READY-TO-DEPLOY PRODUCTS

On-shelf products,
engineered by DevAgent

Platform-grade software you can switch on today, at predictable cost and timeline — and extend to fit your organization whenever you need.

CLOUD CMMS PLATFORM

MAINTEPRO CMMS

Maintenance, made simple.

A cloud-based CMMS built for factories, facilities, and field teams in Thailand — plan preventive maintenance, dispatch work orders, track assets and spare parts, and close every job with compliance-grade e-signatures. Web and mobile, even offline.

16+Operations modulesTH / ENFully bilingual100%Offline-capable mobile24/7Automated PM engine

Every maintenance workflow, in one place

Work Orders

Create, assign, and schedule jobs with checklists and photo evidence

Preventive Maintenance

Recurring PM schedules generate work orders automatically

Assets & Equipment

Full asset register with a QR code on every asset

Spare Parts Inventory

Parts catalog with min/reorder thresholds that flag low stock

Tools & Calibration

Tool inventory with inspection and condition-check workflows

Borrow & Return

Check-out / check-in workflow for shared tools

Inspections

Reusable inspection templates for walkdowns and audits

Incidents & Safety

Incident logging with a mandatory Job Safety Analysis gate

Chemicals Register

Track chemicals and hazardous materials across facilities

Vendors & Contractors

Supplier directory plus a dedicated contractor portal

Stores & Warehouses

Manage stock across multiple storerooms and locations

Dashboards & Reports

KPI dashboards and PM compliance reports — PDF and Excel export

Built to go further than a checklist app

AI that writes the report for you

An in-app AI assistant answers questions about work orders, assets, and inventory, with AI-written weekly/monthly summaries — self-hostable, so data never leaves your infrastructure.

Compliance-grade e-signatures

Multi-stage sign-off with SHA-256 cryptographic signatures modeled on CFR 21 Part 11, plus a full audit trail and print-ready documents.

Offline-first mobile app

Technicians keep working with zero signal — jobs, checklists, photos, and signatures store locally and sync automatically.

Truly bilingual, Thai-first

Every screen, document, and email report in Thai and English — each user picks their own language.

Deployment:Cloud SaaSOn-PremiseEnterprise SSO (OAuth/OIDC)Full audit logging & data governance
Request a live demo

A 30-minute walkthrough with your own asset scenarios — in Thai or English.

PROCUREMENT MANAGEMENT SYSTEM

REQUEST FOR PURCHASE

Every purchase, one governed lifecycle.

An enterprise procurement workflow platform that takes purchase requisitions from draft to close-out — technical review, budget approval, procurement, receiving & QC, and refund handling — in a single auditable workflow. Everyone always knows what's next and who owns it. In production today.

16Workflow statuses, state-machine enforced7Roles with scoped permissions46+REST endpoints, OpenAPI documented100%Of actions audit-logged

The lifecycle, from draft to done

DraftTechnical ReviewBudget ReviewProcurementReceiving & QCClaim / RefundCompleted

Non-technical purchases skip straight to budget review; failed QC branches into claim replacement or refund — every branch stays inside the same traceable lifecycle.

Governance the workflow engine enforces

High-value — full PR/PO rigor

Item-level technical approval scoped to each approver's discipline, budget-holder sign-off before any money moves, and PO, payment, and delivery tracking end to end.

Low-value — a fast lane that keeps governance

Corporate card, expense claim, or direct purchase with proof attached — through the same receiving and QC gate, every step still audit-logged.

Nothing bypasses approval

The state machine enforces it — not policy documents. Budget review can't start until every technical item clears, and every transition writes the audit trail.

QC gates refunds; one currency of record

Claims start only from incoming QC after goods arrive. Multi-currency entry with snapshot rates — every screen and approval computes in THB.

Everything the procurement team touches

My Tasks Action Feed

A role-aware feed of exactly what each person can act on now, mirrored into a daily email digest

Dashboards & Queues

KPI cards and dedicated queues per stage, plus an AI-assisted procurement analysis tile

Notifications Everywhere

In-app notification center with automatic email mirroring and deep links back to the PR

Enterprise SSO

FusionAuth OIDC SSO with role- and discipline-based permission checks on every endpoint

Attachments & PDF Forms

Quotes, POs, receipts, and QC reports in object storage, with the approved PR form rendered to PDF

Delegation & Reroute

Approvers can delegate; admins can reroute a stuck PR and roll it back with full history

Master Data Admin

Users, projects, vendors, corporate cards, currencies, and rules managed in-app with Excel import/export

Jira Integration

High-value purchases auto-open linked Jira issues at PO and goods-received milestones

Vendor Evaluation

Every completed purchase closes with a vendor evaluation, building a real performance record

Under the hood:Vue 3 + VitePython Flask APIPostgreSQLMinIOFusionAuth SSODocker ComposeOpenAPI 3Self-hosted on your infrastructure
Request a walkthrough

See the production system in action — and how the workflow adapts to your organization's procurement process.

