The change-consequence layer

See what a change will break — before it breaks it.

FortLock reads your live environment, maps every dependency across Kubernetes and cloud, and turns every pull request, plan and deploy into a known consequence — woven through the tools your teams already run.

As AI ramps change faster than any human can review, FortLock is the consequence layer that keeps it safe — for engineers and AI agents alike — and gets smarter with every change.

Threads through GitHubGitLabTerraform Argo CDHarnessDatadog PagerDutyServiceNow
FortLock · live mapside panel
app-config ConfigMap ns · boutique
read by 11 services · part of storefront + checkout
change impact WARN
what if I modify this? · reversibility reversible · 23 affected
consequence — how it breaks
errors · dependents may error on this change
SLO / latency · a user-facing path is in the blast
availability · a single-replica SPOF is in the blast
impact probability resilience-adjusted
loadgenerator SPOF100%
checkoutservice72%
boutique-ing Ingress41%
frontend 3 replicas55%
watch-list — verify after you ship
checkout error rate · p99 latency · boutique-ing 5xx at the edge
GitHub sees the change. Wiz sees the exposure. FortLock sees the consequence.
The gap

Every change ships on a guess.

The map of what depends on what lives in senior engineers' heads — never written down, never current. So a one-line config edit takes down checkout, and a 2am page becomes an hour of log archaeology.

🩻

Reviews are blind

A PR diff shows the lines that changed — never the eleven services that read that config, or that one of them is a single-replica payments path.

🧭

Knowledge doesn't scale

"Who uses this?" is answered in Slack, by the few people who remember. They leave. The dependency graph drifts the moment it's written down.

⏱️

Incidents are archaeology

When something breaks, finding the change that caused it is manual correlation across five tools — the single most expensive minutes in the business.

How it works

One live graph. One thread through every change.

FortLock connects read-only to the systems you already run, builds a content-addressed dependency graph of the live environment — across Kubernetes, cloud, config and runtime traffic — and follows a single change record through its entire lifecycle.

Preflight
simulate before the PR exists
Consequence
blast radius + how it breaks
🛡
Safe-ship
canary · split · sequence
Verify
the exact signals to watch
Incident
symptom → the cause + rollback
Recalibrate
outcomes tune the model

read-only by construction · self-hostable · never reads a secret's value

The platform

From "what changed" to "what it does."

Seven capabilities, one engine. Each answers a question about a change — never the steady state, which your incumbents already own.

Blast radius

Cross-seam consequence

Every transitive dependent of a change, weighted by confidence and criticality — including the k8s↔cloud seam a Terraform plan crosses, before apply.

Prediction

Resilience-adjusted probability

A semantic read of what field changed, propagated through a simulation that attenuates for redundancy — a 3-replica service reads differently than a single-replica SPOF.

Multi-dimensional

How it breaks — and what to watch

Errors, SLO/latency, availability, data, security, capacity — each with the exact signals to verify after you ship. Not "73% risky," but "check these."

Incident

Change-cause correlation

A symptom asset, run backwards: the ranked changes whose blast hit it, the likely cause, and the one to roll back. MTTR from an hour to minutes.

Guidance

Safe-ship counterfactuals

Not just what breaks — how to ship it: canary, add a replica, split the fan-out, flag it, rotate with overlap. Each tied to the risk it removes.

Memory

Longitudinal intelligence

The change ledger as institutional memory: which change types and teams carry risk, which assets keep landing in the blast, auto-assembled postmortems.

Governance · expansion (post-SOC 2)

Coordination & evidence

Collisions between in-flight changes, ship-before ordering, and a tamper-evident evidence pack — the artifact a regulated audit asks for. An expansion motion that opens once SOC 2 Type II lands.

Surface

Wherever engineers already are

The same intelligence in the CLI, the PR check, the CI gate, the API and a live interactive map. No new dashboard to adopt.

Posture

Read-only & self-hostable

Built read-only by construction; secret values are never read, only references. Runs air-gapped. Never depends on a competitor's API to function.

Why it wins

The model gets sharper with every change you ship.

Incumbents own state — inventory, posture, monitoring. FortLock owns change-over-state, and that's where the defensible asset will accrue: every prediction gets labeled against what actually happened, so the model calibrates to your environment. The corpus is empty today — it will compound per design partner as it fills, and it can't be bolted on after the fact without the history.

