CodeGuard AI connects your GitHub repositories to Gemini-powered code review, real vulnerability scanning, and role-based team collaboration — all in one workspace.
No credit card required — free while CodeGuard AI is in early access.
Open any commit or PR, trigger an analysis, and get a risk score plus categorized findings across security, performance, and code quality — grounded in the actual diff, not a generic linter.
Every repository gets scanned by gitleaks, Semgrep, OSV-Scanner, and Trivy — then Gemini turns the raw output into a prioritized remediation summary you can act on, exportable as a PDF audit report.
Authenticate with GitHub OAuth and CodeGuard AI syncs your repositories, contributors, and languages automatically. Every repo gets its own Kanban board, task list, and review pipeline without any manual setup.
Invite teammates by email and assign a role — owner, product owner, developer, tester, designer, DevOps, security analyst, and more — each with server-enforced permissions over tasks, comments, and board state.
Seven columns, one board per repository. Tasks move from Open to Closed as your team ships — with every commit and AI review attached along the way.
No infrastructure to stand up — connect a repository and CodeGuard AI does the rest.
Authenticate with GitHub OAuth. Repositories, contributors, and languages sync automatically.
Add teammates by email and assign one of ten roles — permissions are enforced server-side.
Every commit triggers a Gemini review and a security scan across your repository.
Tasks, findings, and activity all land on one Kanban board per repository.
Code review and security remediation summaries are generated by Google Gemini. The AI provider is configurable per deployment, with Gemini as the default and currently the only supported provider.
Yes. There's no billing system yet, so every feature — AI review, security scanning, unlimited repositories and teammates — is free while CodeGuard AI is in early access.
No. Connect a repository through GitHub OAuth and CodeGuard AI reads it via the GitHub API — there's no agent, webhook relay, or CLI to self-host.
gitleaks for secret detection, Semgrep for static analysis, OSV-Scanner for dependency vulnerabilities, and Trivy for filesystem and config issues — all run automatically per repository, with an AI-written remediation summary on top.
Each repository has its own member list with one of ten roles — owner, project manager, product owner, developer, tester, designer, DevOps, security analyst, intern, or viewer — and permissions are enforced on the server, not just hidden in the UI.
Connect your repositories, invite your team, and let AI surface the risks before they reach production.