ZERO-TRUST SSH ACCESS

SSH CA PORTAL

Access that expires. An audit trail that doesn't.

Replace long-lived SSH keys with short-lived certificates signed by your internal CA and bound to a verified corporate identity. Developers help themselves from the web or CLI; administrators stop signing keys by hand — with every request on the record.

4 hDefault cert lifetime0Standing keys to revoke100%Requests audited2Clients — web & CLI

From login to logged-in, in under a minute

Sign in with SSOSubmit public keyCA signs (+4h)SSH straight in

No tickets, no waiting on an administrator — when the certificate expires, request again. Validated end-to-end with FusionAuth SSO.

Security by design — architectural, not procedural

The CA private key never touches the app

Mounted read-only from your secret manager at runtime — never in the repository, never uploadable, never visible in the UI.

Certificate lifetime is operator-only

Set in deployment configuration (4 hours by default) — no client, web or CLI, can request a longer-lived credential.

Identity comes from the token, not the form

The certificate's key ID is taken from the verified SSO token, so every certificate is attributable to a real person.

No standing keys to hunt down

Servers trust one CA public key. Offboarding never means hunting authorized_keys across servers — certificates die on their own within the workday.

One portal, everything around the certificate

Web Portal

Request a certificate, copy or download it in one click, and browse your own request history

sshca CLI

A standalone Rust binary for Linux, macOS, and Windows — one command handles login, signing, and file placement

Host Registry

Admins register hosts once; the CLI syncs them into each developer's SSH config, Cloudflare tunnels included

Audit Log

Timestamp, identity, IP, principal, and outcome for every issuance — searchable, streamed as structured JSON

Your IdP In Charge

Authentication delegated to FusionAuth over OIDC — disable the account and access ends with the current certificate

Server Onboarding

A generated installer fetches the CA key, configures sshd, and hardens a new host in minutes

Under the hood:React PortalRust CLIPython FastAPIFusionAuth OIDCOpenSSH CertificatesDocker Compose + NginxSelf-hosted — keys never leave your infra
Talk about zero-trust SSH

Deployed in an afternoon: generate a CA key pair, point it at your IdP, and bring it up with Docker Compose.

ENTERPRISE LLM GATEWAY & COST CONTROLLER

LLM GATEWAY

The on-premise cost controller for AWS Bedrock.

A self-hosted Bedrock proxy that gives every developer a personal Claude API key — while finance keeps a hard, real-time cap on the AWS bill. Every prompt, trace, and token stays inside your perimeter.

HTTP 429The instant a budget is hit24–48 hAWS billing lag you stop gambling on100%On-prem — data never leaves1 CommitPricing & catalog changes via GitOps

One gateway between your developers and Bedrock

Developer / IDE (SSO)Budget Gate — LiteLLMAWS Bedrock

Every request passes the budget gate before it ever reaches AWS — with Langfuse tracing every token and a self-service portal for keys and budgets.

The only option that is both on-prem and preventative

Stops spend in real time

AWS reports spend 24–48 hours late — a runaway agent loop can burn a month's budget before the first alert. This gateway blocks at the source the instant a cap is hit.

100% of data stays on-prem

Prompts, responses, and logs never leave your data center — unlike SaaS gateways, where data exits your perimeter and per-call fees stack up.

Personal keys, not shared AWS credentials

Every developer gets their own key bound to SSO identity — suspend, rotate, and audit per person, while real AWS credentials exist only at the gateway.

Ready in days, not months

Assembling LiteLLM, SSO, observability, and a portal yourself takes 2–3 engineer-months — this ships as one tested stack, deployed with Docker Compose.

Built for finance, security, and developers at once

Real-time Cost Control

Quota checked on every request at the proxy — overruns return HTTP 429 instantly, with per-user budgets plus a global cap

Identity & Access

OIDC SSO into Azure AD / Google Workspace, auto-provisioning on first login, keys hashed at rest and shown once

Model Catalog

Bedrock Claude out of the box plus on-premise models via llama.cpp, with role-based model exposure

Observability

Langfuse v3 bundled — full per-call traces for tokens, latency, cost, and user attribution on an isolated database

Developer Experience

OpenAI-compatible API — drop-in for any SDK, LangChain, or LlamaIndex, with documented IDE configs

Operations & Compliance

GitOps-native: pricing and catalog changes ship in one commit, secrets stay out of git, vendor telemetry disabled

Under the hood:LiteLLMLangfuse v3FusionAuth SSONext.js PortalPostgreSQL + ClickHouseDocker Compose / GitOpsAir-gapped option
Book a technical deep-dive

See it stop a runaway loop live, or start a 2-week pilot on your own infrastructure — we deploy it with you.