↓ MTTR
The metric execs already fundchange-cause correlation collapses time-to-cause.
↓ CFR
Change-failure ratepreflight + blast context catch the rare scary one.
A compounding corpuspredicted-vs-actual outcomes, calibrated to measured reality.
Calibration · illustrative Brier 0.235 → 0.194 (representative)

How calibration works: predicted probability gets corrected against labeled outcomes, so the number becomes measured, not asserted. Figures shown are representative on the sample environment.

predicted
actual
p high
→100%
p low
→0%

isotonic reliability curve · the corpus accrues after landing with design partners

Built for what's coming

AI writes the change. No human can review it all.

Every safety mechanism — code review, change boards, "ask the engineer who knows this system" — was built for human-paced change. As agents generate and ship changes at machine speed, that assumption breaks. The dependency knowledge that kept you safe lives in a few heads and evaporates with every departure.

🤖

A guardrail for agents

The same calibrated consequence API an engineer reads in a PR is the check an autonomous agent calls before it ships — at machine speed, with an audit trail. The admission control layer for AI-driven change.

🧠

Knowledge that compounds

Operational understanding stops walking out the door. Every change — human or agent — is predicted, then checked against what happened, so the model of how your estate behaves only sharpens. A system of record, not a wiki that goes stale.

⚙️

Across both change chains

It threads the developer pipeline (GitHub/GitLab) and the enterprise change chain (ServiceNow CR/CAB) — tying every change from intent → predicted consequence → real outcome → learning, and moving CFR and MTTR while it does.

Where it fits

A beautiful add-on — not a rip-and-replace.

FortLock doesn't replace a step in your change process. It's the connective intelligence between the steps no single tool owns — landing context exactly where the work already happens.

Open PR / MR

Blast radius + owner routing posted on the pull request. Reviewers get context instead of rubber-stamping.

Terraform plan

Cross-seam consequence before apply — the one thing no other tool shows when cloud cascades into Kubernetes.

CI / CD gate

Advisory check in the pipeline you already run. Shift-left, no new dashboard.

Deploy / rollout

Watch the predicted blast as it rolls out; diverge → flag or roll back in the act.

On-call / incident

Symptom → the change that caused it, plus the rollback. The painkiller that moves MTTR.

Audit / CAB · expansion

Tamper-evident evidence pack: every change, blast, approval and outcome — the expansion motion for regulated teams, gated on SOC 2.

Roadmap

Prove it cheap. Then compound.

A deliberate sequence: land bottoms-up on visibility, earn trust on the painkillers, then let the calibration corpus build the moat. The engine below is built today — the path ahead is adoption and depth.

Phase 0Engine● built & tested

The change-consequence engine

  • Live dependency graph, k8s + cloud + runtime done
  • Blast radius + reversibility done
  • Multi-dimensional consequence + watch-list done
  • Resilience-adjusted propagation + calibration done
  • Change-cause correlation + safe-ship guidance done
  • Coordination + tamper-evident evidence done
Phase 1Design partners5 real teams

Frictionless adoption on real estates

  • One-command connect for live clusters & cloud accounts
  • Native PR / MR checks & CI plugins, zero-config
  • Hosted & self-host / air-gapped deployment
  • SSO, RBAC, multi-tenant data isolation
  • Design-partner telemetry → first real calibration curves
Phase 2Depth & breadththe moat compounds

Deeper prediction, wider surface

  • Cost, security & data dimensions of consequence
  • Counterfactual auto-PRs ("ship it this way instead")
  • Cross-org benchmark intelligence (anonymized)
  • Flux, Spinnaker, Backstage, OpsLevel integrations
  • Outcome-loop automation across the deploy pipeline
Phase 3Platformchange-control system of record

The consequence layer for the enterprise

  • Change governance & CAB automation
  • Policy-as-evidence, compliance frameworks
  • Org-wide change-risk analytics & targets
  • Marketplace of integrations & consequence models
See it live

Turn every change into a known consequence.

Click into the interactive map, pick an asset, and watch the blast radius, consequence and safe-ship guidance light up — the way your engineers will.

Get in touch

Talk to us.

Design partnership, a pilot, security questions, or just curious — send a note and we'll get back to you.

Stay in the loop

Product updates, no noise.

The consequence layer for AI-driven change is moving fast. Get the occasional update on the engine, the thesis, and design-partner openings.

Double opt-in. Unsubscribe anytime. We never share your email.