EU-first · your data, your model

Describe it.
Agents build it.
You approve it.

Scrum4Us builds and maintains your software with AI agents — on a scrum board you control. Every change arrives as a verified pull request, every agent turn is metered in the ledger, and your agents can run on your organization's own AI account.

Now in private pilot — room for five organizations to build along for free.

Webshop — The Corner Bakerysprint 2026-07

Backlog

ST-014Discount codes at checkout
ST-015Holiday opening hours

Agent working

ST-013Email order as PDF receiptagent writing code

Done

ST-012Photo upload for custom cakesPR #12 — awaiting your approval
usage todaymodel · tokens · cost
ST-013 · turn 4claude-sonnet-5 · 18,240 · $0.11
ST-012 · reviewgpt-5.6-sol · 9,812 · $0.06
budget July$14.20 / $50.00 · cap active

How it works

Three steps, and you stay in control throughout

No prompt roulette: Scrum4Us works the way a good team works. Work lives on a board, nothing ships without your approval, and everything is traceable afterwards.

  1. 1

    Put your idea on the board

    Write your idea as a story — plain language is enough. Pick it for the sprint and dispatch an agent; it works the story task by task, updating the board as it goes.

  2. 2

    Agents build

    Every story becomes code in an isolated, throwaway sandbox that can reach your repository, the model gateway and the platform's own job API — nothing else. The result arrives as a pull request with an explanation, never straight into your product.

  3. 3

    You approve

    You review the pull request and merge it — nothing merges without you. The board rolls along automatically, and the ledger shows what the work cost — per turn, per user, per model.

Built-in skepticism

We don't take an agent's word for it — so you never have to

Three mechanisms keep you from having to trust an agent's output.

Isolated sandboxes

Every build job runs in its own disposable container with deny-by-default network access: it reaches your repository, the model gateway and the platform's own job API — nothing else. Discarded after the run.

Verified delivery

The platform checks every delivered pull request server-side — right repository, right branch, a real diff at the reported commit. An agent cannot claim work it didn't do.

Adversarial AI review

Plans and documents that agents write can be sent through adversarial review rounds — independent AI reviewers, deliberately drawn from two different model families, leaving a durable review record.

Beyond building

Your own agents on your organization's knowledge

Next to the build copilot, you define agents for your daily work: a stated purpose, instructions, a model policy and the knowledge they may use. Every employee can make them personal — within the boundaries you set.

Protocol assistant

Purpose: answer questions with citations from your protocols.

Answers always come with the source attached, from documents you manage yourselves. If the protocols don't cover it, it says so — no improvised policy.

source citationshonest when unsure

Onboarding assistant

Purpose: get new colleagues productive from your own handbook.

Grounded in the documents you publish — house rules, how-tos, architecture notes. New hires ask; the agent answers with the source attached, in your organization's own vocabulary.

your handbook as knowledgepersonal per user

Knowledge base

Upload a document, get cited answers

Protocols, manuals, decisions — uploaded once, shared with the whole organization, and quotable by every agent you allow.

  1. 1

    Upload

    Add text or markdown documents to a collection. Indexing happens inside the upload itself: the moment it completes, the document is searchable. No queue, no processing spinner.

  2. 2

    Found two ways

    Questions search your documents by exact wording and by meaning, and both rankings are fused — so the right paragraph surfaces whether you use the document's words or your own.

  3. 3

    Answered with sources

    Agents answer with the documents they used attached as citations. When nothing relevant exists, they say exactly that instead of improvising.

One base, scoped per agentCollections are shared org-wide; each agent sees only the collections you bind to it.
Publish once, teach every agentDocuments you author in Scrum4Us can feed the same knowledge base when published — no second store to keep in sync.
Withdraw instantlyArchive a published Scrum4Us document or turn off its knowledge flag and it becomes uncitable immediately — retrieval excludes it fail-closed.
Indexed in-houseSemantic indexing runs on our own EU infrastructure. Your documents are never sent to an external embedding provider.

You set the dials

Configuration you own, visible in the interface

What an agent may do, what it may know, what it may cost and whose account it runs on are settings your admins manage — not a consultancy project.

Bring your own AI account

Register your organization's own Anthropic or OpenAI key. Turns served on it are billed by your provider — the ledger records them with real token counts and zero platform cost. Keys are encrypted at rest; a test button proves the connection.

Fallback is your call

Per agent, you decide whether the platform may step in when your provider fails. Off means off: a clean error in the chat, never a silent switch to our models — verified in production.

Model & effort per job

Dispatch any job with an explicit model or capability tier, plus an effort level from LOW to MAX. The choice is recorded in the ledger next to what it cost.

Budgets that refuse politely

A monthly cap for the organization, optional caps per user. A turn that would breach the cap is refused with a clear error before the money is spent.

