Start a pilot

CI/CD delivery orchestration

The system of record for your software delivery.

Your pipelines push the events. Yontrack pulls the context. Builds, quality, dependencies and deployments in one model — without replacing any of your tools.

Track. Trust. Deliver.

Release candidate

Is payments-api 4.7.2 ready?

  • payments-api 4.7.2GOLD
  • ledger-core 2.14.0GOLD
  • auth-sdk 9.1.3BRONZE
  • crypto-utils 1.8.1SCAN FAILED
The top of the stack looks shippable. Four levels down, it isn't.

Why now

Delivery changed shape. Three things got harder.

CI 4m12sscan 17tickets 23?commitproduction

Measurement

Your tools measure themselves

Every CI tool measures its own jobs. Nothing measures how long a change takes to reach production — unless someone builds that, and keeps it working.

JenkinsGitHubJiraSonarQubeScansArtifactory???

Scattered evidence

Lost in the tools

Every tool holds part of the evidence. Seeing the whole picture means opening all of them — and the release waits while someone does.

commita7f3c2eauthoragentchecked bytestssafe to ship?

Agents in the loop

Agents make the change

AI agents produce change faster than people can review it — and version control records who committed, not what decided.

Three symptoms, one cause: the evidence of delivery is produced everywhere and kept nowhere.

What you get

One record. Every question it answers.

Visibility

One page answers the release question.

A green service on top of an unvalidated library is visible, not assumed.

A release and its dependency chain, each component with the level it reached: petclinic-ui 2.0.4 at BRONZE, petclinic 1.4.4 and common-library 3.2.1 at SILVER.
Readiness
Every candidate version, every check that ran against it, and the level it has reached.
Provenance
Which commit, which pipeline run, which environment, when — linked back to the source tool.
Change logs
What actually changed between two versions, generated from commits and tickets.
The whole chain
Your dependencies and the quality level each of them reached.

Trust

Quality stops being a matter of opinion.

An agent can open the pull request. It cannot grant itself GOLD.

Consistency
“Ready for production” is defined once, in code, and applied to every change — whoever or whatever authored it.
Evidence
Who promoted what, on which evidence — recorded as it happens, not reconstructed at audit time.
Agents, same gates
Agents read and write the record through the MCP server, and earn levels like everyone else.
Scans in the gate
A failed scan blocks a level instead of being discovered later.

Acceleration

The data pays for itself by removing the toil.

Defined with the code in .yontrack/ci.yaml, reviewed like the code.

Auto-versioning
A library reaches its quality level; every consuming repository receives a bump pull request.
Change logs
Release notes assembled from commits and tickets, across the dependency chain.
Promotions
Granted by rule rather than by someone remembering to click.
Hand-offs
The status update writes itself and lands in the channel that needs it.
Auto-versioning along the dependency graph: petclinic uses the latest build of common-library, and petclinic-ui is not using the latest build of petclinic yet.

Deployments

“What is running in staging right now?”

Deployments are first-class events: which version went where, when, who authorised it, and whether it succeeded.

Yontrack environments — which version of each project runs in staging and in production.
Inventory, rules and lifecycle — an environment can require a promotion level before a version is even eligible.

Who it's for

Different people, one record.

Release managers

Decide on live status instead of assembling it.

DevOps, SRE, platform

Feed data once with reusable pipeline steps, then drive automation across every project.

Engineers

One entry point for the state of their own work — no more manual promotions or version bumps.

Product & leadership

Answer “what's in this release, and is it ready?” without booking a status meeting.

AI agents

Read delivery status and record evidence through the MCP server. Same record, same gates.

A Yontrack dashboard: the promotions and checks of each branch, the versions deployed per environment, the last active projects and the lead time to GOLD on main of petclinic.

In production

“With Yontrack, we moved from scattered snapshots to end-to-end automation and traceability. Manual version bumps are gone, and every development build now produces its own uniquely versioned artifact.”

Pavel Erofeev, Principal Software Engineer, Vyntra
  • Vyntra
  • CluePoints

In production at scale-ups and corporate enterprises in fintech, data and pharma — some for more than ten years — tracking thousands of projects and millions of validation runs.

How it works

Your pipelines push the events. Yontrack pulls the context.

Yontrack joins your CI/CD ecosystem rather than replacing any part of it. No migration, no rewrite of pipelines. Your CI and your tools stay exactly as they are.

Push

From your pipelines

Builds, validations and promotions — through a Jenkins shared library, a GitHub Action, or one CLI call per pipeline stage.

