AI code review on your pull requests, against your own security standards.
Automated security code review for pull requests in GitHub, Azure DevOps and Bitbucket. Findings live on one page, post to the pull request as a single review that updates in place, and are tracked as Open or Fixed until they're gone.

How it works
From a push to a fixed finding.
Link a repository
GitHub, Bitbucket or Azure DevOps, per project. On GitHub, every pull request is reviewed when it opens and on each push.
Review
One review per pull request, reading only the files it changed, against the rules you have switched on.
Post
Findings post to the pull request as a single review that updates in place. No new comment thread on every push.
Track
Findings are deduplicated across pushes and tracked as Open or Fixed on one security page, grouped by type and by repository.
Fix
Raise a ticket per finding or per group, with backlinks both ways. The agent's own fixes pass the same standards check before a pull request opens.
What you get
Everything in Security.
AI code review
One review per pull request, reading only the files it changed, posted to the pull request and updated in place.
Editable standards
41 rules shipped in Security and Frontend categories, each on or off, plus your own Checks category. Every finding names the rule that raised it.
Pre-merge standards check
The agent's own fixes are checked against the same standards before it opens a pull request, with a repair pass for what it finds.
Grouped findings
One security page with findings grouped by type and by repository.
Finding lifecycle
Findings are deduplicated across pushes and tracked as Open or Fixed.
Findings to tickets
Create a ticket per finding or one for a group, with backlinks both ways.
Security audit log
Who changed a standard, dismissed a finding or created a ticket.
AI code review on GitHub, Azure DevOps and Bitbucket
Code review reads any linked repository. Automatic review of every pull request, on open and on push, needs GitHub.
In depth
A closer look.
Review standards
Rules you can read, switch off and add to.
41 rules ship with the product, in Security and Frontend categories, each on or off. Add your own in a Checks category: the shared logger instead of console, the one HTTP client, the naming your team agreed on. Every finding names the rule that raised it, so a finding you disagree with points at a rule you can change.
- 41 shipped rules, each on or off
- Your own rules in a Checks category
- Every finding names its rule
- Changes to standards go in the security audit log

One review per pull request
Posted once, updated in place, tracked until fixed.
A review reads only the files the pull request changed and posts to it as a single review. Each push updates that review rather than adding a new one. Findings are deduplicated across pushes and tracked as Open or Fixed on one security page, grouped by type and by repository, with a ticket a click away.
- Changed files only
- One review that updates in place
- Deduplicated across pushes
- Open or Fixed, grouped by type and by repository

Connects to
A code review tool for wherever your code lives.
Questions
Security FAQ.
Does the AI code review work with Azure DevOps and Bitbucket?
Yes. Code review reads any linked GitHub, Bitbucket or Azure DevOps repository. Automatic review of every pull request, when it opens and on each push, needs GitHub.
What does a review look at?
Only the files the pull request changed, against the rules you have switched on. One review per pull request, posted to the pull request and updated in place on every push.
What are the 41 rules?
Shipped rules in two categories, Security and Frontend, each on or off. You add your own in a Checks category. Every finding names the rule that raised it, so a finding you disagree with points at a rule you can switch off.
Does it review the agent's own code?
Yes. Before the agent opens a pull request, its change is checked against the same standards, with a repair pass for anything found.
How do findings get fixed?
Raise a ticket per finding or one per group, with backlinks both ways, and hand it to the agent or a person. Findings are deduplicated across pushes and tracked as Open or Fixed until they are gone.
Is it a SAST tool?
No. A SAST scanner matches code against fixed patterns. This is an AI reviewer that reads the files a pull request changed against rules you can read and edit, and names the rule behind every finding. You can run it alongside a SAST scanner.
Can a finding block a merge?
Not yet. Optional merge gates are coming. Today a review is advisory and the pull request's reviewers decide.
What does Security cost?
There is no seat charge. Reviews count toward AI usage.
Part of one workspace