Agents as settings

Name, purpose, instructions, model policy, knowledge bindings, on or off — creating an agent is form-filling, not a development project.

Personal, in safe order

Every employee can add personal instructions to any agent. Platform guardrails and your organization's rules always win — the merge order is enforced by the platform, not by convention.

Privacy without asterisks

Here, GDPR is architecture — not an appendix

Built in the EU for organizations that must account for their data. Below is what is engineered in today — the roadmap says what comes next, and we don't blur the line.

Purpose binding per agentEvery agent carries a mandatory one-sentence purpose, visible to everyone who uses it. Purpose limitation as a required form field, not a policy PDF.
Private by constructionConversations are scoped to the individual user at the database layer. Colleagues can't read them — and neither can admins. There is no override switch.
Retention is automaticA per-organization retention term drives an automatic deletion sweep: expired chat history is deleted, not archived.
Export & erasure built inPer-user export and erasure are platform API operations. Erasure is one atomic, audited transaction — a person's conversations disappear while the books stay correct.
EU infrastructureApplication, database and AI gateway run in the Netherlands; the web layer is served from Frankfurt. Semantic document indexing runs on our own hardware.
A ledger, not a black boxEvery agent turn is metered — who, which model or endpoint, how many tokens, and what the platform billed. Financial history stays audit-safe even through erasure: the amounts survive while the link to the erased conversations is severed.

Honest footnote: chat content is processed by the AI provider an agent is configured for — the platform's models or your organization's own Anthropic or OpenAI account. Admin screens for the processing register and self-serve export are on the roadmap; the APIs beneath them are already live.

Where we're going

The roadmap, in the open

Built in this order, each step behind a live verification gate before we call it done. No dates — we'd rather be honest than optimistic.

Self-hosted & local models

Design approved

Point Scrum4Us at your own model endpoint — vLLM, Ollama, TGI — behind a fail-closed egress contract. The design has been adversarially reviewed; the build is not yet scheduled.

Email & photo channels

Planned

Mail a document to an agent, or photograph a receipt and have it staged as an expense entry — input beyond the web interface.

Embedded copilot & public API

Planned

Your agents inside your own application, with delegated identity for your users, plus a system-to-system API.

On-site packaging

Planned

The full platform as an installable bundle on your premises or in your cloud — web layer included, with a proper update story.

Privacy self-service

Planned

A processing-register view for your admins and self-serve export & erasure screens — on top of the APIs that exist today.

Pricing

Fixed per user, transparent AI usage on top

Introductory pricing during the pilot phase. AI usage on platform models is billed at cost plus a fixed, visible margin — with a budget cap you set yourself.

Pro

€49 / user / month
  • Scrum board + build copilot
  • Every change as a verified pull request
  • Usage ledger per user
  • Budget caps that refuse, not surprise
Join the waitlist

Business

€99 / user / month
  • Everything in Pro
  • Custom agents + knowledge base
  • Bring your own AI account (Anthropic / OpenAI)
  • Model & effort control per job
  • Personal agent profiles
Join the waitlist

On-site · roadmap

Let's talk
  • Full installation on your premises
  • Local language model possible
  • DPIA & register support
  • Shaped together with launch customers
Book a call

Become a design partner? The first five organizations use Scrum4Us free for six months, in exchange for weekly feedback and a case study.

Apply with your organization

Prices excl. VAT. AI usage on platform models: cost + 25% platform margin, visible in the ledger in real time. Turns on your own AI account are billed by your provider, not by us.

Frequently asked questions

Honest answers

Does code go live without me seeing it?

No. Agents work in an isolated sandbox and deliver every change as a pull request that the platform verifies server-side. Merging is a human act — there is no auto-merge path in the product. That is a property of the architecture, not a setting.

What happens to the data in conversations?

Conversations are scoped to the individual user under database row-level security, expire automatically under your organization's retention term, and can be exported or erased per user through the platform API. Which AI provider processes them is your configuration: platform models, or your organization's own Anthropic or OpenAI account — with fallback off, there is never a silent switch.

Can I process health or patient data with this?

Not yet. The foundations are in place (purpose binding, retention, private-by-construction conversations), but we take that step together with a customer, after a proper DPIA. We'd rather promise less than too much.

What if my AI budget runs out?

Then platform-billed usage stops — new agent turns are refused with a clear error until you raise the cap. Turns on your organization's own AI account with platform fallback off are billed by your provider and don't touch the platform cap; enable fallback and they count against it, since they may land on a platform model. No surprises on the invoice either way.

Am I locked in?

No. Your code lives in your own Git repository and is always yours. Knowledge documents are plain text and markdown you keep the originals of, and per-user conversation export is built into the API. Cancel monthly.

Build along as a design partner

Five seats. Six months free. Your way of working shapes the product.

Apply with your organization