Security Code Review on Every Pull Request

Security findings only help if people trust them. CodeSightAI runs a security-focused review with one model, then has a second model challenge it — so what reaches your team is ranked by severity and has already survived a second reading.

Vulnerability classes we review for

  • Broken authentication and authorization, including missing ownership checks.
  • SQL and command injection, and unsafe dynamic query construction.
  • Cross-site scripting and unsafe rendering of user input.
  • Hardcoded credentials, API keys and tokens committed to source.
  • Insecure direct object references and over-permissive data access.
  • Sensitive data in logs and error responses.
  • Weak or missing input validation on request payloads.

Why static rules miss things

Pattern-based scanners are fast and precise on known shapes, and blind to anything that depends on intent. A query can be perfectly parameterised and still return another tenant's rows.

A reading-based review reasons about what the code is meant to do, which is where authorization bugs live. Running that review twice, independently, is how we keep the confidence of the result honest.

Severity that means something

Findings are normalised to critical, high, medium and low, and the score attached to a review is derived from those severities rather than a model's self-assessment. Stylistic nitpicks can be turned off entirely.

Our own security posture

  • Your code is used to generate the review only, and is not used to train models.
  • GitHub tokens are stored encrypted and used server-side.
  • Webhook payloads are signature-verified.
  • SOC 2-aligned practices; formal certification is not in place.
  • GDPR-ready handling of account data.

Frequently asked questions

Does this replace a penetration test?

No. It is a review of source code before merge. It does not test a running system and is not a substitute for a professional assessment.

Are you SOC 2 certified?

No. We follow SOC 2-aligned practices. We do not hold a certification and do not claim one.

Can I see what a security finding looks like?

Yes — the sample review walks through four findings on a real Supabase endpoint, including two critical ones.

Start free

Free plan available. No credit card required.