Security review on your pull requests, against your own standards.
Findings live on one page, post to the pull request as a single review that updates in place, and are tracked as Open or Fixed until they're gone.
Injection · rule SEC-03Open
Secrets · rule SEC-11Open
API · rule SEC-20Fixed
Example data
From a push to a fixed finding.
Link a repository
GitHub, Bitbucket or Azure DevOps, per project. On GitHub, every pull request is reviewed when it opens and on each push.
Review
One review per pull request, reading only the files it changed, against the rules you have switched on.
Post
Findings post to the pull request as a single review that updates in place. No new comment thread on every push.
Track
Findings are deduplicated across pushes and tracked as Open or Fixed on one security page, grouped by type and by repository.
Fix
Raise a ticket per finding or per group, with backlinks both ways. The agent's own fixes pass the same standards check before a pull request opens.
Everything in Security.
AI code review
One review per pull request, reading only the files it changed, posted to the pull request and updated in place.
Editable standards
41 rules shipped in Security and Frontend categories, each on or off, plus your own Checks category. Every finding names the rule that raised it.
Pre-merge standards check
The agent's own fixes are checked against the same standards before it opens a pull request, with a repair pass for what it finds.
Grouped findings
One security page with findings grouped by type and by repository.
Finding lifecycle
Findings are deduplicated across pushes and tracked as Open or Fixed.
Findings to tickets
Create a ticket per finding or one for a group, with backlinks both ways.
Security audit log
Who changed a standard, dismissed a finding or created a ticket.
GitHub, Bitbucket and Azure DevOps
Code review reads any linked repository. Automatic review of every pull request, on open and on push, needs GitHub.
A closer look.
Rules you can read, switch off and add to.
41 rules ship with the product, in Security and Frontend categories, each on or off. Add your own in a Checks category: the shared logger instead of console, the one HTTP client, the naming your team agreed on. Every finding names the rule that raised it, so a finding you disagree with points at a rule you can change.
- 41 shipped rules, each on or off
- Your own rules in a Checks category
- Every finding names its rule
- Changes to standards go in the security audit log
Example rules
Posted once, updated in place, tracked until fixed.
A review reads only the files the pull request changed and posts to it as a single review. Each push updates that review rather than adding a new one. Findings are deduplicated across pushes and tracked as Open or Fixed on one security page, grouped by type and by repository, with a ticket a click away.
- Changed files only
- One review that updates in place
- Deduplicated across pushes
- Open or Fixed, grouped by type and by repository
Example data
Where your code lives.
The same standards on every repository.
Security FAQ.
Which repositories can be reviewed?
Any linked GitHub, Bitbucket or Azure DevOps repository. Automatic review of every pull request, when it opens and on each push, needs GitHub.
What does a review look at?
Only the files the pull request changed, against the rules you have switched on. One review per pull request, posted to the pull request and updated in place on every push.
What are the 41 rules?
Shipped rules in two categories, Security and Frontend, each on or off. You add your own in a Checks category. Every finding names the rule that raised it, so a finding you disagree with points at a rule you can switch off.
Does it review the agent's own code?
Yes. Before the agent opens a pull request, its change is checked against the same standards, with a repair pass for anything found.
How do findings get fixed?
Raise a ticket per finding or one per group, with backlinks both ways, and hand it to the agent or a person. Findings are deduplicated across pushes and tracked as Open or Fixed until they are gone.
Can a finding block a merge?
Not yet. Optional merge gates are coming. Today a review is advisory and the pull request's reviewers decide.
What does Security cost?
There is no seat charge. Reviews count toward AI usage.