Skip to content
Hlebourg

Hlebourg FZCO · Dubai

Agent-native software for work that cannot be improvised

Three lines of operational software for the places an organisation loses its own trail — documents after they leave your perimeter, strain that never reaches a survey, and work done where the network is not. Every one of the 9 products runs in infrastructure you control and ships an MCP server, so an agent can operate it without a bespoke integration.

Products
9
Across three lines, each deployed into its own environment.
Agent tools
70
Never more than 8 on any one server, and you should not install them all.
Default deployment
Yours
Self-hosted, air-gapped included, at the same price as anything else.

The through-line

Three places where the record stops

These lines look unrelated until you ask the same question of each: where does this organisation stop being able to account for what happened?

A file shared legitimately with eleven people is controlled for the three months of a transaction and uncontrolled for the decade afterwards. A person's workload is legible in a resignation letter and in almost nothing that precedes it. A commitment made on a vessel, a site or a ward exists on paper until somebody has signal again, and the reconciliation is done by memory.

Each of those is a gap between what happened and what the organisation can later demonstrate happened. They are not adjacent markets. They are the same failure in three different departments, and each one is usually sold a product that measures the part that was already visible.

Agents make all three worse and faster. An assistant that fetches a document, writes a summary and sends it has crossed the perimeter three times in a second; an engineer whose working pattern changed because twenty agents now run in parallel is invisible to an annual survey; a field tool that queues work offline now queues an agent's work too. Speed is not the problem. The absence of a trail is.

What follows from that

  • The record is the product. Every one of these keeps an append-only trail that we expose no way to edit — including to ourselves.
  • It has to work where you are. Self-hosted by default, offline where the work is offline, and readable by software that is not ours.
  • An agent's action is a person's action. Every call an agent makes is attributable to the human whose authority it borrowed, with the policy that allowed it recorded alongside.
  • What it will not do is written down. Refusing a capability is a design decision with a stated reason, not a roadmap item we are quiet about.

Three lines

What each one is for

A line is a deployment boundary rather than a marketing group: products inside one share an environment, a store and one agent access profile. A product from the next line knows nothing about the first unless you deliberately connect them.

Confidential document control

Nocturne

Most leaks are not break-ins. A file is shared legitimately with eleven people, and one of them forwards it. Perimeter tooling stops the first case and is blind to the second.

Who buys it
Legal, corporate finance, deal advisory, IP-heavy engineering
Products
Nocturne Vault · Nocturne Trace · Nocturne Entropy

Encryption, per-recipient tracing and key material for documents that leave your perimeter and must not be untraceable when they do. Built for the files that a DLP product never sees, because they were sent deliberately.

Workforce sustainability

Cadence

Attrition is visible in the resignation letter and in almost nothing that precedes it. Annual engagement surveys report on a quarter that has already been paid for.

Who buys it
People operations, engineering leadership, occupational health
Products
Cadence Signal · Cadence Pulse · Cadence Ledger

Burnout screening, team pulse and personal capacity tracking that measure a person against their own baseline instead of a company average. Designed so that the number a manager sees is one the employee has already seen.

Offline-first operations

Harbour

Operations software assumes constant connectivity and a head office. Warehouses, sites, clinics and vessels do not have either, and the spreadsheet that fills the gap is never reconciled.

Who buys it
Operations, trade and distribution, field and site services
Products
Harbour Registry · Harbour Flow · Harbour Watch

A counterparty registry, an order and demand engine, and an obligation follow-up system that keep working with the network cable pulled out. State lives on the machine; synchronisation is something you choose, not something you depend on.

Start here

One product from each line

The rest of the catalogue is a click away; these three are where most evaluations begin.

Controlled distribution you own, opened in an ordinary browser

Vault is a document room that does not expire when the transaction does. Policy is written against attributes rather than named people, external parties read in an ordinary browser with nothing installed, and the price is published and flat — no per-page metering, no storage overage, no extension fee.

MCP server
hlebourg-vault
From
€1,200 / month, rooms unlimited

Burnout screening measured against a person's own baseline

Signal combines short self-report instruments with work-pattern telemetry from your AI gateway to detect sustained drift in how a person works — compared with how that same person worked three months ago, not with a company average. It never reads message content and never infers emotion.

MCP server
hlebourg-signal
From
€6 per employee / month

Offline sync for business records, where every merge rule is declared

Registry is a record store for work orders, inspections, stock counts and approvals on devices that spend real time disconnected. The merge rule for every field is declared up front, enforced by the server and readable afterwards — and where no rule describes what happened, Registry quarantines the record rather than inventing an answer.

MCP server
hlebourg-registry
From
€7 per device / month, 25-device floor

Agent interface

One interface, and an honest account of its limit

Every product speaks the Model Context Protocol. That is the easy half of the claim, and it is the half everybody makes.

The hard half is what a vendor does with it once it works. An agent calls a tool under the authority of the person who authorised it, never a service account with a superset of everyone's rights — and every call lands in the audit record with both identities, the policy that allowed it, and the model request it came from. "The agent did it" is not a state any of these products can be in.

The other half nobody prints is the ceiling. Agent judgement degrades as you add tools, so across 70 of ours no single server exposes more than 8. You install two or three, not the catalogue, and during an evaluation we will say which of ours you should leave out.

Three kinds of tool

read
Returns data, changes nothing. The worst case is that an agent learns something its operator was already entitled to know.
write
Changes state inside the product. Granted per tool, and every call names both the human and the agent.
act
Has an effect outside the product — sends, exports, notifies. Off by default everywhere, enabled only against a written policy.

What is different here

Four positions, each checkable before you talk to us

Every one of these costs us something real — a discovery call we cannot run, a capability we cannot claim, a renewal we cannot hold. They are on the website rather than in a proposal because that is what makes them worth anything.

  1. 01

    The price is on the website

    Every product has a published price, one meter, and the minimum printed underneath — including where that minimum means we are telling you that you are too small to buy. Almost nothing in these categories publishes a rate card, and what comparable buyers actually pay differs by a factor of seven.

    Read the prices →

  2. 02

    Every product has a section listing what it cannot do

    Not caveats at the bottom of a datasheet — a required field in the schema these pages are built from, so a product page that does not state its limits fails the build rather than shipping vague. Some of those limits are capabilities we are refusing on purpose, and we say which.

    See the catalogue →

  3. 03

    The exit costs nothing and we will rehearse it

    Full history in a documented format, the question library that makes it comparable, a standalone decryptor for anything encrypted — free during the contract and after it, on any anniversary you ask. A renewal conversation held with your own history as collateral is not an honest one.

    Read the exit terms →

  4. 04

    We will design the study that could show we do not work

    Pre-registered, randomised at the organisational unit, run by an evaluator you contract and pay directly, with the outcome measure fixed before the data exists. The strongest evidence against this whole category — 46,336 workers across 233 organisations — deserves an answer better than a case study.

    How the evaluation works →

Ninety days, one team, a criterion agreed before we install anything

The pilot is €9,000, runs on your infrastructure with your data, and is credited in full against the first year if you continue. If the criterion is not met we say so in the report, and that is the end of it — there is no clause that turns a failed pilot into a subscription.

Hlebourg FZCO is a licensed software design and systems consultancy in Dubai. Software is contracted from there; deployment happens wherever your infrastructure already is.