SeewhatyourPRactuallytouches
AridNova reconstructs your microservice dependency map from source code — surfacing blast radius, coverage gaps, and authorization policy drift on every pull request. No agents. No instrumentation.
The pattern
Recognize this?
A change looks contained. It passes review. It ships.
Two hours later, a service three teams away breaks — and nobody can say why, because nobody could see the connection before it shipped.
Could your team name every service a change might affect, before it merges?
If an auditor asked what changed, what it could have affected, and what was tested — how long would that take to assemble?
Was your last cross-service incident a technology failure, or a visibility failure?
AridNova surfaces that structure before it becomes a postmortem.
How it works
From PR to production,
nothing is hidden
AridNova runs inside your existing CI pipeline — no agents, no runtime access. Here's what happens when a developer opens a pull request.
A developer opens a pull request
Your pipeline already runs unit tests and style checks; that tells you the code is correct in isolation. It says nothing about what else it might break across your other services.
The whitespace
The gap between your code and your production
SonarQube checks your code. Datadog monitors your production. AridNova tells you what your change will do to the system — before it ships.
Pre-deploy, system-level. What your change does to the whole system, before it merges.
Post-deploy, system-level. Tells you what is happening now — after it shipped.
Pre-deploy, repo-level. Correct code in isolation, one repository at a time.
Post-deploy, repo-level. The exception, after a user already hit it.
We don't replace Datadog or SonarQube — we fill the gap between them. No rip-and-replace, no migration.
The evidence
Your prescribed architecture on paper vs. your actual architecture in production
Before / after
Release confidence stops being a feeling. It becomes a fact.
- Review depends on who's in the room and what they happen to know.
- Blast radius is guessed. Coverage is reported at repo level — cross-service gaps invisible.
- Audit prep: 100+ hours of manual archaeology per cycle.
- Post-incident: 4–18 hours of diagnosis, 2–3 teams, executive escalation.
- Blast radius surfaces automatically — which services, which endpoints, which tests are missing.
- Review is structural, not tribal. Any engineer can assess the change safely.
- Audit prep: continuous evidence per release — minutes to export, not weeks.
- The incident that would have happened doesn't. Caught in the PR.
Compliance & audit
Evidence that controls are operating and evolving, not just defined.
Existing tools help you write policies. AridNova helps verify they're being enforced — consistently, across every service, at every release.
A first-time SOC 2 audit consumes 100–300+ hours of internal engineering time — most of it tracing what changed, what it affected, and what was tested.
Source: Thoropass
AridNova runs on every pull request and release review — so what ships is provably consistent with what was assessed, not just what was documented.
Built on research
Built by the researchers who defined this problem — not discovered by a startup.
Grounded in peer-reviewed microservices research from the University of Arizona, with a publication and citation record spanning years of work on exactly this problem.
Seven patent filings cover architecture reconstruction, change-impact analysis, test-coverage intelligence, and authorization verification.
Built by the researchers who defined this problem, working alongside engineers who've lived it in production.
Use cases
Built for the people who own the system.
Platform engineers managing independent-deploy teams have no reliable way to know which downstream services a change will affect until something breaks. AridNova reconstructs the full dependency graph from your GitHub repositories and surfaces blast radius at the PR — so cross-service impact is visible before review is signed off, not after the incident post-mortem.
In regulated environments, it's not enough to write policies. Auditors want evidence they're being enforced consistently across every service at every deployment. AridNova detects authorization-policy drift from source code — no production access required — and generates an exportable evidence record of what was assessed, what changed, and who approved it.
AridNova generates focused authorization-aware endpoint test scenarios from the discovered architecture — scoped to the services a release actually touches — covering RBAC behaviors and targeted regression coverage across affected endpoints. QA teams move from evidence to executable validation without manual triage.
Contact
Talk to the team
We work directly with platform engineering, security, and QA leaders running Java-based microservices. Tell us about your environment and we'll set up a focused 30-minute technical conversation — no slides, no pitch deck.
team@aridnova.cloud
Based in
Tucson, Arizona