Skip to content
TrussGet in

Software you describe, instead of software you rebuild

Write down how your work works.TRUSS runs it.

You describe the things you keep track of, and who may see or change each one. TRUSS reads that description and starts working. Nobody builds new software.

And from the first minute, TRUSS remembers. Every change keeps who made it, when, and what the value was before. That memory is not a feature you switch on. It is the only way anything is allowed to change.

  • 7rules we never break
  • 1way anything can change
  • 0sign-up buttons, on purpose

The idea, in one picture

The rules are printed on a card, not glued inside the box.

Swap the card and the same box plays a whole new game. TRUSS is the box. Your description is the card.

Glued inside the box

Printed on a card

Most business software has the rules glued in. "A patient has a list of allergies" is buried somewhere inside the program. To change it, somebody has to open the software up, edit it, test it and ship it. That takes weeks. It is why every new question turns into a new project.

TRUSS keeps the rules on the outside, in a file a person can read. The file says what things exist — a patient, a visit, a bill, a pump, a student. It says what facts each thing holds. And it says who may look, and who may change.

TRUSS itself knows nothing about hospitals, banks or factories. That is not a gap we are apologising for. It is the exact reason one TRUSS can run all three.

One more thing follows from this, and it is the useful one. The rules are written about meaning, not about where the data happens to sit. You write "a nurse may see a patient's allergies". You do not write "a nurse may read table 14, column 9". So the day somebody finally moves the database, the rule still says what it always said. It never mentioned the database.

Two ways to run a business on software

You need a new kind of record

Software with the rules glued in

A project. Weeks, if you are lucky.

TRUSS

A few lines in the description. Today.
Who is allowed to see this field?

Software with the rules glued in

Written into the code, usually in three places, and they disagree.

TRUSS

One line, in one place, that anyone can read.
What did this record say last year?

Software with the rules glued in

Ask whoever kept the backups.

TRUSS

Open the record. It is still there.
A second team wants their own version

Software with the rules glued in

A second system to look after for ever.

TRUSS

A second description.
You move to a new database

Software with the rules glued in

Rewrite the rules and hope.

TRUSS

The rules never mentioned the database.
Who read this yesterday?

Software with the rules glued in

Nobody knows.

TRUSS

It was written down as it happened.

A description you can read out loud in a meeting is a description somebody can argue with. Code is not, which is how wrong rules survive for years.

Four worked examples

What this actually looks like on a Tuesday morning.

Four ordinary situations. One TRUSS, four descriptions. Read the one closest to your work — the others will make sense afterwards.These four are worked examples, written to show how the product behaves. They are not case studies. No customer of ours is described on this page.

Care01

A hospital moving forty years of paper into a computer

hidden is not blank — a withheld value says so

The situation

A hospital group with three sites is putting its patient notes on a computer for the first time.

What goes wrong today

Paper does not tell you who read it. A file leaves a ward and comes back, and nobody can say whose hands it passed through. The first time somebody asks "who looked at this patient's record?", the honest answer is: we do not know.

Then the copying starts. A chart is pasted into a spreadsheet so the new clinic can use it. That copy has no rules attached to it at all. It is a file on somebody's laptop, and in five years it will still be there.

And when a value is wrong — an allergy typed onto the wrong patient — the old value is simply gone. Afterwards, the correction looks exactly like the truth. There is no way to tell, from the screen, that anything was ever different.

What TRUSS does

You describe the hospital once. A patient. A visit. A test result. A prescription. Then you say, in the same file, who may see each fact.

A ward nurse sees the allergies. Only the treating team sees the HIV result. The billing office sees the visit dates and no clinical detail at all. Nothing else in the hospital has to be rebuilt for that to become true. The description is the rule — there is no second copy of it hidden in the software.

Every change goes through one door. There is no back way in: no "just this once, straight into the database". So the list of who touched a record is the whole list, not most of it.

The moment it clicks

A clerk in billing opens a patient. Where the HIV result would be, the screen does not show a blank box. It says the value is withheld.

