AI code review on your pull requests, against your own security standards.

Automated security code review for pull requests in GitHub, Azure DevOps and Bitbucket. Findings live on one page, post to the pull request as a single review that updates in place, and are tracked as Open or Fixed until they're gone.

A code review of the web app with a critical finding, where it occurs and what to do
41 rulesshipped in Security and Frontend categories, each on or off
1 review per PRposted once and updated in place on every push
Changed files onlythe review reads what the pull request touched
3 hostsGitHub, Bitbucket and Azure DevOps

How it works

From a push to a fixed finding.

  1. Link a repository

    GitHub, Bitbucket or Azure DevOps, per project. On GitHub, every pull request is reviewed when it opens and on each push.

  2. Review

    One review per pull request, reading only the files it changed, against the rules you have switched on.

  3. Post

    Findings post to the pull request as a single review that updates in place. No new comment thread on every push.

  4. Track

    Findings are deduplicated across pushes and tracked as Open or Fixed on one security page, grouped by type and by repository.

  5. Fix

    Raise a ticket per finding or per group, with backlinks both ways. The agent's own fixes pass the same standards check before a pull request opens.

What you get

Everything in Security.

Coming soon
Optional merge gates

AI code review

One review per pull request, reading only the files it changed, posted to the pull request and updated in place.

Editable standards

41 rules shipped in Security and Frontend categories, each on or off, plus your own Checks category. Every finding names the rule that raised it.

Pre-merge standards check

The agent's own fixes are checked against the same standards before it opens a pull request, with a repair pass for what it finds.

Grouped findings

One security page with findings grouped by type and by repository.

Finding lifecycle

Findings are deduplicated across pushes and tracked as Open or Fixed.

Findings to tickets

Create a ticket per finding or one for a group, with backlinks both ways.

Security audit log

Who changed a standard, dismissed a finding or created a ticket.

AI code review on GitHub, Azure DevOps and Bitbucket

Code review reads any linked repository. Automatic review of every pull request, on open and on push, needs GitHub.

In depth

A closer look.

Review standards

Rules you can read, switch off and add to.

41 rules ship with the product, in Security and Frontend categories, each on or off. Add your own in a Checks category: the shared logger instead of console, the one HTTP client, the naming your team agreed on. Every finding names the rule that raised it, so a finding you disagree with points at a rule you can change.

  • 41 shipped rules, each on or off
  • Your own rules in a Checks category
  • Every finding names its rule
  • Changes to standards go in the security audit log
Review standards for security, each rule switched on or off, 40 of 41 on

One review per pull request

Posted once, updated in place, tracked until fixed.

A review reads only the files the pull request changed and posts to it as a single review. Each push updates that review rather than adding a new one. Findings are deduplicated across pushes and tracked as Open or Fixed on one security page, grouped by type and by repository, with a ticket a click away.

  • Changed files only
  • One review that updates in place
  • Deduplicated across pushes
  • Open or Fixed, grouped by type and by repository
Pull request reviews for the web app: every push reviewed again, with the findings fixed since the last push and the ones still open

Connects to

A code review tool for wherever your code lives.

GitHubAutomatic review of every pull request, when it opens and on each push.
BitbucketCode review on any linked repository.
Azure DevOpsCode review on any linked repository.
Claude, ChatGPT, GeminiReviews run on the platform quota or your own Anthropic, OpenAI or Google Gemini key.
TicketsA ticket per finding or per group, with backlinks both ways.
MonitoringThe endpoint scanner's findings share the Signals Inbox with errors and slow pages.

Questions

Security FAQ.

Does the AI code review work with Azure DevOps and Bitbucket?

Yes. Code review reads any linked GitHub, Bitbucket or Azure DevOps repository. Automatic review of every pull request, when it opens and on each push, needs GitHub.

What does a review look at?

Only the files the pull request changed, against the rules you have switched on. One review per pull request, posted to the pull request and updated in place on every push.

What are the 41 rules?

Shipped rules in two categories, Security and Frontend, each on or off. You add your own in a Checks category. Every finding names the rule that raised it, so a finding you disagree with points at a rule you can switch off.

Does it review the agent's own code?

Yes. Before the agent opens a pull request, its change is checked against the same standards, with a repair pass for anything found.

How do findings get fixed?

Raise a ticket per finding or one per group, with backlinks both ways, and hand it to the agent or a person. Findings are deduplicated across pushes and tracked as Open or Fixed until they are gone.

Is it a SAST tool?

No. A SAST scanner matches code against fixed patterns. This is an AI reviewer that reads the files a pull request changed against rules you can read and edit, and names the rule behind every finding. You can run it alongside a SAST scanner.

Can a finding block a merge?

Not yet. Optional merge gates are coming. Today a review is advisory and the pull request's reviewers decide.

What does Security cost?

There is no seat charge. Reviews count toward AI usage.