Review a repository against its whole codebase.

Code, architecture and dependencies in one report. Then its pull requests and its site kept under watch.

Deterministic tools find the problem. A model explains it only if you let it, and the report says which way that was set.

high low SAST

Shell command built from a variable in src/legacy/export.ts

Tool
semgrep 1.177.0
Rule
detect-child-process
Graded
Down: no entrypoint reaches this module. Original severity kept beside it.
Status
Visible in the list. Not suppressed.
The shape of a finding, drawn for this page. Not output from a customer run.

Two packages

A one-off audit of a repository, and the same project kept under review afterwards. Each says what it leaves out.

Codebase Audit Report

One-off, per repository snapshot

Code
Code review lanes over the whole tree, graded against the repository that contains each finding.
Architecture
Dependency cycles, drift and structural metrics judged against the code, not against a diagram somebody drew. Custom rules.
Security
Secrets (gitleaks), SAST (Semgrep), IaC misconfiguration (Trivy), GitHub workflow security (zizmor), container and Kubernetes hardening, SBOM and licences.
Dependencies
Advisories across eight ecosystems, transitive through lockfiles, with EPSS. Packages we could not assess are named, not counted clean.
Report
Exported as PDF.

Optional compliance readiness section. 126 SOC 2 and ISO/IEC 27001:2022 controls, a gap plan, and a score over the controls actually assessed. Readiness, not certification.

Leaves out DAST, pentesting and API testing. Codebase grading is JavaScript and TypeScript only; other languages get the scanners, ungraded.

PR Review

Monthly, per workspace

Pull requests
Check runs, a summary and inline comments on GitHub pull requests, from the same review lanes as the audit, run on the change.
Disagreement
Dispute a finding and it leaves the merge gate. It is not deleted; the record of what was measured stays.
Alerts
Rules by event, severity and category, sent to Slack, Microsoft Teams or a webhook, for the workspace or one project.

Site health, included

Outside-in HTTP and browser-rendered probes of a site you have proved you control. TLS expiry, incidents and a public status page. Latency is synthetic and labelled synthetic. Accessibility and SEO audits of the same site.

Leaves out Fixes written to your branch. Paging and on-call. GitHub is the integration we have observed working; GitLab is not yet verified.

How your code is treated

  • Isolated per workspace in the database. Every row carries its workspace, and row-level security decides what a query can see.
  • Model use is yours to switch off. Per workspace or per project. Every run records which way it was set.
  • Uploaded archives are scanned, then deletable. A source archive is virus-scanned before anything reads it, and deleted when you ask.
  • Every finding shows where it came from. The tool, its version and the rule, so you can check it yourself.

What it does not do

Better to read it here than to find it in the report.

  • No pentesting or dynamic application testing.
  • No paging, on-call or incident response.
  • No fixes applied to your branch.
  • No certification. Readiness against 126 controls is not SOC 2 or ISO compliance.
  • Not yet codebase grading beyond JavaScript and TypeScript.
  • Not yet modernization planning as something you can buy.

Start with a trial workspace

Connect a repository and run a review. Prices and the trial's limits are on the pricing page, read from the same catalogue that decides what your workspace is allowed to do, so they are never out of step with this site.