How we build, in the open.
Engineering and design notes from the studio. System design and the stack we reach for, how we wire AI agents into a build, the performance and accessibility work, and the design decisions behind the interface. Specifics over slogans, written by the team that ships it.
How we built a repeatable DPDPA engineering audit
How a 49-check DPDPA skill turns legal duties into repeatable, evidence-backed engineering work.
Read →How we ran a 5MB semantic search model in the browser
On-device semantic search: type a question, get back meaning-ranked results in milliseconds. No server involved.
Read →Who builds GattyWorks: senior designers, engineers, and AI agents
How is that even possible with that few people? Here is who is actually behind GattyWorks, and what they built before.
Read →Google uses click data in Search. That does not make CTR a shortcut
Google's trial exhibits confirm that click data informs Search rankings. Here is what Navboost proves, what one famous SEO test does not, and how we audit titles.
Read →Using AI tools without technical skills: lessons from daily work
Ten stories shipped in a day, three walls hit: what our non-engineer learned using AI tools daily.
Read →Vendure checkout audit: eight order states, six payment states, and hidden bugs
Vendure publishes its order and payment state machines. We use them as the yardstick when auditing a checkout.
Read →How we fixed AI crawler access on a Cloudflare site
A 5/100 agent-readiness scan exposed Cloudflare Bot Fight Mode and three missing discovery pages on GattyWorks.
Read →What is a software audit? Scope, evidence, and timing
What a professional software audit checks, what evidence it needs, and when to use one before buying, accepting, or renewing software.
Read →Software audit cost in 2026: scope, pricing, and what to expect
GattyWorks software audit prices, cost drivers, scope differences, and a practical way to compare audit quotes.
Read →How to audit a SaaS vendor: security, backups, and continuity
A practical SaaS vendor audit covering security claims, account ownership, backups, data flows, AI permissions, and exit readiness.
Read →Jan Aushadhi Dost: building a client-side medicine search
We shipped Jan Aushadhi Dost, a mobile-first search over India's public Jan Aushadhi medicine catalogue. The engineering notes: a fuzzy-search bug that returned an antidepressant for ORS, a no-dose linter for AI content, and a Turnstile widget that died on navigation.
Read →TTFX Rust rewrite: TerminalTextEffects byte-level parity
The 9.6x claim is already stale. The repo tells a better story about agent-built software.
Read →Metrics design system: an eye mark, Poppins, and Arimo
One PR, one identity: Metrics' own icon, its own palette, and a typeface that is not gattyworks.com's.
Read →How we built first-party analytics you own
The architecture of analytics we fully own, and the anti-bot stack we shipped this week.
Read →How we made AI agents write in simplified technical English
One rule, 19 repos, 8 PRs. Why agent replies now follow the aerospace ASD-STE100 spec, with before and after examples.
Read →How we reported a critical login bug without publishing exploit details
Nobody paid us to audit this site. We found a critical login bug anyway, and chose not to explain how.
Read →Cloudflare free-tier audit: two quotas we were already exceeding
Five domains, twelve Workers, one audit. Two Cloudflare quotas were already on fire and we did not know.
Read →CommonCrawl: how the web archive trains LLMs
Most LLMs were trained on this. It's free, public, and sitting in an S3 bucket anyone can pull from.
Read →Review Relay: building a policy-aware Google review workflow
One GattyWorks tenant, a reusable client intake, and no model call behind the review drafts.
Read →Web Audio UI sounds: testing five feedback sound families
We tested 30 generated click sounds, chose Warm Pulse, removed hover audio, and gave email its own motif.
Read →Why GattyWorks became an AI and software audit studio
Three audit tiers, public prices, and one test: can the buyer prove what the vendor or AI system does?
Read →How BitChat works: Bluetooth mesh, Noise, Nostr, and Radicle
Inside BitChat's BLE flood control, Noise sessions, courier mail, Nostr fallback, and failure modes.
Read →How we built a local social publishing dashboard with SQLite
Inside GattyWorks' local social desk: SQLite state, live checks, human gates, and no scheduler.
Read →Astryx AI-agent manifest: a machine-readable design-system contract
AI agents hallucinate props from prose docs. Astryx fixes that, and it is a pattern worth stealing.
Read →P2P text sharing with WebRTC: a one-time secret without server storage
Paste text, get a link, it travels browser to browser over WebRTC. Here is what our relay is and is not allowed to see.
Read →Rate limiting a Cloudflare Worker: abuse controls for a WebRTC relay
Our signaling relay was unauthenticated on purpose. Here is what we shipped once we thought through what that actually exposes.
Read →How to evaluate LLM judges against expert reviewers
An LLM judge that spits out a score is not the same as one you can trust. Here is how you tell the difference.
Read →Prompt injection audit: protecting AI agents from GitHub issue attacks
An attacker leaked private repos with plain English in a public issue. We used it as a checklist against our own agents.
Read →LocalSend review: open-source peer-to-peer file sharing
Send a file across the room without touching a cloud server in between. Free, open source, cross-platform.
Read →How we added client-side search to a static Next.js site
Fuzzy search across every tool, post, and story, running entirely in the browser with zero backend.
Read →selfhost.directory review: 2,500 self-hosted software alternatives
Self-hosted alternatives to the SaaS tools you are renting, organized by category, license, and version.
Read →Search relevance evaluation: why full post bodies barely improved the score
We built an eval harness for our own search and ran it. The number that mattered most was smaller than we expected.
Read →FckSignups: 174 open-source tools with no account required
174 open-source, no-signup tools in one directory, built by one person for free. Here is why we back it.
Read →DPDPA for Indian software: personal data and AI systems
AI features widen how much personal data an Indian build touches. The DPDP Act and final Rules turn that into phased engineering work.
Read →Anytype review: why the local-first app became too restrictive
We moved to Anytype for local-first notes and said so. The rigid object model boxed us in, so we went looking again.
Read →CC Switch: manage configuration for multiple AI coding CLIs
One window for every AI CLI's config, instead of editing dotfiles by hand. We recommend it, with one honest catch.
Read →Notion vs Anytype: moving past Notion's 1,000-block limit
Add a second person to a free Notion workspace and you hit a 1,000 block wall that deleting cannot undo. Here is our fix.
Read →Instant Domain Search: domains, generators, and aftermarket prices
The domain tool we keep open on every scope call. Live availability as you type, no forced checkout, no upsell maze.
Read →GattyWorks in 2026: SEO, tools, and product spinouts
Our plan for gattyworks.com: ship small useful tools, make them findable, and spin out the ones that get real traction.
Read →How we built a live website brand kit
Brand assets go missing exactly when you need them. So ours live on a public page, not a locked folder, one click away.
Read →Cookbooks, playbooks, and the tools we ship.
We publish the notes we use internally. Email is the only channel. No tracking pixel, no list rental. One note when something new is live.
hello@gattyworks.com