Reinvent your software

Your software never needed replacing.
It needed an operator.

You already bought the database, the API, the internal tools. They work. They just sit there waiting for somebody to click through them. Caterfli connects to what you own, learns what it can do, and hands it back as a colleague you can talk to. Nothing migrates. Nothing gets rebuilt.

records migrated, ever
0 records migrated, ever
checks before a write lands
6 checks before a write lands
afternoon to a working agent
1 afternoon to a working agent

production-db · PostgreSQL

connected

What your team can now ask for

  • customers read Answer questions about who bought what
  • orders read · create Raise an order without opening the admin
  • refunds create Issue one, with the reason written down
  • customers delete needs approval Only after a named person says yes

Nobody wrote an integration. Caterfli read the schema, worked out what each table affords, and drafted the agent for review.

Systems Caterfli connects to

  • PostgreSQL
  • MySQL
  • REST APIs
  • OpenAPI 3
  • MCP servers
  • Webhooks
  • Slack
  • Telegram
  • WhatsApp
  • Built-in toolkit

Two minutes

Watch a reinvention, start to finish

One system connected, the capabilities it turns into, the agent drafted from them — and a destructive request stopping dead for a person to decide.

0:00 / 1:55

Recorded from the running product — every screen in it is real.

Reinvention, not replacement

Nobody wants another system to migrate to

The last decade of software sold you the rewrite: export everything, retrain everyone, then find out in month nine what the old system quietly did for you. Caterfli runs the other way. Your systems stay exactly where they are and gain the one thing they never had — somebody to operate them.

Replace it

A project with a launch date

  • Months of migration before one person is better off
  • Retraining everybody on a tool that does less at first
  • The integrations you already had quietly stop working
  • A rollback plan nobody honestly believes in

Reinvent it

An afternoon, and then it compounds

  • Point it at one system and it is useful the same day
  • Your team already knows the data — now they can just ask
  • Everything you built keeps working, untouched
  • Disconnect it and you are exactly where you started

What actually happens

Three moves, and the software is a colleague

  1. 01

    Hand it a key

    One URL and one credential. The credential is encrypted before it is stored and decrypted only inside the connector, at the moment of a call.

  2. 02

    It reads the place

    Endpoints, tables, relationships, MCP tools — inspected and turned into described, schema-checked capabilities, each with a risk level attached.

  3. 03

    You review, then ask

    Caterfli drafts the agent: its purpose, its instructions, which capabilities it holds and which stop for a person. You approve it before anyone talks to it.

discovery · PostgreSQL

ready
  • list_customers read
  • list_orders read
  • create_refund create
  • update_order update
  • delete_customer delete Approval

Discovery is deterministic: the same schema produces the same agent, so a colleague reviewing it next month sees exactly what you saw.

Why you can point it at production

The model asks. It never acts.

Reinventing software you depend on only works if the reinvention cannot break it. So the language model is treated as exactly what it is — an untrusted planner. It proposes a call; the platform decides, independently, whether that call happens at all.

execution trace

paused
  1. Message Delete every customer inactive since 2023
  2. Plan delete_customer · 32 matches
  3. Ownership connection belongs to this workspace
  4. Permission customer.delete — granted
  5. Schema 2 arguments validated
  6. Policy needs a human DELETE · CRITICAL — approval required

Thirty-two customers still exist. The run is holding until a person approves delete_customer — for exactly those thirty-two records, and no others.

Day to day

Less like a query tool, more like a new hire

It replies in sentences

Nobody ever asked their database a question and hoped for a grid of column names back. Answers arrive the way a colleague would give them, with the reasoning alongside if you want to check it.

chat

how many orders came in today?

  1. proposed list_orders
  2. schema + policy checked
  3. read — no approval needed

Forty-one orders so far today, worth £8,420 between them. Two are still waiting on payment. The busiest hour was between 11am and noon.

