Business teams build. You govern.

Shadow IT exists because teams no longer wait for the roadmap. Open them a frame you validate once: accounts, two-factor authentication, roles, per-project isolation, hosting in France, DPA, exportable code.

foundation validated once, applied to every tool
1foundation validated once, applied to every tool
data hosting (Scaleway), backups included
Parisdata hosting (Scaleway), backups included
proprietary formats: readable, exportable JavaScript
0proprietary formats: readable, exportable JavaScript
Data map
Your situation

Banning doesn't work anymore. Framing does.

Every IT department knows the inventory: shared spreadsheets holding customer data, SaaS subscribed by credit card with no processing agreement, access never revoked when a colleague leaves, and a six-month IT project for every need that comes up. Shadow IT isn't a discipline problem: it's the rational response of teams that have a need now and a saturated roadmap.

Banning moves the problem without solving it, and consumer no-code tools often make it worse: quick to adopt, but with no access governance, no controlled hosting, no reversibility. AI code generators add a new risk: code nobody has reviewed, foundations reinvented for every project, secrets in the browser.

Kubbler offers a frame rather than a ban. The foundation is written and operated by engineers, identical for every tool: accounts and enforceable two-factor authentication, roles and organisations, per-project isolation (database, secrets, domain), hosting in Paris, backups, security headers, DPA. The AI doesn't touch it; it interprets the business need to assemble the application layer within it. You validate the frame once, you keep visibility and reversibility, and business teams move forward.

HostingBackend in Paris (Scaleway), frontend on Cloudflare's edge, automatic backups
ComplianceDPA (GDPR article 28) provided, compliant usage analytics
SecurityEnforceable 2FA, roles, quotas, anti-fraud, CSP, per-environment encrypted secrets
ReversibilityReadable JavaScript code, exportable to GitHub at any time

Ban, endure, or frame.

What shadow IT costs when left alone, and what it becomes on a governed foundation.

Today
Dozensof unregistered tools, with data inside
Shared spreadsheets holding customer data
SaaS subscribed by credit card, with no DPA or review
Access never revoked when a colleague leaves
AI-generated code nobody reviewed, with secrets inside
A six-month IT project for every need that comes up
With Kubbler
A frameset once, inside which business teams move on their own
One shared foundation: accounts, enforceable 2FA, roles, per-project isolation
Data in Paris, encrypted secrets, backups, DPA provided
The AI assembles the business layer; the foundations are written by engineers
Exportable, readable code: no imposed dependency, full reversibility
Start there

What you validate once.

Governance isn't a brake when it lives in the foundation rather than in a process. Here is what applies to every tool built, without having to ask again.

01

The frame

What applies to every tool built, without having to ask again.

Organisations & roles

One space per organisation, one role per member, traced invitations, access that leaves with the colleague.

Security

Enforceable 2FA, quotas, anti-fraud, security headers (CSP), systematic validation: set for everyone, once.

Secrets

End-to-end encrypted vault, per environment, injected at deploy time. Never in the browser.

Customer accounts
02

Control

What lets you say yes without fearing tomorrow.

Isolation

Each tool its own database, secrets, domain, backups. No leaks between projects.

Hosting

Backend in Paris (Scaleway), frontend on Cloudflare's edge, automatic backups, a test version before release.

Reversibility

Code exportable at any time, readable, conventional JavaScript, DPA provided. No proprietary format.

Brand identity
03

What you can build with it.

Three cases where "no" is no longer tenable, and where a frame beats a ban.

Internal tools built by business teams themselves

On a foundation you validated once: accounts, two-factor authentication, roles, per-team isolation, backups. What would have ended up in a spreadsheet ends up in a governed tool.

A partner or supplier portal

External access partitioned per organisation, data hosted in France, end-to-end encrypted secrets, logging. Open to the outside without opening the information system.

Shadow IT brought back onto a shared foundation

The spreadsheets and small tools lying around everywhere, put back on a base you govern: registered, isolated, backed up, reversible. Without a six-month project for each.

Dashboard

How it works, concretely.

Four steps, three actors: you set the frame, the AI interprets the business need, and the engineers who wrote the foundation answer for it.

01You

You open a frame

One workspace per organisation, roles per member, two-factor authentication enforced if you wish, centralised billing. You validate the foundation once, not every tool.

02The AI

The AI interprets

Teams describe their need; the AI translates it into screens, fields and access rights, from existing blocks. It works strictly within the application layer, never within the foundation.

03The engineers

The foundation carries

Authentication, roles, per-project isolation, encrypted secrets, security headers, quotas, anti-fraud, hosting in Paris, backups: written, reviewed and operated by engineers, fixed for every tool at once.

04You

You keep visibility

You see the projects, the members, the access. You can audit, export the code, revoke an access. Business teams publish their tools; you govern the frame in which they do it.

Our approachHumans structure. AI interprets.Read our approach

Why Kubbler, for an IT department.

Four reasons that answer the criteria you apply to every tool: compliance, security, reversibility, risk control.

Compliance lives in the foundation

Data hosted in Paris, DPA compliant with GDPR article 28, consent-respecting usage analytics, automatic backups, logging. You don't validate every tool: you validate a frame that applies to all of them, and that is documented.

The AI doesn't touch the foundations

It's the new risk of code generators, and the one Kubbler is designed to rule out: the AI interprets the business need and assembles the application layer; authentication, payments, security, data and deployment are written, reviewed and operated by engineers, identical for everyone.

A team of engineers answers for the foundation

The foundation is fixed and extended for every project at the same time; a vulnerability fixed for one is fixed for all, with no action from business teams. You have a contact, support, and (on the Team plan) an availability commitment.

Reversibility is total

Every tool's code belongs to your organisation and exports at any time to GitHub, in readable, conventional JavaScript, with its data model. No proprietary format, no imposed dependency: you can take any tool back in-house whenever you decide.

The questions we get asked.

Precise answers, because decisions are made on facts, not on promises.

Frame instead of banning.

Free during the beta. Open a space for a pilot team, set the frame, and watch what they build inside it, then audit the code.