Pages
Build Partner Portal

Source: c62 build-partner — Surface A, the shared portal. Painted directly from content-architecture.md + sharp-edges.md (no wireframe pass).

Viewing as Meridian Systems· Founding Build Partner #3 of 8
Cycles closed
9
across all repos · last 30d
Ships
14
4 from partner asks
Partners live
4
Edges open
15
Edges closed 30d
3

This band is generated from the cycle system and the sharp-edges registry — it is never hand-edited.

Now

active cycles
Subprocess trust attribution
Re-modeling proxy policy around process attribution so agents that shell out stop breaking MITM for their children.
closes sharp edge · Agents that shell out can break inspection
Provider adapter expansion
Bedrock Converse and Azure OpenAI URL shapes — widening what parses cleanly beyond the current four agents.
Desired-state tap healing
Taps that survive reinstalls and path moves without a manual re-tap.
closes sharp edge · Reinstall to a new path loses coverage

Next

queued
Cost attribution (cost_usd)
Spend lands on every LLM event instead of None — starting where the wire already carries it.
asked by Alloy Fintech · #2
target_pid dual-key attribution
Proxy events name the tapped child, not the proxy host.
Config wildcards + live reload
auto_tap agent patterns and policy changes without a restart.
asked by Meridian Systems · #3

Order shifts with partner feedback — that's the point.

Shipped

ship log
Event consumer guideJul 2026
The stable event contract is documented — build collectors on it without guessing.
Windows host-side supportJul 2026
Wrapped runs on Windows fleets, with the limits stated plainly (see Sharp Edges).
↳ traces to Torchline AI · #5
Selective MITM exclusionsJun 2026
Cert-pinned hosts learned and excluded instead of breaking every session.
Fleet inventory viewAug 2026
Every agent, machine, and shadow install on one ledger in qdash.
↳ traces to Meridian Systems · #3

Sharp Edges

10 of 15 shown · reviewed every release

The honest list. Every edge names what it affects, a workaround (or says "none"), and where the fix stands. If you hit something that isn't here, that's a bug in this page — tell us.

highFirst connection to a cert-pinned host always failsknown

Selective MITM learns exclusions by observing a cert rejection — so the first request to a pinned endpoint breaks before the exclusion exists. Later connections work.

Affects : any stack calling pinned endpointsWorkaround :pre-declare known pinned hosts in policy.toml
highAgents that shell out can break inspection for their childrenfix planned

Child processes inherit proxy env but often honor only HTTPS_PROXY and reject the MITM cert. Our own assessment: current endpoint-based exclusions are not a sufficient fix.

Affects : most real agents — subprocess use is the normWorkaround :none today
highUnattributed connections silently pass through uninspectedknown

When process attribution fails or times out, the connection falls back to raw tunneling. Traffic flows; you see nothing — a gap, not an error.

Affects : oversight and compliance expectationsWorkaround :treat absence-of-events as a signal to investigate
highThe event stream is lossy — no replayby design

The event socket is a bounded live stream: brief buffering while a collector is down, drops under pressure, no replay. Snapshot restores current state, not missed history.

Affects : audit and compliance pipelinesWorkaround :run your collector highly available; snapshot on reconnect
highWindows is host-side onlyfix planned

No agent injection, no OS trust-store management, no per-process attribution, no live telemetry — and identity enforcement proceeds without the control applied.

Affects : Windows fleetsWorkaround :treat Windows as observe-lite; keep enforcement on macOS/Linux
mediumAgent adapters: four todayknown

Adapter-grade understanding exists for Claude Code, Codex, Cursor, and OpenClaw. Other agents can be tapped, but without adapter depth.

Affects : coverage planningWorkaround :tell us your roster — partner asks order this queue
mediumNo cost attribution yetfix planned

cost_usd is empty on every provider — even where the wire carries cost, the schema has nowhere to put it yet.

Affects : spend-oversight expectationsWorkaround :derive spend from token counts externally
mediumqcontrol run is terminal-silentby design

Because it wraps TUIs, all diagnostics — including pre-launch failures — go to log files, never the screen. A non-working tap looks like nothing happened.

Affects : first-run debuggingWorkaround :the log file is the first stop, always

If you also deploy the qtap eBPF agent

separate product — separate requirements
highTLS decryption is OpenSSL-only todayknown

Go crypto/tls, Java JSSE, and Node TLS are not yet implemented — a Go or Rust AI workload will not have its TLS decrypted.

Affects : Go, Rust, Java, Node workloadsWorkaround :none today
highHeavy prerequisites; capped, best-effort captureknown

Kernel 5.10+ with BTF and an effectively-privileged container. Captured messages cap at ~120 KiB (large LLM bodies truncate), and capture is best-effort under load — loss is a first-class metric.

Affects : locked-down clusters · large payloads · high loadWorkaround :clear the deploy recipe with security early; alarm on the drop counters

The Program

Founding cohort · week 4 of 12

The program has rules and they're written down: five phases, a real end date, and a real ask at the end. Where the cohort stands is always visible — including to each other.

1Deploy
qcontrol on the machines your agents run on
1 partner here
2Traffic visible
your agents' activity on the ledger
2 partners here
3Policies on
first controls live in observe mode
1 partner here
4Oversight live
enforcement on, leadership view real
2 partners here
5Conversion
week 12 — a real yes/no
What we ask
  • · A real integration, not a lab — qcontrol on the machines your agents run on
  • · A 30-minute structured session every two weeks
  • · Honest signal, especially when it's bad
  • · A yes/no conversation at week 12 — paid pilot of the next phase
What you get
  • · A numbered founding seat, priced like one — locked at conversion
  • · Direct line to the people building it (below)
  • · Your asks visibly reordering the roadmap — with your name on the ship log
  • · This portal: the same view of the project we have

Founding Partners

6 seated · 2 seats reserved
#1May 2026
Quarry Data
Data infra · 40 engineers
First production deploy
#2May 2026
Alloy Fintech
Payments · 120 engineers
Asked: cost attribution → queued
#3you
Meridian Systems
B2B SaaS · 85 engineers
2 ships trace to your asks
#4Jun 2026
Fieldnote Bio
Research tools · 25 engineers
#5Jul 2026
Torchline AI
Agent platform · 30 engineers
Asked: Windows support → shipped
#6Jul 2026
Herewith Labs
Healthcare AI · 60 engineers
#7seat reserved
#8seat reserved

Why we're building this

Every org is quietly becoming an AI company — not by strategy, but by installation. Agents arrive on laptops, wire themselves into repos and credentials, and start acting. The org chart didn't change; the actors on it did.

Oversight tools built for humans watch the wrong layer. We think the right layer is the seam where agents touch the world — the process, the connection, the credential — and that visibility there has to be honest about its own gaps to be worth trusting. That's why this portal has a Sharp Edges page and why it will never be empty.

The long version — the one to send your leadership — lives in the thesis doc, alongside how we work: small numbered cycles, shipped weekly, in the open with this cohort.

Direct Line

Shared Slack channel
The same channel the team works in — not a support queue. Median response is minutes, not days.
#meridian-x-qpoint
Office hours
Thursdays, drop-in, engineers present. Bring a broken tap or a hard question.
Thursdays 11:00 PT →
Book the founders
Thirty minutes, any topic — architecture, roadmap, the ask at week 12.
cal.qpoint.io/founders →

Everything you raise — in Slack, in sessions, in the feedback queue — lands in the attribution ledger. When it ships, the ship log says so, by name.

Qpoint Brand Style Guide