Code-grounded plans, independently reviewed.
Corvi reads your real repo and writes the plan — cited, reviewed, costed before you run, then carried through execute, self-review, and the PR.
Writing code got cheap. Reviewing it didn't.

No invented APIs.
Every claim points at a path and line in your repo. If Corvi didn't read it, it doesn't assert it.

The model that drafts doesn't grade itself.
A different model reviews the draft and a third reconciles them — so one model's blind spots don't ship.

Priced before you run, not after.
Every pass estimated and totaled up front, then reconciled against what it actually cost.

The plan doesn't stop at a doc.
Execute it in an isolated worktree, and a different model reviews the diff against the plan — then Corvi opens the PR with a plan-tied description. The plan is the contract; every stage proves it was honored.

Local-first by default
Private unless you say otherwise.
- Code and plans stay on your machine.
- Every network call is audited.
- Your keys, your models — nothing relayed.

Multi-model engine
Different models draft, review, and synthesize.
Cross-model self-review
A different model grades the diff against your plan. The one that wrote it doesn't grade it.
Open the PR
Ship a pull request with a plan-tied description and conformance readout.
Plan types
Feature, bugfix, refactor, migration — each its own shape.
MCP + skills
Opt-in tools, every call egress-gated.
Re-grounding
Citations re-checked against the current repo.

