The Key Leaker
Hides live secrets in the client bundle.
Spine is the enterprise backend OS your AI agents can't break. 20 platform modules out of the box — plus guardrails that fail the build the moment an agent takes a shortcut.
AGENT VS. BUILD
starring SpineThat arcade machine is a cartoon of the real thing. Spine ships ArchUnit boundary tests inside the platform. When an agent crosses a boundary, ProductBoundaryTest fails the build — the agent reads the failure, self-corrects and follows the enterprise pattern.
PLAYER 1 · AGENT.EXE · LEVEL 1 > quest: let users upload a profile photo > shortcut spotted. grabbing it… + import com.grahmur.platform.modules.files.internal.s3.S3StorageProvider; $ ./mvnw test ✕ ProductBoundaryTest FAILED · product_consumes_only_platform_contracts ✕ BUILD FAILURE > reading the error… new strategy - import com.grahmur.platform.modules.files.internal.s3.S3StorageProvider; + import com.grahmur.platform.modules.files.api.FileStorage; $ ./mvnw test ✓ BUILD SUCCESS · guardrails green · +1000 XP
PLAYER 1 · AGENT.EXE · LEVEL 2 > quest: load the signed-in user’s account > shortcut spotted: read the account collection + import com.grahmur.platform.modules.identity.persistence.IdentityAccountMongoRepository; $ ./mvnw test ✕ ProductBoundaryTest FAILED · product_consumes_only_platform_contracts ✕ BUILD FAILURE > reading the error… new strategy - import com.grahmur.platform.modules.identity.persistence.IdentityAccountMongoRepository; + import com.grahmur.platform.modules.authentication.api.AuthenticatedPrincipal; $ ./mvnw test ✓ BUILD SUCCESS · guardrails green · +1000 XP
PLAYER 1 · AGENT.EXE · LEVEL 3 > quest: summarize support tickets with an LLM > shortcut spotted: grab the orchestrator directly + import com.grahmur.platform.modules.llm.internal.LlmOrchestratorService; $ ./mvnw test ✕ ProductBoundaryTest FAILED · product_consumes_only_platform_contracts ✕ BUILD FAILURE > reading the error… new strategy - import com.grahmur.platform.modules.llm.internal.LlmOrchestratorService; + import com.grahmur.platform.modules.llm.api.LlmService; $ ./mvnw test ✓ BUILD SUCCESS · failover unlocked · +1000 XP
Spawned by coding agents optimizing for the demo instead of enterprise longevity. Each one is an instant fail in a vendor security review.
Hides live secrets in the client bundle.
Builds SQL by concatenating user input.
Serves every customer everyone’s data.
Writes bearer tokens to production logs.
Squeezes every upload through app memory.
No grinding. Every module is pre-built and covered by 700+ automated tests. Six of the load-bearing ones:
Opaque, deployment-bound sessions; provider-verified credentials; exact runtime-context authorization with direct permission grants.
Presigned uploads and downloads — clients go straight to the cloud, zero bytes through your backend.
Platform state runs on PostgreSQL, MongoDB-compatible stores or Firestore — you pick with one setting. Your own domain data can live in any database.
Multi-provider model routing with free-tier failover chains and paid tiers on your own cloud credits.
Idempotent delivery with provider adapters and product-owned templates, including approved WhatsApp templates.
Fail-closed audit: if the event can’t be written, the operation doesn’t proceed. Secrets and tokens are filtered from audit data.
Spine provides controls that support HIPAA, SOC 2 and GDPR programs (fail-closed audit, secret scrubbing, deployment-bound sessions). It is compliance-ready, not certified: using Spine does not by itself make a product compliant, and your organization remains responsible for its own compliance.
FULL INVENTORY · 20/20 UNLOCKED
Whether you write Spring Boot in-process or build your product API in Next.js or Express with the typed Node.js SDK, Spine OS is the unbending infrastructure core underneath.
| Language / framework | Integration model | Status |
|---|---|---|
| TypeScript / Node.jsNext.js · Express · Fastify · Bun | Official typed SDK@grahmur-org/spine-client on npm (Apache-2.0, zero dependencies). Covers authentication, permissions, audit, notifications, host/brand resolution and bootstrap. Express and Next.js middleware included. | SHIPPED |
| Java / JVMSpring Boot 3 | In-process modules, starters & BOMMaven artifacts com.grahmur:grahmur-platform-* with all 20 modules. Depend on the umbrella, a lean starter, or individual modules. | SHIPPED |
| Python · Go · anything with HTTPFastAPI · Django · Gin · … | REST + webhook APIsThe platform exposes versioned HTTP endpoints (/api/v1/*) and delivery webhooks. No official SDK yet; call it like any JSON API. | REST ONLY |
The SDK connects to a Spine engine service that you run in your own cloud over HTTP. A prebuilt engine container image is not published yet, and the SDK does not cover files, LLM routing or payments today.
