Mirepoix brings AI-assisted understanding, porting, review, and validation into customer-controlled infrastructure. Its sovereign runtime profile requires a loopback model provider, workspace-confined tools, denied tool egress, and a replayable JSONL record. Host firewall, IAM, and deployment evidence remain independently reviewable.
Teams often have to choose between conventional tooling inside a controlled environment and hosted AI outside it. Mirepoix is designed to close that gap with local-model port assistance, multi-agent review, equivalence validation, and evidence from both the runtime and its deployment.
Modernization is delivered by partners with deep engineering experience and existing customer relationships. The work happens with the tooling the market has had — which has not, until now, included AI assistance that can operate inside the customer's perimeter.
Mirepoix runs in customer-controlled infrastructure. Your engineers or delivery partner operate the engagement, with the model provider constrained to loopback and tool access constrained by the declared runtime profile.
Mirepoix can run the modernization pipeline with a locally served model in customer-controlled infrastructure. Under the sovereign runtime profile, model traffic is restricted to loopback, file writes stay inside the workspace, and tool network access is denied. Outputs remain reviewable and validation compares the port with the legacy behavior.
Architecture graph, dependency-ordered tour, and per-module summaries built from the source in the controlled workspace.
Generate the modernized port to the target language (Rust, Go, modern C++, TypeScript) following the dependency tour.
Two independent reviewer agents adjudicate each port. Hallucinations and integration errors are caught before they ship.
Generated test suites compare modernized code against legacy behavior. Numerical equivalence is measured to an explicit tolerance where applicable.
JSONL event records capture agent, tool, review, and validation activity for replay and investigation.
Mirepoix makes bounded claims about the controls it enforces. The harness can fail closed on model routing and tool access. The deployment can separately collect evidence for firewall, IAM, and service configuration. Current GPU deployments do not produce Intel TDX or AMD SEV-SNP hardware-attestation quotes.
A reusable harness, modernization packages, and operating runbooks that can be evaluated in a bounded pilot.
The current validated posture uses a GCP GPU VM and a local model. Other platforms require their own deployment qualification.
Choose and operate an open-weight code model locally. In sovereign mode, Mirepoix refuses non-loopback provider URLs and redirects.
Runbooks, acceptance gates, and explicit responsibility boundaries make the operating posture reviewable.
Delivery partners bring customer relationships and engineering capacity. Mirepoix supplies a local-first harness for AI-assisted understanding, porting, review, and equivalence validation, with runtime controls that can be inspected before an engagement begins.
The partner operates Mirepoix inside customer-controlled infrastructure under the customer's security and authorization process. Model selection, network policy, operator access, and acceptance criteria remain explicit deployment decisions.
This structure is intended for organizations evaluating whether local AI assistance can fit their controlled-development workflow. Any regulatory, contractual, or authorization claim must be assessed for the specific customer deployment.
Mirepoix's founding engagement is a Python-to-Rust modernization using a locally served model on a GCP A100 host with a deny-all public-egress posture. Repository tests exercise runtime confinement and equivalence behavior. These results do not establish hardware attestation, regulatory compliance, or universal performance.
The validation package supports explicit absolute and relative tolerances; an internal Kirk-precursor pattern compared numerical output to about ten decimal places.
Focused tests cover sovereign configuration, loopback model routing, redirect refusal, process-sandbox startup checks, and workspace confinement.
The full repository test run passes with zero failures, alongside package type checks, formatting checks, and ADR consistency checks.
Bring a bounded legacy module and its expected behavior. We can demonstrate codebase mapping, a modernization pass, multi-agent review, equivalence validation, and the runtime evidence produced along the way.