Skip to content

Framework Philosophy

Small enough to read end-to-end. Real enough that several live products already run on it.

Built for a Coding Agent to Extend

The conventions here — the data layer, the auth system, the notification pattern, the multi-app routing — are documented specifically so a coding agent (Claude Code, or any other) can read them once and reuse them, rather than inventing a new one-off stack for every new app.

That only works if the conventions are actually worth reusing. A parameterized query builder, hardened session handling with a dated public fix history, and a real inter-app API aren't aspirational — they're what's already there.

What It Actually Gives You

▣ A Real Data Layer

A fluent query builder that's parameterized by construction, plus a lightweight Active Record ORM with real multi-database context switching.

🔒 A Documented Security History

Hardened sessions, AES-256-GCM encryption, login throttling, CSRF — and a dated log of specific vulnerabilities found and fixed, not a marketing claim.

🔗 Multi-App, Actually

Several apps can share one login and session under a single install, and call each other directly over a built-in API — not a hypothetical, it's running in production today.

🔍 Small Enough to Audit

No package ecosystem to trust blindly, no DI container hiding what calls what. What you can't see isn't there — you can read the whole thing.

What's Deliberately Not Here

Being honest about trade-offs is part of the pitch, not a footnote:


Want to see it work?

The reference implementation renders this framework's own integration guide — code and docs together, not a separate pitch.

Explore the Reference App