That difference is the entire product. A blank is a claim — a blank says nothing is there. Showing a blank where a real value is hidden is a small lie, and people make decisions on small lies. Withheld says something else: there is something here, the record is complete, and you are not cleared for this part of it.

The clerk still cannot see the value. Nobody has been embarrassed. And the fact that the clerk looked, and the reason they were refused, are both written down.

And the second thing

A month later the ward wants to widen who can see that field. One person asks for the change. That same person cannot be the one who approves it — and this is not our software being polite. The database itself refuses to store the row.

Money02

A lender who must show a regulator where a number came from

every change: who, when, and what it was before

The situation

A lender turns down a loan. Months later the regulator asks why, and where the number in that decision came from.

What goes wrong today

The number came from a report. The report came from a spreadsheet. The spreadsheet came from an export somebody ran on a Thursday, and that person has left. Nobody is lying. Nobody can prove anything either.

So the answer is found by hand, by a team, over three weeks — and the question was about one customer, one number, one day.

It is worse than slow. Somebody corrected that customer's income figure last year, and correcting it was the right thing to do. But the file now shows the corrected number, the decision was made using the old one, and there is nothing on the page that says so.

What TRUSS does

Every value carries where it came from: the system it was pulled out of, the day it arrived, and the person or program that wrote it. Not in a separate log somebody hopefully kept. Attached to the value itself, always, because a value cannot be written any other way.

And nothing is ever painted over. A correction is a new fact laid on top of the old one. The old one stays underneath, with the date it stopped being used.

The moment it clicks

The regulator asks about one customer, one number, one day. Someone opens the customer, opens History, and reads it out.

On 3 March the income figure was 84,000, and it came from the payroll feed. On 19 August a named person changed it to 91,000, and said why. The decision on 5 March used the March figure.

That is a three-second answer to a three-week question. And it is the same answer whoever asks, because nobody assembled it. It is not a report. It is the record.

You can also ask TRUSS what the record looked like on 5 March, and it will show you that — not today's version with today's corrections in it.

Students03

A university where everyone needs some of it and nobody should have all of it

an agent can propose. it cannot approve.

The situation

A university keeps records for thirty thousand students: marks, fees, disability support, and safeguarding notes.

What goes wrong today

One big system has one big login. The honest answer to "who can see the counselling notes?" is "more people than we would like", and nobody wants to be the one who says it out loud.

Then a mark changes the week after results are published. The only way to find out who changed it is to ask people whether they remember.

Meanwhile a tutor emails a class spreadsheet to a colleague, because that is the fastest way to get the job done. It is now a permanent copy with no rules on it, sitting in two mailboxes for ever.

What TRUSS does

You describe a student, an enrolment, a mark, a support note. You say who may see what — and you say it once, about meaning: "a tutor may see the marks of students they teach."

Because that rule is about students and tutors rather than about tables and columns, it survives the day IT finally replaces the student database. The rule did not know which database it was, and it did not need to.

Every mark, every fee waiver, every change of any kind carries the name of the person who made it.

The moment it clicks

A script is set up to fix a batch of miskeyed marks overnight. Sensible — far faster and more accurate than a person doing it by hand at midnight.

The script can propose all of them. It cannot approve a single one.

When it tries, the database refuses the row and records what tried. So the next morning a human sees a list of proposed corrections, approves them one at a time, and their name goes on each one. The one who asks can never be the one who agrees.

That is not a checkbox in a settings menu that somebody could switch off during a bad week. It is a rule inside the database. Switching it off would mean deliberately rebuilding part of the database, which is not something that happens by accident at two in the morning.

Things04

A factory that has to answer "which ones got the bad batch?"

change the description, not the software

The situation

A factory builds pumps. Every pump is made of parts, and every part came from somewhere.

What goes wrong today

A supplier calls: one batch of seals was faulty. Which pumps got them?

Today that question is answered by a person with a spreadsheet, a stack of delivery notes and a weekend. Guess wide and you recall four thousand pumps that were perfectly fine. Guess narrow and you miss the one that matters.

