Deployment intelligence

See what breaks before you deploy.

Whatbreaks maps your repositories, services, pipelines and environments into one knowledge graph, keeps the evidence behind every relationship, and runs deterministic preflight rules over a release’s blast radius.

  • Evidence on every relationship
  • Reproducible results
  • Honest about coverage

Reads from the tools you already run

  • GitHub
  • GitHub Enterprise
  • GitLab
  • Jenkins
  • Azure DevOps
  • Any HTTP-capable pipeline
  • AWS
  • Microsoft Azure
  • Google Cloud

A green pipeline can still ship a broken release. Production configuration that quietly points at a dev service is easy to miss in review. Whatbreaks finds it before you deploy.

How it works

From a file in your repository to a finding in your pipeline.

  1. 1

    Declare

    Each repository describes what it builds and what it depends on, per environment, in a versioned metadata.yml.

  2. 2

    Publish

    Connect GitHub or GitLab. Whatbreaks reads the file at an exact commit, validates it with located errors, and publishes it into the catalog.

  3. 3

    Preflight

    A pipeline step sends the commit it is about to deploy. Whatbreaks analyses it against the pinned catalog and returns findings, each with its evidence.

What you get

Answers you can trace, from a graph you can trust.

The blast radius, drawn

Walk forward through dependencies and along change-propagation paths, then see every service a release can touch highlighted on the topology.

Evidence on every relationship

Each edge keeps its source: the file, the line, the commit and a confidence score. Open a finding and see exactly why it was raised.

Reproducible by construction

An exact-commit analysis is a pure function of its pinned input. The same input gives a byte-identical result, and a saved analysis stays explainable after its evidence ages out.

Honest about coverage

Coverage is complete, partial or insufficient. When evidence is missing, the answer is unknown, never a falsely reassuring low.

Wired into your pipeline

A pipeline step posts the commit to a webhook; the analysis runs as a job and lands in Runs. Templates for Jenkins and Azure DevOps are included.

A canvas for cloud inventory

Upload an AWS, Azure or Google Cloud export and explore every resource, grouped and linked. Kept apart from deployment analysis, so it never skews a finding.

Built for teams

Shared by everyone who ships, separated where it matters.

Organizations and roles

Owner, admin, member and viewer, with invitations by email.

Scoped API tokens

Read, ingest, analyze and manage-integrations scopes, never more than their creator holds.

Isolated by the database

PostgreSQL row-level security keeps each organization's data apart.

An audit log

Who changed what and when, with credentials never recorded.

Bounded by design

Every analysis has limits, and says when it reaches one.

Each analysis reads one read-only snapshot with hard limits. If a limit is hit, the result says so in its coverage, instead of quietly returning less.

levels of depth
6
relationships loaded
5,000
visits per analysis
2,000
to load the neighbourhood
2 s

Plain about its limits

What a result tells you, and what it never pretends to.

It tells you

  • Which declared dependencies cross from one environment into another.
  • What depends on the service you are about to change.
  • Which evidence is missing, stale or conflicting, kept apart from risk.

It does not claim

  • That a deployment is safe. A result describes declared topology only.
  • That a declaration matches what is running. A catalog entry is the owning repository's word, not runtime verification.
  • Anything about source code, API compatibility or runtime health.

Know the blast radius before your next deploy.

Create an account, connect a repository and run your first preflight.