The numbers out of Ramp caught people's attention. More than half the code merges at the fintech company now come from an internal AI agent, not human engineers. That stat, buried in a Modal engineering blog post, crystallized something platform teams had been whispering about for months: autonomous coding agents aren't a science project anymore.
But there's a gap. Most companies aren't Ramp. They lack the resources to build what Ramp built—the sandboxes, the permission layers, the verification workflows that let an AI agent touch production code without everyone holding their breath.
Enter Proliferate, a Y Combinator startup that just made a calculated bet. On February 20, the Summer 2025 batch graduate released its entire codebase under an MIT license, wagering that enterprises want infrastructure they control when AI starts filing pull requests.
"You can use GitHub Copilot or Cursor," the company's positioning suggests, "or you can own the whole stack."
The Infrastructure No One Wants to Build Twice
Here's what background agents actually need to function in a real engineering organization: isolated execution environments that mirror production. Event triggers tied to Sentry exceptions, GitHub webhooks, or Linear tickets. Permission controls granular enough to satisfy security teams. Verification artifacts—diffs, preview links, audit trails—before anything ships.
Build that in-house and you're recreating tooling that probably already exists somewhere. Proliferate bundles it into a single self-hostable platform.
Each agent run spins up in its own Docker container. The system defaults to Modal or E2B for sandboxing, though companies can swap providers. Agents access internal tools through the Model Context Protocol, APIs, or webhooks—the same MCP connectors proliferating across the ecosystem.
Triggers work how you'd expect. A Sentry exception fires, the agent attempts to reproduce the bug, generates a fix, posts a preview link and draft PR to Slack. GitHub events, ticket updates, Slack commands—all become potential automation entry points.
What's less obvious: the verification layer. Before code merges, engineers get preview URLs, line-by-line diffs, and a full audit trail of what the agent touched. Review happens through a web dashboard, CLI, or directly in Slack. That collaborative handoff is where theory meets the reality of teams that won't merge blind.
The Permission Problem (and Why Schemas Matter)

Proliferate implements three action modes: allow automatically, require human approval, or deny outright. Organizations set defaults at the company level, then override per automation.
When an agent requests a restricted action, engineers review through the web interface or Slack. Standard stuff—except for one feature that hints at deeper concerns.
The platform watches MCP tool schemas for drift. If a connector's schema changes between reviews, permissions automatically downgrade until a human re-examines the integration. It's a direct response to supply chain anxieties that recent audits validated.
VirusTotal flagged roughly 8 percent of the 17,845 MCP server repositories it scanned as potentially malicious. That's the sort of stat that makes security teams nervous about plugging third-party connectors into codebases.
Proliferate ships with first-class integrations for GitHub, Linear, Sentry, and Slack. MCP extends that to PostHog, Stripe, Zapier, Supabase, Asana, Semgrep, Apify, Playwright—the usual SaaS pantheon. Custom MCP servers route through the same permission system.
Self-Hosting vs. Waiting for Cloud
Deployment runs through Docker Compose. Out of the box: Anthropic's models, Modal sandboxes, a GitHub App for private repo access, a Slackbot for Slack workflows. Documentation covers AWS, GCP, and Azure deployments.
The repository includes the agent runtime, dashboard, gateway, sandbox implementations—everything. Companies wanting managed hosting can join a waitlist for Proliferate Cloud, though pricing remains unpublished.
The technical stack won't surprise anyone: TypeScript, React, Python, Postgres, Redis, AWS. The team works in-person from SoMa.
Where the Market Is Moving

GitHub recently launched a Copilot coding agent with enterprise security controls and approval workflows before CI/CD. They also released Agent HQ for orchestrating multiple AI agents across the development lifecycle. Cursor added the ability to trigger background agents from Slack. DeepSource focuses autonomous agents on CVE triage and vulnerability remediation.
Open-source alternatives exist, though fragmented. Background Agents (formerly Open-Inspect) runs on Modal and Cloudflare Workers with multiplayer support. Adopt AI released an agent stack for production use. VibeKit wraps sandboxing and observability around coding agents.
None package the full infrastructure—triggers, sandboxes, permissions, verification—under one roof with an MIT license and self-hosting as the default path.
The Control Question

Platform engineers evaluating these tools face a specific calculation. How quickly do they need agents in production? How much control do they require over execution environments? Are they comfortable letting GitHub or Cursor operate inside their systems, or do they need to own the infrastructure?
Proliferate's positioning targets that last question directly. If you're not ready to hand external platforms the keys to production, self-hosting becomes the only real option.
The February 20 changelog marks the public launch. The repository is live on GitHub. Hard adoption metrics—deployed organizations, customer references—aren't published yet, which is typical for early releases. But the architecture mirrors what companies like Ramp built internally, suggesting product-market fit exists somewhere in the Fortune 500.
Whether enterprises adopt the self-hosted path or wait for the managed cloud offering will likely depend on procurement timelines and risk tolerance. Security teams move slowly. Engineering teams want to ship fast. Proliferate is betting those tensions create space for a third option between "build it yourself" and "trust a black box."
The codebase is out there now. What happens next depends on how many platform teams download it.
