Code review companies, products & suppliers
Bots that comment on diffs and pull requests rather than writing the first draft. Jobs: pr comments; style and defect hints on diffs; reviewer workload routing.
What is Code review?
Bots that comment on diffs and pull requests rather than writing the first draft. Jobs: pr comments; style and defect hints on diffs; reviewer workload routing.
What problems does it solve?
Reviewers spend time on nits while substantive defects still ship.
Typical business use cases
- PR comments
- Style and defect hints on diffs
- Reviewer workload routing
Important capabilities
- SCM integration
- Diff context
- Policy packs
What buyers should evaluate
- False-positive rate
- Where diffs are sent
- Override process
Risks and governance considerations
A bot that blocks merges on noisy findings or leaks private diffs.
Procurement checklist
- SCM permissions
- Finding export
- Human override
Relevant AI Trustmark assurance
AI Trustmark independent findings appear only when an assessment or certificate exists. Category membership does not imply verification.
Companies and providers
Claimed suppliers appear first so buyers can start with listings the company has taken ownership of. Payment does not buy this order.
Governor understands your code and routes each request to the best model, two levers that cut coding agent costs in half without touching quality. Bito publishes Bito AI Code Revie
Govern code quality, security and AI coding policies from a single place. Enabling dev teams to ship safely without slowing down. Codacy publishes Codacy Quality as named AI produc
Review, prioritize, understand, and secure agent outputs with CodeRabbit. CodeRabbit is used for Code review work. CodeRabbit publishes product information at coderabbit.ai. CodeRa
DeepSource publishes DeepSource as a named AI product. DeepSource is used for Code review work. DeepSource publishes product information at deepsource.com. DeepSource is grouped wi
Define agents as config files in your repo – Ellipsis runs them to review PRs, build features, and investigate production issues. Ellipsis is used for Code review work. Ellipsis pu
GitHub, a Microsoft company, sells Git hosting, Actions CI and Copilot AI coding assistance. Public pages cover cloud repositories and developer tools. GitHub publishes GitHub Copi
Graphite helps teams on GitHub deliver higher quality software, faster. Graphite publishes Graphite Diamond as named AI products. Graphite is used for Code review work. Graphite pu
AI Code Reviews that understand your entire codebase. Automate PR reviews, catch bugs faster, improve code quality with AI-driven analysis. Greptile publishes product information a
Qodo is an agentic code review and integrity platform for improving code quality at every stage. Qodo publishes Qodo Merge, Qodo Cover, and Qodo Gen as named AI products. Qodo is u
Every AI-building team faces one question: can you trust what you're shipping? Snyk secures the code AI writes, the agents it runs, and the apps it builds. Get started for fre
Sourcery AI Limited publishes Sourcery, a Python refactoring and GitHub pull-request review assistant that comments on diffs inside IDEs and CI. Public docs cover the GitHub app, C
Products
Claimed products appear first. Ranking packs and payment do not change this list.
- Bito AI Code Review Agent· Bito
- Codacy Quality· Codacy
- CodeRabbit· CodeRabbit
- DeepSource· DeepSource
- Ellipsis· Ellipsis
- GitHub Copilot Code Review· GitHub
- Graphite Diamond· Graphite
- Greptile· Greptile
- Qodo Merge· Qodo
- Sourcery· Sourcery
Also used in this category
These products have a different primary category so they do not compete for the same ranking queries. They are listed here because buyers still encounter them in this job.
- Snyk Code· Snyk
Related categories
Relevant procurement and assurance guides
Frequently asked questions
What is Code review?
Bots that comment on diffs and pull requests rather than writing the first draft. Jobs: pr comments; style and defect hints on diffs; reviewer workload routing.
What should not be listed as Code review?
Products whose buyer job is coding assistants inside the editor, AppSec scanners, or QA test generators. Those belong on their own category page so search queries are not split.
Has AI Trustmark independently assessed every Code review supplier?
No. A category listing is descriptive. Independent assessment is shown only on company or product pages that carry Trustmark evidence.
Should coding assistants be allowed to send private source code to third-party models?
That is a buyer policy decision. Procurement should require the default data-use terms, retention, whether snippets leave the organisation, and whether secrets are redacted. A listing under coding assistants does not mean code stays on-premises.
How should prompt injection and tool-output attacks be controlled?
Agents that read untrusted content or tool output can be instructed to exfiltrate data or take writes. Buyers should ask what is treated as untrusted, whether tool output can change the plan, and what tests were run. Scanner marketing is not the same as independent testing.
How can buyers tell whether customer data is used to train models?
Ask whether prompts, files, logs or outputs are used to train, fine-tune or evaluate models, including by subprocessors. Require the contractual default, any opt-out, and whether the setting can be changed silently. Treat marketing 'we do not train' claims as unverified until evidenced.
What model or provider changes should a buyer insist on being told about?
Material change usually includes a new model family, new region, new subprocessor, new write-capable tool, or a change that affects logging, privacy or human oversight. Those changes should trigger evidence refresh rather than a silent release.
How should buyers verify where AI customer data is processed?
Ask for the named processing locations, cloud regions and any subprocessors that see prompts, files or outputs. A directory listing is not evidence of residency. Independent assessment records the locations that were in scope on the assessment date.