And the shop floor corrects its numbers constantly — a torque reading typed in wrong, a batch number transposed. Correcting them is right. Correcting them silently is how a recall goes wrong.

What TRUSS does

You describe a part, a batch, a pump, a shipment, and how they join together. A pump then stops being a row in a spreadsheet and becomes a thing connected to the batches that went into it.

"Which pumps contain batch 7742?" turns into a question you ask the system, instead of a project you staff.

And when the factory starts making a new kind of part, that is a few lines added to the description, in force the same day. Not a release. Everything recorded before still reads back exactly as it did.

The moment it clicks

A technician corrects a torque reading from 42 to 48. The 42 does not vanish.

The record shows 42, then 48. It shows who changed it, when, and that it came from a person rather than from a machine feed.

Six months later, in a recall, that difference is the whole argument. You can show an inspector what was measured, what was corrected, and by whom. A system that quietly overwrites hands you a tidy number and nothing to stand on.

Three promises

If you remember nothing else from this page, remember three things.

They sound small when you say them out loud. They are the entire product, and each one is enforced rather than encouraged.

promise01

Everything that happens is written down, and it stays written down.

Who did it, when, and what the value was before. Not in an add-on that somebody could turn off during a busy quarter, and not in a separate log kept beside the data that might have missed something.

The change and the record of the change are saved in the same breath. They cannot drift apart, even if a machine falls over between one and the other.

Everything you see on a screen is worked out from that record. Delete every summary in the system and TRUSS builds them all again. The history is the truth. The screen is only a view of it.

The part your auditor should ask about

The record is chained, link to link, like links you cannot re-forge. Alter one old link and every link after it stops matching.

So your own auditor can write down where the chain had reached on a given date and keep that note in their own drawer. Later, they ask TRUSS whether their note is still true.

Somebody with complete control of our database could delete history and tidy up perfectly after themselves — and would still fail that question. They cannot reach into your auditor's pocket.

ExampleA torque reading, corrected.
  1. 48now

    when14 Mar 2026 · 09:12

    whoa technician — a person, not a feed

  2. 42before

    when02 Mar 2026 · 06:40

    whoa machine feed

promise02

A thing you may not see says so. It never shows you a blank.

TRUSS keeps four different situations visibly apart, because they mean four completely different things:

  • 48there is a value, and here it is
  • withheldthere is a value, and you are not cleared to see it
  • —nothing was ever written here
  • nullsomebody deliberately set this to nothing

Most systems show you the same empty space for all four. That is how a person ends up telling a regulator, or a patient, that there is no record — when in fact there is one and they simply could not see it.

Your permissions are part of the question TRUSS puts to the database, not a filter laid over the answer afterwards. And permission is checked before the work is done, never after — so being told "no" does not accidentally reveal that the thing you asked about exists.

ExampleOne record, opened by someone in a billing office.
visit date14 Mar 2026
wardWard 3
test resultwithheld

promise03

Important changes need a second person — and the database is what insists.

Whoever proposes a change cannot be the one who approves it.

That is not a checkbox. It is not a setting in a menu. It is not even a rule written in our software, which a determined person could eventually route around. It is a constraint inside the database: the row cannot be stored, and the attempt is named.

This is also what makes it reasonable to point an AI at real work. An agent can read, and an agent can propose. It cannot approve itself. Its proposal waits for a human, exactly like everybody else's.

ExampleOne proposed change, and what happens next.
proposed byan agentproposed
approved bythe same agentrefused
approved bya second personstored

Where this comes from

TRUSS is our own build of the pattern behind Palantir Foundry, and we would rather you heard the honest part from us: Foundry has far more features than we do.

What we can show you is our half of it. In TRUSS the separation of the person who proposes from the person who approves is enforced by the database itself — a constraint in the schema, not a setting in a menu. Nobody can be talked out of it, because there is no switch to talk them out of.

The seven rules

These are the product. Not the small print.

“If a change breaks one of these rules, it is wrong — even if it works, and even if a customer asks for it.”

  1. One door in.

    There is exactly one way to change anything. Not a main way and a quiet back way. One. So “who changed this?” has one place to look, and the answer is complete.

