Skip to content

Enterprise

Run it inside your perimeter, on your terms.

The same reviewer, with the controls your security team will ask about before it reads a line of code: single sign-on, an exportable audit trail, a deployment that never leaves your network, and a written answer for every question in the questionnaire.

annual contract, seat minimum applies.

Controls

Everything procurement asks for, in one place.

These are Enterprise-tier entitlements, enforced by the same code that enforces rate limits — not switches a support engineer flips by hand.

SSO, SAML and RBAC

SAML 2.0 with your identity provider, enforced org-wide. Roles map to what people can change: who edits review configuration, who can pause the bot, who sees billing.

Audit log export

Every configuration change, command, suppression and admin action, exported to your SIEM. If someone turned the reviewer off before a release, the log says who and when.

Self-hosted and air-gapped

Run the whole pipeline inside your perimeter, pointed at your own model endpoint — Bedrock, Azure OpenAI or an on-premise deployment. No egress required, no shared control plane.

Data residency

Pin processing and storage to the EU, including the inference endpoints. Residency is a deployment property, not a promise in a support ticket.

DPA and zero retention

Signed data processing agreement with SCCs, and a zero-retention mode that stores no snippets and derives no learnings from your code — verifiable in the audit log.

SLA and named support

An uptime commitment with credits, a named contact, and an escalation path with response times in the contract rather than on a marketing page.

Review throughput
Unmetered
no hourly ceiling on Enterprise
Changed files per PR
2000
large refactors are reviewed, not skipped
Review depths
quiet · balanced · thorough
set per repository in config

Deployment

Four ways to run it. You pick the blast radius.

Air-gapped is a real product, not a euphemism for a VPC peering call. It runs against your own model endpoint with no outbound network access.

Deployment options compared
DeploymentManagedManaged, EUSelf-hostedAir-gapped
Where reviews executeOur cloud, US regionOur cloud, EU regionYour Kubernetes or VMsYour network, no egress
Who runs inferenceOur provider accountsOur provider accounts, EU endpointsYours or ours — your choiceYour Bedrock, Azure or on-premise model
Code at rest with usNone beyond the review windowNone beyond the review windowNoneNone
Derived learningsOn, per repo or orgOn, per repo or orgOn, in your databaseOff unless you enable them
UpgradesContinuousContinuousYou choose the versionSigned offline bundles
Typical time to first reviewMinutesMinutesA day with your platform teamScoped per environment

Security architecture

What your code touches, and what touches your code.

The summary your security reviewer will ask for. The long version, with the subprocessor list and retention windows, is in the trust center.

  1. 01

    Each review runs in a disposable sandbox

    Your repository is cloned into a single-use microVM that is destroyed when the review ends. The only credential that crosses into it is a single-repository, one-hour, read-only token. Tokens that can post comments stay outside the sandbox and never enter it.

  2. 02

    The app cannot push to your code

    Contents are read-only. Write access covers pull request conversations and check runs, nothing else. There is no path by which the reviewer commits to a branch, closes a pull request, or changes a setting.

  3. 03

    Instructions come from people, not from diffs

    Bot commands are honoured only from identities with write access, checked against the GitHub permission API on every command. Text in a pull request body, a code comment or a dependency README is data — it is delimited as untrusted and stripped of invisible and unicode-tag characters before a model sees it.

  4. 04

    Everything posted goes through an outbound filter

    Image channels, foreign links and raw HTML are removed from comments on a path the poster cannot bypass. A prompt-injection attempt in a vendored file cannot turn our comment into an exfiltration channel.

  5. 05

    Model providers are under zero-retention terms

    Prompts are not retained or trained on by our providers. Zero-retention mode goes further on your tenant: no derived learnings, no stored snippets, nothing kept after the review is posted. Self-hosted and air-gapped deployments can point at your own Bedrock, Azure or on-premise endpoint instead.

  6. 06

    Uninstall means deletion

    Removing the app triggers erasure of your review data on our side, logged with a timestamp you can request. Retention windows for everything else are published rather than negotiated per deal.

Procurement

What we have, and what we do not.

Vendor pages usually list only the first half. Both halves are below, because you will find out anyway and it is cheaper for everyone if you find out now.

What we can hand you today

  • A signed DPA with standard contractual clauses, plus a zero-retention addendum.
  • A maintained subprocessor list, with notice before it changes.
  • Security questionnaires answered from a kept-current document, usually inside two business days.
  • An uptime SLA with service credits, written into the order form.
  • A named contact, an escalation path, and incident notification commitments in the contract.
  • Annual invoicing, purchase orders, tax paperwork, and vendor-portal onboarding.

What we do not have yet

We are a young company and the compliance shelf is not full. We would rather lose a deal than put a badge on this page that an auditor has not issued.

SOC 2 Type II
Not issued. Ask us where the observation window stands and we will give you a date rather than a roadmap slide. The controls themselves are described in the trust center.
Third-party penetration test
If a current report is a hard requirement, tell us your deadline in the form below and we will tell you plainly whether we can meet it.
Customer references
We have no logo wall and will not manufacture one. What we can offer instead is our measured accuracy and a public status history.

Contact

Tell us what you need it to satisfy.

Requirements, deadlines, the reviewer you are replacing and why it annoyed you. We will come back with a straight answer about fit — including when the answer is that we are not ready for you yet.

  • A person replies, usually within one business day.
  • No drip sequence, no demo gate on the docs, no calendar ping-pong.
  • Design partner applications are welcome here too — say so in the message.

Compliance requirements, timelines, the reviewer you are replacing.

Goes to the founders, not a sequence. We do not sell or share what you type here.