Customer story · anonymized evaluator
Evaluator 25-Q3A representative regulated monorepo team consolidated overnight fix automation onto one audit-linked desk.
The Driftlock evaluator for 25-Q3 is a representative regulated monorepo team with a parent-bank auditor: one Rust-and-TypeScript monorepo, one GitHub App identity, one Bazel cache, one signed PR per overnight advisory. The team is eleven engineers across two time zones; the SBOM hash is the lockfile diff; the cosign key lives in the team's KMS. Names withheld because the index page is the public conversion surface — the founder rebadges against a real-evaluator readout once a customer signs off.
The three readout dimensions
What an evaluator looks like — repo shape, integrations, and the first signed overnight PR.
Each dimension carries a stated unit and a short detail. The time-to-first-PR figure is currently (projected)— the founder rebadges the figure against a real-evaluator hours readout once a customer audit completes.
Repo profile
~1.4M LOC monorepo
One Rust-and-TypeScript workspace, one protected main branch, one CI identity; roughly 80 PRs a week merged, of which about a third touch a dependency boundary the lockfile has to keep in sync.
Active integrations
3 live surfaces
GitHub App (one identity, one PR per advisory), SBOM diff (lockfile-cached so reruns reuse the team's own test evidence), audit log (per-PR row the reviewer replays from the run id, no Driftlock-managed control plane in the loop).
Time to first signed overnight PR
~36 hours (projected)
From "helm install driftlock" to the first signed, sandboxed overnight PR landing on a settlement-touching branch. Drawn from the planner-style projected readout the founder tracks before a real evaluators signs on; rebadge with a real hours figure once a customer audit completes (projected).
projected sample· match against your evaluator before quoting. Names withheld because the index page is the public conversion surface; the per-slug stories at /customers/[slug] carry the deeper narrative.
How the wiring lands
One Helm chart, four signal surfaces, one signed PR per overnight run.
Driftlock ships into the evaluator’s monorepo as a single Helm + Terraform deployment sitting behind the same egress policy as the settlement services. The watcher mounts four signal surfaces, the signing key lives in the customer’s KMS, and the sandbox mounts the monorepo’s Bazel cache so reruns reuse the team’s own test evidence. The rollout week ends with the auditor replaying one PR from the run id — same posture as the deeper story at /customers/acme-platform.
Team shape
Eleven engineers across two time zones; two staff engineers on rotation, the rest split across settlement, ledger, and partner API surfaces — no dedicated night-shift on-call.
Monorepo shape
One Rust-and-TypeScript monorepo, one protected main branch, one CI identity (a GitHub App), one Bazel cache. Roughly 80 PRs a week merged, of which around a third touch a dependency boundary.
Compliance shape
SOC 2 Type II in flight, with a parent-bank auditor. Seven per-PR fields (alert id, sandbox run hash, SBOM hash, approver chain, signature, diff bytes, triage verdict) on every settlement-touching PR.
What changed
Three numbers the platform team and the auditor both reach for.
Each number carries an explicit unit. The figures below mirror the deeper /customers/acme-platform read so a buyer cross-checking the index against the deeper story sees the same units and the same shape.
Engineer-hours reclaimed per overnight pass
5.6 hours / night
Mean reclaim when an overnight advisory lands on a senior engineer — Driftlock drafts the remediation, runs it in the sandbox, and opens a signed PR before shift starts.
Monorepo-upgrade window compressed to one overnight run
1 overnight run
Bazel, Rust, and TypeScript toolchain upgrades that used to land as a week-long sprint now land as one signed, audit-linked upgrade PR per release line.
Audit-trail compliance posture shift
96 % in one click
Of the regulator's quarterly evidence-pack questions replayed row-by-row from a run id — no Driftlock-managed control plane in the loop, no spreadsheet stitched after the fact.
In the engineer’s words
What the auditor stopped asking about.
“The first quarter we ran Driftlock, the auditor opened the run id, replayed the sandbox, diffed the SBOM, and asked one follow-up — about a test fixture, not the audit trail. Late-night triage stopped being the rule. The monorepo-upgrade sprint stopped costing a week of one engineer. The seven per-PR fields stopped being reauthored from memory.”
Platform team · Driftlock evaluator 25-Q3 · role-only attribution
Attributed — Senior Platform Engineer
illustrative placeholder attribution · rebadge with a named customer before launch
Run it on your monorepo
See the same audit trail on a stack you own.
Driftlock ships into your VPC, points at two of your existing watchlist surfaces for ten days, and signs every audit-linked PR with your cosign key in your KMS. The trial ends with a walkthrough of the same per-PR record the regulator replays here.