  2. Your world is a document, not code.

    Your things and your rules live in a file a person can read. The software knows nothing about your business — which is precisely why it can run anybody’s.

  3. One referee, and nobody carries a pass.

    Every single look and every single change asks the same question of the same referee: a person, another program, or an AI. There is no “internal” caller that gets to skip it.

  4. Nothing happens quietly.

    The moment a change is saved, its record is saved with it, in the same breath. The two cannot come apart later, however badly the day is going.

  5. You can always rebuild the answer.

    Everything on screen is worked out from the original record of what happened. Throw away every summary and TRUSS makes them again from scratch.

  6. Every fact remembers where it came from.

    Each value carries who wrote it, when, and whether it arrived from another system, from a person, or from several sources merged together. “Why does it say this?” always has an answer.

  7. Machines suggest. People decide.

    An AI or a script can propose a change. It cannot approve its own. The database refuses the row — which is what turns pointing a machine at real work into a plan rather than a gamble.

The same seven, in the words your auditor and your engineers will use

What this page calls itWhat the documents call it
the written description of your worldthe ontology, published as a bundle
a kind of thing you keep track ofan object type
where a value came fromprovenance
the label that decides who may see a fielda marking
the one refereethe policy decision point, or PDP
your organisation’s own separate copya tenant, or workspace
a named person signing to say something is correctan attestation

We use the plain words on this page and the exact words in the product’s documents. Both sets describe the same thing. Neither is marketing.

How it works

Write it down. Publish it. Switch it on.

Three steps — and then a fourth, which is the point: there is no fourth step.

  1. 01

    Write it down

    List the things your work is made of. Patients, orders, pumps, students, cases, vehicles — whatever it actually is. Say what facts each one holds, who may look, and who may change. It is a file you could read aloud in a meeting. It is not a program.

  2. 02

    Publish it

    TRUSS takes a fingerprint of that file. From then on, that version cannot be quietly edited: change one letter and the fingerprint stops matching.

    Before it lets you publish, TRUSS compares the new version against the old one and says plainly which it is — safe to add, or this will break things. That is a machine's answer, not a tired colleague's opinion at six o'clock on a Friday.

    Permissions only ever tighten on the way through. You can add a restriction; you cannot quietly drop one. So a change can never accidentally show people more than they could see yesterday.

  3. 03

    Switch it on

    Choose which version your team works with. That choice is written down for good. If you change your mind, you switch forward to the older version — so the history shows that you changed your mind, instead of pretending it never happened.

  4. 04

    That is the whole job

    Nothing was rebuilt. Nothing was redeployed. A second team, or a second customer, is a second description — not a second system to look after for the next ten years.

And every second it is running

It asks permission first.
Before doing the work, not after. So a refusal never accidentally tells you that the thing you asked about exists.
You are shown only your rows.
Your permissions are part of the question we put to the database, not a filter over the answer.
An approval can wait as long as it needs to.
Some work needs a human to say yes. That step survives restarts and upgrades and picks up exactly where it left off, days later.
Your own code still obeys the rules.
You can plug in your own logic. It runs outside TRUSS, and it is checked and recorded like everything else. Your code does not get to stand outside the rules.

Honest limits

What TRUSS is not, and what is not built yet.

This is a governance product. If we shade the truth on our own website, nothing else we tell you is worth much. So here is the unflattering list, in public, where it is hardest for us to move it later.

  1. TRUSS is early.

    Every deployment so far began as a conversation about one specific problem. We are not a shelf you buy from, and we are not going to pretend otherwise while you are making a decision this size.

  2. Some screens do not exist yet.

    The record is kept whether or not there is a page to look at it on — but you should know exactly which pages there are.

    Today you can: browse your description, browse and change records, see a record’s full history, approve changes that are waiting on a decision, see who holds which clearance, see the labels that gate data, and publish and switch on new versions.

    There is no screen yet for: how well governed a workspace is overall, tracing a value back to the system it started in, the rules themselves, who can get in, the control checklist, browsing the audit record, the source connections, or settings.