  • Jenkins · GitHub Actions · GitLab · Bitbucket
  • Tests, SonarQube, security scans

The record

One model over all of it

Builds · validations · promotions · dependencies · deployments — queryable, shareable, automatable.

  • Pull: commits, branches, pull requests and tickets from GitHub, GitLab, Bitbucket and Jira

Out

What comes back

  • Release views and change logs
  • Version bump pull requests
  • Notifications and workflows
  • Deployments
  • Metrics to Grafana

First project reporting in an afternoon.

The core idea

A promotion is a word your whole organisation agrees on.

What gets said today

“Yes — X passed its long integration tests, the security scan came back clean, and I think the perf run was fine?”

What gets said instead

“X is SILVER.”

Your levels, your meanings. Each level is earned automatically when the checks behind it pass — defined once, versioned with the code, identical across every team.

BRONZESILVERGOLD

The Yontrack builds page — every build on a branch with its promotions and validations.
Every build on a branch — one row per build, one column per check.

The word is also a trigger.

A promotion is a real event in the delivery graph, so it can start things. This is where a status board becomes an orchestration layer.

On promotion

Version bumps

Downstream repositories get a pull request raising the dependency.

On promotion

Notifications

Slack, email, Jira — and Jenkins jobs or GitHub workflows, called the same way.

On promotion

Deployments

Only versions at the required level become eligible for an environment.

On promotion

Workflows

Sequences chaining approvals, jobs and notifications together.

Security findings

Every CVE, followed on every branch.

Yontrack records the findings of the scans your pipelines already run, and follows each of them over time: when it appeared, where it is still exposed, when it was fixed.

The findings of petclinic-billing open on release-2.3, each with its scanner and the branches it is exposed on: a high CVE in spring-webmvc on release-2.3 only, a CodeQL insecure cookie and a commons-io CVE on main too.
Your scanners, unchanged
Trivy, CodeQL, Semgrep, ZAP — sent as SARIF, Trivy JSON or a neutral format. Yontrack doesn't scan; it keeps the record.
Per branch
Fixed on main, still shipping on release-2.3? You see it before the release, not after.
Fixed, not bumped
A package bump that leaves the CVE in place is not a fix. The finding stays open.
Acceptances where they live
Ignore files, VEX documents and SARIF suppressions are read, shown with their expiry, and reopened when they lapse.
In the gate
Thresholds by severity turn a scan into a validation: a new CRITICAL blocks the promotion.
One search
Type a CVE and see every project and branch where it is exposed or accepted.

Delivery scorecard

Delivery measures, straight from the record.

Yontrack reads its own history. Every day, every project gets its readings — and Yontrack says plainly when it cannot tell.

A project's scorecard: each reading with its sample count, met or missed against the targets of the estates the project belongs to.
DORA-style measures
Lead time, deployment frequency, success rate and time to restore — plus test pass rate and flakiness.
Derived, never pushed
Nothing to send beyond what your pipelines already send. No extra instrumentation, no other tool.
Estates
Group projects by label and read them against shared targets: met or missed.
Explainable
Every number opens the builds that made it, with its sample count beside it.
Unknown is not bad
A reading Yontrack cannot measure says why — never a zero, never red.
Out to your stack
Readings and any pipeline number export to InfluxDB, Elasticsearch and Grafana.

For the people who will run it

Easy to set up. Yours to run.

Licence & support

Open core

MIT-licensed core, free to try. At scale, a commercial product — licence, support, consultancy and training from the team that builds it.

Runtime

Runs in your cluster

Self-hosted by design. A Helm chart installs it on Kubernetes or OpenShift, with PostgreSQL, Elasticsearch and RabbitMQ.

Interfaces

API-first, agent-ready

GraphQL API, open-source CLI, webhooks and configuration as code — plus an MCP server and AI skills.

Governance

Enterprise auth

OIDC and LDAP, group mappings, granular project roles and API tokens for automation accounts.

How teams get there

Value at each step — not only at the end.

  1. Collect

    Add reporting to one pipeline. Builds, tests and scans start landing in one place.

  2. Visualise

    Release readiness becomes a page instead of a conversation.

  3. Agree

    Define the promotion levels your organisation will share, and put them in code.

  4. Automate

    Let those levels drive versioning, notifications and deployments across every project.

Start with a pilot.

One team, one dependency chain, one release cycle — enough to measure the before and after honestly.

Services

From the team that builds it.

Training

Hands-on, in groups or one-on-one, in your workplace.

Support

Day-to-day help, and a say in what gets built next.

Keynotes

Our vision of delivery, shaped by years in the field.