Nebula CRM Core v2.4.0
A CRM backbone you can put your own front end on.

What this is
Pipeline, contacts, activity log, and a permissions model that survived real sales teams. Ships with a Next.js admin surface and a Go API you can keep or throw away. Multi-tenant from the first commit.
Technical fingerprint
REF NEBULA-CRMTrust lattice
82
Composite of 6 weighted axes. The list beside this holds every figure and its evidence.
Trust lattice · click a column to pin
6 axes
Composite trust
Height = measurement · width = weight · colour = state
82
Weighted axes
Composite is the weighted mean of the axes above. Recompute it by hand if you want to — the inputs are all on this page.
Dependency surface
Surface view unavailable on this device. The table holds the same figures — install weight, advisory count, and fan-out per package.
Dependency surface · drag to orbit
133.2 MB installed
Radius = install weight · colour = advisory risk · distance = transitive fan-out
7 direct packages
2 flagged
Clean-room rebuild probe
Clone, install, scan, build, boot — outside the tool it was written in.
0% of pipeline weight
No probe on record for this build yet. Run it and the six stages report individually — a committed key or a build that only works inside the original generator shows up here, before escrow funds move.
Commit provenance · 26 weeks
26 active weeks
Distributed history across 26 weeks. Green bars had more than one author.
Run cost at volume
$40.00 /mo
- Edge hostingmetered$21.00
detected via next.config · $0.42 per 1k req
- Managed Postgresfixed$19.00
detected via DATABASE_URL · $19 per mo
At this volume the purchase price equals 77.5 months of infrastructure. Rates are list price for the detected services, before egress.
Demo
Read-only demo tenant with 400 seeded contacts.
Certification report · checklist v1.2
reviewed 2026-06-28 · severity floor mediumScope reviewed
- ✓Full source read of API and admin surface
- ✓Tenant isolation review on every data path
- ✓Secret handling and logging review
- ✓Dependency provenance audit
Findings on record
- — Tenant scoping enforced at the query layer, not only in the UI.
- — No credentials, tokens, or customer data found in the repository history.
- — One medium note on rate limiting was fixed by the seller before certification closed.
This is a point-in-time review of the artifact at the hash on record. It is not a warranty that the build is free of defects or vulnerabilities. Read the checklist.
Revenue on record
Figures are seller-declared and connected to a read-only payments export. Ask for the export in escrow before you confirm delivery.