    Those appear in the menu and say plainly that they are not switched on. Hiding them would misrepresent what TRUSS is today.

  3. The audit record exists; the page to browse it does not.

    Worth separating, because they get confused. Every change and every decision is recorded and chained, and the chain can be checked. There is simply no screen yet that lets you sit and read it.

  4. Sign-in is ours, today.

    Every person is issued a username and a password by us, on infrastructure we run. TRUSS does not yet connect to your organisation’s own sign-in. We would like to say otherwise. It is not built, so we do not say it.

  5. We publish no numbers.

    No uptime figure. No speed. No size of thing we have handled. We have not measured any of them to a standard we would defend in a room with your engineers, and a number on a website is a promise. When we have measured, we will publish how we measured it.

  6. We hold no certificate.

    TRUSS produces evidence. It does not produce a compliance outcome, and it cannot. No auditor has certified this product and we will not let a badge on a page imply one has. What TRUSS gives your auditor is a record they can check themselves. The judgement stays theirs, which is where it belongs.

  7. It does not replace your systems on day one.

    TRUSS can pull records in from systems you already run. There is no screen for managing those connections yet, so today we set them up with you. Most first deployments sit alongside what you have and take one painful question off the table.

  8. It will not make you faster this week.

    Writing down what your things are, and who may see them, is genuinely hard work. It is usually the first time an organisation has had to agree on the answer. That is the cost, and it is also most of the value.

Ways to work with us

Five shapes, smallest first.

No prices on this page, and no promises about the shapes we have not built.

  1. T0

    Foundation

    One team, one description, one machine. Try the whole idea on your own work before anybody signs anything.

  2. T1

    Team

    For a team past its first description: a place to practise and a place that is real, kept properly apart — and somebody to call.

  3. T2

    Enterprise

    More machines, each customer's data kept properly apart, and an engineer who knows your world by name.

  4. T3

    Sovereign

    Runs inside your own building, with no internet at all if that is what your rules require. Priced per site, because a meter that phones home is not an option here. What you are really buying is proof: your own auditor can check the history themselves, without asking us.

  5. T4

    ISV

    Put TRUSS underneath your own product, and ship your world as descriptions instead of as code.

Today we run the first two shapes, for organisations we work with directly. The other three describe how we would work — they are not something you can buy this week. We would rather say that now than let you find it out in month three.

This suits you if:

  • you can name the things you keep track of, even roughly
  • somebody will one day ask you to prove what a record said on a particular day
  • different people need different parts of the same record, and today they all see all of it
  • you are moving off paper, or off a system nobody dares change any more
  • you want to put an AI near real work without giving it the power to act alone

This does not suit you if:

  • you want to sign up this afternoon and try it by yourself — there is no such door
  • you need every screen finished before you start
  • you need a certificate to hand somebody next month
  • nobody in your organisation is willing to write down who may see what

No prices on this page. We have not settled them, and a number we would have to take back is worse than no number.

One promise we will make now: looking at your own data will be near-free, and being told "no" will cost nothing at all. Nobody should ever have a money reason to weaken a safety rule.

Getting in

There is no sign-up button, on purpose. Sign-in is a different door.

Two doors, and it is worth saying plainly which is which — most websites merge them, and that is a habit rather than a fact about software.

You already work in TRUSS

Your workspace has its own address and its own front door. If you have forgotten which one it is, that is all this link is for: type the name, and we point you at it. We ask you for nothing else. Your own sign-in does that.

Sign in

You do not have one yet

Nobody can make an account appear by filling in a form. Not you, and not us either. A person is written down first, by name, and only then can they get in.

That is slower for us and less convenient for you, and it is exactly the point. "Who is allowed to do this?" only has an answer if somebody decided it in advance. Nobody arrives here by accident.

So write to us instead, and write like a person. Tell us what you keep track of, and what keeps going wrong. That is a far better first message than any form, and it is what every deployment so far actually started as.

Talk to us

legal@binari.digital

You will get a reply from a person who has read it, and it will be a question rather than a brochure.