs where your engineering runs
- On engineer workstations today, with no server required. Self-hosted and enterprise deployment follow the same file-first architecture.
- Air-gap capable
- Deterministic analysis is fully functional offline. AI features attach to models inside your perimeter — or stay off.
- No silent data collection
- Nothing leaves your environment without explicit configuration. Anything that does is visible, yours, and off by default.
Organizational memory
The organization remembers — even when people move on.
Every decision is recorded with its rationale and its rejected alternatives, versioned with the engineering it governs. When the question comes back in three years — and it always comes back — the answer is in the repository, not in a departed engineer's head.
That turns knowledge from a depreciating asset into a compounding one. Every artifact, every decision, every review makes the graph more valuable — and onboarding faster, because the reasoning is finally somewhere a newcomer can read.
How it works
One compiled pipeline, closed through your repository.
Everything is a file in Git. Ejadah compiles those files into facts, facts into a typed knowledge graph, and runs deterministic analysis over it. Findings carry their own provenance. AI sits at the rim — proposing edits that return to the repository as ordinary commits a human reviews.
- 01
Repository
your artifacts, in Git — the only source of truth
- 02
Facts
what the sources say, extracted 1:1, uninterpreted
- 03
Knowledge
roles become typed relationships in one compiled graph
- 04
Evidence
deterministic findings and metrics, with provenance
- 05
Intelligence
questions answered, impact traced, drift detected
- 06
Git edits
AI proposals return as commits — reviewed, then part of the truth
The loop closes: step six returns to step one. Nothing enters the truth except through the repository.
- 01
Requirements
intent, captured
- 02
Architecture
structure, allocated
- 03
Implementation
code, linked
- 04
Verification
claims, tested
- 05
Certification
evidence, assembled
Engineering philosophy
Principles with enforcement, not values on a wall.
Each of these exists because a specific engineering failure demanded it, and each is enforced by the platform's own architecture — several fail our build when violated. Our full constitution is public.
- Evidence First
Why — A claim without provenance is an opinion, and opinions cannot be audited.
Enforced — Every finding carries its rule, its artifacts and its commit. Reports are projections of findings — never fresh readings of the data.
- Single Source of Truth
Why — Two sources of truth always diverge, and the divergence stays invisible until it is expensive.
Enforced — The repository is the only store. Every model is compiled from it, per run, and thrown away — a derived model can never disagree with the files for long.
- Deterministic Engineering
Why — Certification requires the same answer twice. A tool that answers differently on Tuesday is not an instrument.
Enforced — No wall-clock, no randomness, no environment on any evidence path. Byte-identical regeneration is asserted in our test suite, not assumed.
- Compiled Knowledge
Why — Meaning interpreted in two places becomes two meanings, and every save becomes an invalidation problem.
Enforced — A declared role becomes a typed relationship in exactly one module. Nothing downstream re-derives what something means.
- Compiled Governance
Why — Policy re-evaluated at the point of use drifts with whoever evaluates it.
Enforced — Rules, rigour bands and inheritance resolve once, at load. Engines look policy up — they are forbidden from computing it.
- Continuous Verification
Why — A review held twice a year catches drift twice a year — at its most expensive.
Enforced — A full analysis pass runs in milliseconds at five thousand requirements, so it runs on every change instead of every quarter.
- AI with Explainability
Why — An unexplained suggestion is a liability anywhere a regulator can ask why.
Enforced — Inferred results are marked as candidates for human judgement, rendered as such at every surface, and excluded from reproducible evidence.
- Organizational Memory
Why — The reasoning behind a decision leaves with the engineer unless it is captured where the work happens.
Enforced — Decisions are recorded with their rejected alternatives, in the repository, versioned with the engineering they govern.
The full constitution is public: ejadah-foundation.
The platform
One intelligence layer. Seven engineering disciplines.
The Ejadah Engineering Intelligence Platform is a single compiled substrate — graph, policy, evidence, governed AI — beneath discipline-specific workbenches. Each workbench is a complete product alone; together they compose through your repository, never by calling each other. We build the next one when a real user is waiting for it.
- E-REWAvailable
Requirements Engineering
Authoring, traceability, quality, safety, impact and drift — over requirements that live as files in your repository.
- E-AEWVision
Architecture Engineering
Architecture, interfaces and design decisions, held against the system actually built.
- E-SWEVision
Software Engineering
Source analysis, reverse engineering and dependency intelligence.
- E-VEWVision
Verification Engineering
Coverage, quality gates and verification evidence.
- E-RVWVision
Review Engineering
Reviews, disposition and review metrics across every discipline.
- E-SEWVision
Systems Engineering
MBSE, functional analysis and allocation.
- E-CEWVision
Certification Engineering
DO-178C, ISO 26262, IEC 61508 and ARP4754 evidence packages.
Industries
Built for engineering that must be defended.
- Aerospace & Defense
- DO-178C, DO-254, ARP4754A
- Automotive
- ISO 26262, ASPICE
- Medical Devices
- IEC 62304, ISO 14971
- Industrial Automation
- IEC 61508
- Rail & Energy
- EN 50128, IEC 61513
- Enterprise Software
- internal governance at scale
Outcomes
What changes for your organization.
- Evidence in hours, not quarters
- Certification artifacts regenerate from a commit instead of being assembled by hand and defended from memory.
- Drift caught the day it happens
- Not at the review months later, where it is most expensive to unwind.
- Audit-ready as a steady state
- When every answer is reproducible at a commit, an audit is a demonstration, not a project.
- Onboarding in days, not months
- New engineers read the reasoning, not just the results.
- No lock-in, by construction
- Your engineering knowledge is files in Git. Remove us, and all of it remains yours.
The long view
In ten years, this is simply how engineering will work.
Methodologies distributed like software packages. Standards shipped as reusable process packs. Every artifact an organization produces feeding a graph whose value compounds with age.
The organizations that compile their engineering knowledge will outbuild the ones that file it — because compiled knowledge gets better every year, and documents only get older.
We are building for that decade deliberately: one proven workbench at a time, extracting the platform from demonstrated need rather than speculation. A platform with one consumer is not a platform — so we ship products that are indispensable before we generalize them.
Why Ejadah
Determinism cannot be retrofitted.
Every claim on this page is structural, and structure is set at the first commit. A product that began with generation cannot add evidence later — evidence is a foundation, not a feature. We began with the compiler, and put AI at the rim.
Our methodology is public and enforced. Our engineering constitution, principles and architecture decisions are published, and our own build fails when we violate them. We hold ourselves to the standard we sell — mechanically.
That is why a focused company can define this category: the incumbents own the silos this replaces, and the AI industry is optimizing for fluency. The space between — engineering you can prove — is where Ejadah builds.
Careers
Help define a category.
We are a small team building the Engineering Intelligence category from first principles. The work is unusually foundational: the primitives you design will still be load-bearing in a decade.
How we work is public — our constitution, engineering principles and architecture decisions are published, and we hold ourselves to them in CI, not in retrospectives. Arguments here are settled by measurement. Deletion is a celebrated form of progress.
We hire when a real need exists, not to a headcount plan. If evidence-first engineering is how you already think, write to us.
Begin now
The category is being defined. Early partners define it with us.
E-REW is available today, and every requirement you put through it starts compounding into knowledge immediately. Early engineering organizations get unusual influence over what gets built next — that is the trade, and we would rather state it than have you discover it. You work directly with the engineers who build the platform, with a substantive response inside 72 hours on defects — published as policy, not promised in a deck.