---
id: "entity-strongdm"
type: "entity"
entityType: "organization"
canonicalName: "StrongDM"
aliases: ["strongDM"]
source_timestamps: ["00:06:30"]
tags: ["cybersecurity", "case-study"]
related: ["concept-dark-factory", "entity-justin-mccarthy", "entity-claude-3-5-sonnet"]
url: "https://www.strongdm.com/"
sources: ["s01-5-levels-ai-coding"]
sourceVaultSlug: "s01-5-levels-ai-coding"
originDay: 1
---
# StrongDM

## Profile
A cybersecurity firm and access management provider, cited as the **primary real-world example of a Level 5 [[concept-dark-factory|Dark Factory]]**.

## Operating Model (per source)
- **3-person engineering team**
- Uses [[entity-claude-3-5-sonnet|Claude 3.5 Sonnet]] plus an open-source agent called *Attractor*
- Manages a codebase of **25,000+ lines** of Rust, Go, and TypeScript
- Autonomously writes, tests, and ships code without human review

## Operating Principle
'[[quote-code-must-not-be-written|Code must not be written by humans. Code must not be even reviewed by humans.]]'

## Leadership
CTO [[entity-justin-mccarthy|Justin McCarthy]] leads the team.

## Verification Notes
Public sources confirm StrongDM as an access management vendor. CTO Justin McCarthy has discussed AI agents in engineering, but **no public confirmation** of the specific 3-person / 25k LoC autonomous claim. Treat as a directional case study.
