How Aspectobots is built
Who makes this, with what, and how a change gets from an idea to the page you're reading. If something here stops being true, we fix the page, and the changelog says when.
Who builds it
Aspectobots is made by Sym Services, a one-person business in Kansas that also makes Aspectora, the modular framework Aspectobots is built on. One founder, no investors, no outside owners. The founder decides what gets built, how it should feel and what it must never do, checks the results, and handles everything that involves money, the law, passwords or accounts.
Friends and family help as unpaid volunteers for now, with testing and support, under a signed volunteer agreement. When there's revenue, staff get paid, at 1.5 times the going rate for the role.
The AI on the team
Most of the code, the words on this site and the scripts that draw our art are written by Claude, an AI model made by Anthropic, working in Claude Code on the founder's computer. The founder sets the direction and the rules, and Claude does the building, testing and fixing, then puts changes live. Every change Claude helps write is marked "Co-Authored-By: Claude" in our project history.
- What Claude does: writes and changes code, writes copy in plain English, runs the tests and security checks, takes screenshots on desktop and phone sizes to check the layout, and deploys to this site.
- What it never does: type passwords, card numbers or ID details anywhere; make payments; sign anything; send messages or publish anywhere outside this site without the founder saying yes; change our main Discord server without being asked.
- What it can reach: the project on the founder's computer, which includes the keys needed to deploy and to run our own bot. Its standing rule is the same as staff: never print, copy or read a secret it doesn't need, and never unseal a customer's bot token. Our security page is plain about who could technically reach what.
- The security watch: once a week an AI session reviews our code and security setup and writes a report for the team. It reads and reports; it doesn't change the live site.
AI helpers are listed in our staff register next to the humans. Our rule: nothing an AI writes is passed off as a person, and a human owns every decision.
The art is drawn by code too, not by an image generator: the 3D bot is a WebGL shader we wrote, and the profile pictures, banners and server icons are rendered from that same shader by our own scripts.
What it runs on
The Aspectora framework. Aspectora is our own modular framework, made by Sym Services: one system that everything we build plugs into as a module. Aspectobots is its first module. The framework is being built right alongside it, so the shared parts (accounts and sign-in, the support desk, the staff dashboard, the site's header and footer, the database layout) are written once for every Aspectora module to use, not just for bots.
- Website and Studio: HTML, CSS and JavaScript we wrote ourselves on the Aspectora framework. No outside frameworks or libraries, no ad or tracking code.
- Server code: PHP 8.4 with a MariaDB 11.8 database.
- Hosting: a shared cPanel plan at ShockHosting, which also runs our email.
- Protection: Cloudflare's free plan sits in front of the site. Visit statistics come from Cloudflare Web Analytics, which uses no cookies.
- Domain: aspectora.site, registered at GoDaddy.
- Fonts: Rethink Sans, Martian Mono and Unbounded, loaded from Google Fonts.
- Bots: Discord sends button presses to our server over HTTPS, signed so we can prove they came from Discord. Bot tokens are encrypted with libsodium before they're stored.
- QR codes and 2FA: made on our own server, so a sign-in key never goes to an outside service.
- Code history: a private repository on GitHub.
What these cost goes on our open books page once the hosting and domain bills are in. Revenue so far is $0: billing isn't on yet.
How a change ships
- The founder asks for something, or a bug turns up.
- Claude builds it on a copy of the site on the founder's computer, with the same database the live site uses.
- Automated tests run: sign-in, accounts, the bot engine, support tickets, code downloads, QR codes, and a check of every page.
- The security check runs: 49 checks covering headers, sign-in, how tokens are stored, secrets in the code, and more.
- Screenshots on desktop and phone sizes to catch layout problems.
- The release gets a changelog entry and a version number. The deploy tool refuses to go live if they're missing.
- Only the changed files are uploaded, then the live site is checked again.
New Discord features are tried on our Showcase server before they reach our main one.
Versions
You're looking at v0.7.1. The number stays at 0.x for the whole early alpha: the middle number goes up when something new ships, the last when we only fix things. 1.0 comes when the alpha ends. Every release is in the changelog, which you can also follow as a feed.
What isn't public yet
- The source code. Our repository is private for now. On Architect and up you can download your own bot's code, MIT licensed, from the Studio.
- Costs. Coming to the open books page, as above.
Questions about any of this: [email protected]. Security problems: [email protected].