And keeps its own notes

Searchable by the record that changed, months after anyone remembers the conversation it came from.

changes

  • Deleted Deleted customer 100 approved by Sarah
  • Updated Updated order 4471 Support Agent
  • Created Created refund 812 Billing Agent

It knows when to stop

Reads flow through. A delete, a bulk change or anything policy calls high-risk waits for a named person — and their approval covers that one call with those exact arguments, not the capability in general.

It shows its working

Intent, tool choice, policy decision and result are kept per run, including the calls that were refused. A history of successes only would hide the interesting part.

It asks a colleague

A generalist hands a billing question to the agent that knows billing rather than holding every billing tool itself. The delegated run gets its own approvals.

Reinvented software should not need a new tab

Web chat, Telegram, Slack and WhatsApp all reach the same runtime under the same policy set. Set the agent up once — a destructive request sent from WhatsApp stops for approval exactly as one typed here does.

  • Web chat
  • Telegram
  • Slack
  • WhatsApp
  • REST API
  • Webhooks

Pricing

Reinvent one system free. Pay when it earns its keep.

Free

$0 /mo

Reinvent one system and watch a real run.

Start free

Starter

$19 /mo

Put agents to work across a handful of systems.

Choose this plan
Most popular

Pro

$29 /mo

Multi-channel agents with human approval.

Choose this plan

Compare every plan feature by feature →

Tester programme — open

Want to be a tester?
Take Pro free for a month.

Point it at one system you actually run, then tell us where it got in your way. Apply with your GitHub profile — a person reads every application, and you hear back either way.

No card, nothing to cancel, and your work stays yours when it ends.

  • Every accepted tester

    Pro, free for a month

    On your own workspace. When it ends you drop back to the free plan and keep every agent, connection and conversation.

  • Top testers

    Pro for life

    For the people whose reports change the product. Chosen by hand — there is no leaderboard to game.

  • Apply with your GitHub profile — that is the whole form, plus a paragraph.

FAQ

The questions that come up first

Something not covered here? Ask us directly.

Do I have to move my data into Caterfli?

No, and there is nowhere to move it to. Caterfli holds a connection — a URL and an encrypted credential — and calls your system the way any other client would. Records stay in your database, your API, your MCP server. Disconnect it and your systems are exactly as they were.

What can an agent actually do once it is connected?

Whatever the system already exposes, and nothing beyond it. Caterfli inspects an MCP server, REST API, OpenAPI document or database and turns its capabilities into described tools — reading records, creating them, running reports. It can never do something the credential you supplied is not permitted to do.

Can the AI model see my credentials?

No. Credentials are encrypted with a key separate from the application key and injected by the connector at the moment of a call. They never appear in a prompt, a model response, a log line or a browser. The model only ever sees tool names and argument schemas.

What stops it deleting something it should not?

The model is treated as an untrusted planner. It proposes a call, and the platform independently verifies that the tool exists, that this agent may use it, that your workspace owns the connection, that the acting person holds the permission and that the arguments match the schema. Destructive work then pauses for a human, and an approval authorises exactly one call with exactly the arguments that were reviewed.

How long before it is useful?

An afternoon for the first system. Connecting takes minutes, discovery is automatic, and the slow part is you reading the agent Caterfli drafted and deciding which of its tools should stop for a person. There is no migration to schedule and nobody to retrain — your team already knows what the data means.

Which AI providers can I use?

The runtime is provider-agnostic. Anthropic, OpenAI, Google and OpenAI-compatible endpoints are supported, and the provider is configuration rather than code — switching does not change how your agents behave.

What happens if my subscription lapses?

There is a grace period before anything changes. After it, paid features are restricted but nothing is deleted — your connections, agents, execution history and audit trail are all preserved, and paying restores access immediately.

Pick the system nobody enjoys using

Connect it, review the agent Caterfli drafts from it, and see what it takes off your team this week. Free plan, no card, and disconnecting puts everything back exactly as it was.