Never migrate your database to fit a backend. Point Spine OS at the PostgreSQL, MongoDB or Firestore you already run. It manages its own platform_* tables and leaves your business tables untouched.
| Engine | Services | Why builders care |
|---|---|---|
| PostgreSQLRelational / SQL | 29 platform_* tables via plain JDBC: no JPA or Hibernate. Keep using Prisma, Drizzle, Kysely or JPA for your own tables in the same database. | |
| MongoDBDocument / NoSQL | Flexible documents, optimistic-locking revisions, and the managed clusters you already run. | |
| Cloud FirestoreServerless NoSQL | Serverless scale with a dependency-free JDK client; no MongoDB cluster required. |
Select the engine with platform.persistence.type (postgres, mongo or firestore). Spine creates its platform_* tables on first boot, which you can turn off. Named services are common targets for standard PostgreSQL and MongoDB, not per-provider certifications.
Direct-to-cloud presigned uploads and downloads
Multi-provider routing with failover chains
Queued delivery with retries and provider adapters
A strict in-process modular architecture. Your product can only travel through api. There are no warp pipes into internal or persistence.
Domain logic. Any database — PostgreSQL via JPA included.
YOU ARE HERE ▶The only door into the platform.
✓ OPENSealed. No warp pipes.
✕ LOCKEDPostgreSQL · MongoDB · Firestore. Sealed.
✕ LOCKEDA plain-language architecture overview, the boundary model, the security controls and where responsibility sits, on one page you can forward or save as a PDF.
Rebuilding the backend yourself costs 4–8 months and $100k+ in payroll. Or buy it once. No subscriptions. Source-available, debug symbols intact.
US dollars $499
ONE COIN · ONE TIMEUS dollars $1,999
UNLIMITED CONTINUESOne-time price per license. Terms are set by the Commercial License Agreement from GRAHMUR OÜ. Buying for a security review or a team? Read the architecture & security summary.
Straight answers, including what Spine does not do. More detail for security reviewers is on the architecture & security page.
Spine OS is a commercial, source-available Java 17 / Spring Boot 3.5 backend platform, with an open-source TypeScript client for Node.js teams. It ships 20 ready-made modules (identity, authentication, authorization, files, LLM orchestration, notifications, audit, payments and more) plus an ArchUnit test, ProductBoundaryTest, that fails the build when product code reaches into platform internals.
ProductBoundaryTest runs with ./mvnw test. It fails if product code depends on platform internal or persistence packages or on Spring Data. That stops an AI agent from bypassing the public api contracts. It does not review your business logic or scan for every insecure pattern; secret handling, audit and session security come from the platform modules you call, not from this one test.
Spine provides controls that support HIPAA, SOC 2 and GDPR programs (fail-closed audit, secret scrubbing, deployment-bound sessions). It is compliance-ready, not certified: using Spine does not by itself make a product compliant, and your organization remains responsible for its own compliance. Have your own auditor or counsel validate your deployment.
Yes. You get the Spine starter repository (application wiring, product adapters, AI rule files such as AGENTS.md) as source. The platform core is delivered as versioned Maven artifacts with line numbers and debugging symbols intact and no obfuscation, so you and your AI agent can step through it. Redistribution is limited by the commercial license.
Platform state (sessions, audit events, notification deliveries and so on) runs on PostgreSQL, MongoDB-compatible stores (Atlas, AWS DocumentDB, Azure Cosmos DB Mongo API) or Google Firestore, selected with platform.persistence.type. Your own product data is independent: use any database and any ORM, and its tables are never touched because platform tables are prefixed platform_.
Yes, for the capabilities the client covers. The open-source @grahmur-org/spine-client SDK (Apache-2.0) gives Next.js, Express and other Node apps typed access to authentication, permissions, audit, notifications and host/brand resolution. It talks over HTTP to a Spine engine service that you run; a prebuilt container image is not published yet. Files, LLM routing and payments are not in the SDK today.
Yes. Add the dependency to your existing pom.xml; the modules auto-configure through standard Spring Boot auto-configuration, so no scanBasePackages changes are needed, and platform tables are prefixed platform_ so they do not collide with yours. You can also depend on individual modules or on the leaner starters.
Founder / Startup ($499, one-time): one production application and one year of platform releases, provider adapters, security updates and documentation. Agency / Studio ($1,999, one-time): unlimited client projects, white-labeling permitted, same one year of updates. The full terms are in the Commercial License Agreement from GRAHMUR OÜ.