CoFix / Product / Security
Security

Security review on your pull requests, against your own standards.

Findings live on one page, post to the pull request as a single review that updates in place, and are tracked as Open or Fixed until they're gone.

 security / PR #241 review
HighSQL built from request input
Injection · rule SEC-03
Open
MediumSecret logged on auth failure
Secrets · rule SEC-11
Open
LowMissing rate limit on /export
API · rule SEC-20
Fixed

Example data

41 rulesshipped in Security and Frontend categories, each on or off
1 review per PRposted once and updated in place on every push
Changed files onlythe review reads what the pull request touched
3 hostsGitHub, Bitbucket and Azure DevOps
How it works

From a push to a fixed finding.

  1. Link a repository

    GitHub, Bitbucket or Azure DevOps, per project. On GitHub, every pull request is reviewed when it opens and on each push.

  2. Review

    One review per pull request, reading only the files it changed, against the rules you have switched on.

  3. Post

    Findings post to the pull request as a single review that updates in place. No new comment thread on every push.

  4. Track

    Findings are deduplicated across pushes and tracked as Open or Fixed on one security page, grouped by type and by repository.

  5. Fix

    Raise a ticket per finding or per group, with backlinks both ways. The agent's own fixes pass the same standards check before a pull request opens.

What you get

Everything in Security.

AI code review

One review per pull request, reading only the files it changed, posted to the pull request and updated in place.

Editable standards

41 rules shipped in Security and Frontend categories, each on or off, plus your own Checks category. Every finding names the rule that raised it.

Pre-merge standards check

The agent's own fixes are checked against the same standards before it opens a pull request, with a repair pass for what it finds.

Grouped findings

One security page with findings grouped by type and by repository.

Finding lifecycle

Findings are deduplicated across pushes and tracked as Open or Fixed.

Findings to tickets

Create a ticket per finding or one for a group, with backlinks both ways.

Security audit log

Who changed a standard, dismissed a finding or created a ticket.

GitHub, Bitbucket and Azure DevOps

Code review reads any linked repository. Automatic review of every pull request, on open and on push, needs GitHub.

Coming soon
Optional merge gates
In depth

A closer look.

Review standards

Rules you can read, switch off and add to.

41 rules ship with the product, in Security and Frontend categories, each on or off. Add your own in a Checks category: the shared logger instead of console, the one HTTP client, the naming your team agreed on. Every finding names the rule that raised it, so a finding you disagree with points at a rule you can change.

  • 41 shipped rules, each on or off
  • Your own rules in a Checks category
  • Every finding names its rule
  • Changes to standards go in the security audit log
 security / review standards
SQL built from request inputSecurity
Secret written to a logSecurity
Missing rate limit on a public routeSecurity
Image without alt textFrontend
Use the shared logger, not consoleChecks · yours

Example rules

One review per pull request

Posted once, updated in place, tracked until fixed.

A review reads only the files the pull request changed and posts to it as a single review. Each push updates that review rather than adding a new one. Findings are deduplicated across pushes and tracked as Open or Fixed on one security page, grouped by type and by repository, with a ticket a click away.

  • Changed files only
  • One review that updates in place
  • Deduplicated across pushes
  • Open or Fixed, grouped by type and by repository
 security / PR #241
Push 14 findings posted as one review09:40
Push 2Review updated in place · 2 fixed11:05
OpenSQL built from request input · api/orders.tsticket SEC-31
OpenSecret logged on auth failure · auth/login.tsticket SEC-32
FixedWeak hash for reset tokenspush 2
FixedMissing rate limit on /exportpush 2

Example data

Connects to

Where your code lives.

GitHubAutomatic review of every pull request, when it opens and on each push.
BitbucketCode review on any linked repository.
Azure DevOpsCode review on any linked repository.
Claude, ChatGPT, GeminiReviews run on the platform quota or your own Anthropic, OpenAI or Google Gemini key.
TicketsA ticket per finding or per group, with backlinks both ways.
MonitoringThe endpoint scanner's findings share the Signals Inbox with errors and slow pages.
Questions

Security FAQ.

Which repositories can be reviewed?

Any linked GitHub, Bitbucket or Azure DevOps repository. Automatic review of every pull request, when it opens and on each push, needs GitHub.

What does a review look at?

Only the files the pull request changed, against the rules you have switched on. One review per pull request, posted to the pull request and updated in place on every push.

What are the 41 rules?

Shipped rules in two categories, Security and Frontend, each on or off. You add your own in a Checks category. Every finding names the rule that raised it, so a finding you disagree with points at a rule you can switch off.

Does it review the agent's own code?

Yes. Before the agent opens a pull request, its change is checked against the same standards, with a repair pass for anything found.

How do findings get fixed?

Raise a ticket per finding or one per group, with backlinks both ways, and hand it to the agent or a person. Findings are deduplicated across pushes and tracked as Open or Fixed until they are gone.

Can a finding block a merge?

Not yet. Optional merge gates are coming. Today a review is advisory and the pull request's reviewers decide.

What does Security cost?

There is no seat charge. Reviews count toward AI usage.