Skip to content
    StaidKit
    PlatformArchitectureComplianceDesign partnersStart a conversation
    Contact

    Design partner programme

    Five design partners before general availability.

    The industry uses “design partner” loosely, usually for an unpaid pilot of something already decided. Here it has a narrow meaning: five named companies whose operational reality sets the scope of the first release, who see decisions while those decisions can still change.

    They pay nothing in the first year. In exchange they give us design feedback with real operational context, and a public reference when we reach general availability. Both halves of that are written down below.

    Start a conversationdesign-partners@staidkit.com
    Partners
    5, before general availability
    Mix
    2 financial services, 2 health technology, 1 critical infrastructure
    Fee
    None in the first year
    In return
    Design feedback, and a public reference at GA
    Stage
    Pre-GA. Three of four foundations unbuilt.

    The count and the mix are a product decision, not a sales device. Spec §12.2, decision ledger D12.

    Who it is for

    Read both columns before you write to us.

    This programme is narrow on purpose. Five partners cannot represent every kind of operator, so we picked the kind whose evidence problem the product is being built around. If you are in the right column, saying so early costs you nothing and saves us both a quarter.

    This is built for you if

    • You are a regulated operator between roughly $200M and $5B in revenue: financial services, health technology, or a critical-infrastructure platform.
    • A named executive owns this. A CISO or equivalent with budget authority and the standing to sign, not a working group evaluating tools in the background.
    • A 2026 or 2027 deadline is forcing the work: a DORA audit, the EU AI Act's high-risk rules, NIS2, a HIPAA Security Rule audit, or another SOC 2 Type II cycle.
    • You run PagerDuty, Opsgenie or something like them, and your audit evidence is assembled by hand out of a compliance tool, spreadsheets and screenshots.
    • You can put real operational context in front of us: actual incidents, actual evidence requests, and the people who actually carry the pager.

    Spec §12.1, decision ledger D3 and D12

    This is not for you if

    • You need software to deploy this quarter. Most of what makes StaidKit different is still being built.
    • You are pre-revenue, or well below $200M. The product is being built to the operational and audit load of a company at the scale above and will not fit you well.
    • You are air-gapped only. That is not supported and is not planned before v2.
    • Nobody senior owns the problem. A partnership carried by one enthusiastic engineer stalls the first time priorities move.
    • You want a vendor rather than a counterparty. Partners get asked to argue with us about scope and to tell us when something we built is wrong.

    What a partner gets

    Standing in the build, not a discount.

    1. No fee in the first year

      You pay nothing for the first year of the agreement. Year two is a commercial conversation, held later, with a working product to judge rather than a promise.

      Spec §12.2

    2. Influence over the first release, in the open

      Sequencing decisions get made with partners in the room. When a partner tells us the order is wrong, changing it is the normal outcome, not an escalation.

    3. The build shaped around the evidence you produce

      The controls we automate first, the export formats, and the fields the ledger carries come from what your assessor actually asks you for.

      Spec §6.5

    4. Each capability as it lands

      Access as things become usable rather than at a launch, with the same build status language used everywhere on this site. The ledger comes first, because everything else depends on it.

      Spec §9

    What we ask in return

    Two things, and they are not small.

    The first year has no fee because these two obligations are the payment. They belong in the agreement, so they are stated here in the words we would use in it.

    1. Design feedback, with real operational context

      A working session most weeks, with the people who run incidents and the person who answers the assessor. Sanitised feedback from a sponsor who has not carried a pager in five years is no use to us, and we will say so.

    2. A public reference at general availability

      At GA you go on the record: your company named, a person named, and cooperation on a written case study. That is the consideration for the free first year, and it goes in the agreement rather than being hoped for later. If you cannot be named publicly, say so in the first conversation and we will not take it further.

    A partner who cannot commit to either one is still welcome to talk to us. They are just not a design partner, and we will not pretend otherwise to keep the conversation going.

    What you should know first

    What a partner would be signing up to.

    This belongs here rather than in a footnote. A partner who discovers any of it in month four is worse for us than one who reads it now and declines.

    Three of the four foundations are not built

    Eleven backend services run today, covering incidents, telemetry, prediction, assets and compliance control models. That is the foundation. The parts that make the product different from what you already run are designs:

    • Cryptographic action ledgerSpecified
    • Typed runbook languageSpecified
    • Scribe and remediation agentsSpecified

    Verified against the repository, not the specification

    There are no other customers

    You would be among the first five. There is no reference customer to call, no user community, and no accumulated operational pattern to inherit. The people you would work with are the people building it.

    StaidKit holds no certifications

    No SOC 2 report, no ISO 27001 certificate, no HIPAA attestation for StaidKit itself. Your vendor review will find that, so you should hear it here. The first audit is part of the road to general availability. What exists today is the control model inside the product, which is a different thing from a certificate for the company.

    You would be shaping something, not deploying it

    A design partner agreement is not a deployment plan for this quarter. If your deadline needs production software now, take that seriously and decline. We will tell you the same thing if we hear it on the first call.

    How the ledger, the graph and the runbook language are designed to fit together

    How it starts

    One working call, and no demo in it.

    The first conversation covers five things:

    1. What you have to prove, to whom, and by when.
    2. How evidence gets assembled today, and who does it by hand.
    3. What you run on-call with, and what breaks about it during a real incident.
    4. Which control set is worth building first, and what would make it usable by your assessor.
    5. What would make you walk away. We would rather find that now than in month four.

    Write to us and say who you are, what is forcing the work, and the deadline. The link below prefills those questions in a draft. We read and answer these ourselves, and if you are not a fit we will say so in the reply rather than book a call to find out.

    Start a conversationdesign-partners@staidkit.com

    Five places. When they are filled, this page will say so.

    StaidKit

    Incident response and on-call for regulated enterprises, built so that running operations produces the evidence an audit asks for.

    Product

    • Platform
    • Architecture
    • Compliance

    Company

    • Design partners
    • Contact

    © 2026 StaidKit

    Pre-general-availability. Recruiting design partners.