Skip to content

CodeArmor 2.6 adds policy-as-code architecture rules and GitLab merge request audits

Read the changelog
CodeArmor AI

Autonomous Codebase Architecture & Security Auditor

Ingest entire microservice repositories. Uncover critical logic flaws and architecture drift before production. Autonomously patch vulnerabilities via GitHub PRs.

  • Free for up to 3 repositories
  • No credit card required
  • SOC 2 Type II
Tokens Context
200k
Whole services in a single reasoning pass
False Positive Target
Zero
Every finding is self-verified before it ships
Top 10 Compliant
SOC2 & OWASP
Findings mapped to OWASP, CWE and SOC2 controls

Trusted by security and platform teams at

  • Northwind
  • Lumen Pay
  • VEKTOR
  • Orbital Health
  • STACKLINE
  • Meridian Labs
  • helio
  • QUANTA
3,400+
Repositories under continuous audit
48k
Verified pull requests merged
40 min
Median time to remediation
99.98%
Platform uptime, trailing 12 months

Live interactive audit

Watch Claude audit a payment gateway in real time

A scripted replay of a real CodeArmor session against a sample repository. Pick a target, run the agent, inspect each finding and open a verified pull request.

app.codearmor.site/acme-corp/payment-gateway

Ready to scan

Agent reasoning stream

Idle
claude-opus-5-5

Agent is idle

Run a scan to watch Claude decompose the AST, map dependencies and hunt for exploits.

  • parse_ast
  • map_dependency_graph
  • trace_data_flow
  • check_architecture_rules
  • run_sandbox_tests
  • create_pull_request

Findings

0

No scan yet

Select a repository and press Scan with Claude Agent to populate findings.

Why legacy SAST is not enough

Pattern matchers see syntax. CodeArmor understands intent.

Signature-based scanners flag string concatenation and known sinks. They cannot reason about whether two statements that are each correct become a race when run together, or whether a role claim should ever be trusted. CodeArmor reads your repository the way a senior AppSec engineer does, across files and across services.

Legacy SAST

  • Regex and taint rules on single files
  • Thousands of noisy, unranked alerts
  • Blind to business-logic and ordering flaws
  • Reports problems, never fixes them

CodeArmor AI

  • Whole-repository reasoning with 200k-token context
  • Self-verified findings with a zero false positive target
  • Detects races, auth bypasses and architecture drift
  • Opens verified pull requests with generated tests

How it works

From repository to verified pull request in minutes

  1. 01

    Connect

    Install the GitHub App or run the Action. CodeArmor clones the repository, builds the dependency graph and primes Claude's prompt cache with your architecture rules.

  2. 02

    Audit

    Claude decomposes the AST, traces data flow across service boundaries and hunts for OWASP Top 10 patterns and business-logic exploits that rules cannot express.

  3. 03

    Patch

    Each finding is remediated, exercised against generated unit tests in an isolated sandbox, and opened as a pull request your team can review and merge.

Platform

Everything a senior AppSec engineer would do, on every commit

CodeArmor combines whole-repository reasoning with verified remediation so your team ships fixes, not tickets.

Deep architectural reviews

Reasons over the entire dependency graph to surface coupling, layer violations and drift from the architecture you actually designed.

Zero-day business logic detection

Finds race conditions, price manipulation, auth-flow bypasses and IDOR chains that no signature database contains.

Cross-service data-flow tracing

Follows untrusted input from the edge through queues, RPC boundaries and persistence layers to the sink that matters.

Verified auto-remediation PRs

Every patch is executed against generated tests in a sandbox before a pull request is opened. No drive-by diffs.

CI/CD native

Runs as a GitHub Action on every pull request, posts inline review comments and can gate merges on severity.

Compliance-ready evidence

Findings are mapped to OWASP Top 10, CWE and SOC2 controls with an audit trail your compliance team can export.

Customer story

Lumen PayFintech · Series C · 180 engineers · 62 services

How Lumen Pay cut mean time to remediate from eleven days to forty minutes

Lumen Pay processes card and bank transfers for marketplaces in 14 countries. Their security team was drowning in SAST noise while real business-logic flaws slipped through quarterly pen tests. After rolling CodeArmor out across every repository, verified remediation PRs became the default way findings get fixed.

Our engineers stopped treating security findings as tickets and started treating them as code review. That shift is worth more than any dashboard.
Priya Raman · Head of Security, Lumen Pay
11d → 40m
Mean time to remediate
312
Verified PRs merged in six months
2
Legacy SAST tools retired
0
Critical findings reached production

What customers say

Security teams that stopped triaging and started merging

“CodeArmor found a race condition in our payout service that two penetration tests had missed. The pull request it opened was the one we merged, tests included.”
Priya RamanHead of Security, Lumen Pay
“We retired two SAST tools and cut triage time by roughly 80 percent. The findings read like they were written by a staff engineer who knows our codebase.”
Daniel OkaforVP of Engineering, Northwind
“The architecture drift checks alone paid for it. CodeArmor keeps forty services honest without us maintaining a single custom lint rule.”
Mei Lin ChenPrincipal Engineer, Orbital Health

Integrations

Fits the tools your engineers already live in

Findings land as review comments, tickets and alerts. Identity and audit logs plug into the systems your security team already runs.

  • GitHubSource control
  • GitLabSource control
  • BitbucketSource control
  • Azure DevOpsSource control
  • GitHub ActionsCI/CD
  • CircleCICI/CD
  • SlackChat
  • Microsoft TeamsChat
  • JiraIssue tracking
  • LinearIssue tracking
  • PagerDutyOn-call
  • OpsgenieOn-call
  • OktaIdentity
  • Entra IDIdentity
  • DatadogObservability
  • SplunkObservability

Plus a REST API and signed webhooks for anything custom.

Security & trust

Your source code is the most sensitive thing we touch

CodeArmor is built and operated like the security product it is: ephemeral sandboxes, zero retention, independent audits and the deployment model your compliance team requires.

SOC 2 Type II

Independently audited controls across security, availability and confidentiality. Report available under NDA.

Zero retention, zero training

Clones are ephemeral and destroyed after each audit. Your source is never used to train models and never leaves the audit sandbox.

Deploy where you need

Multi-tenant cloud, single-tenant private cloud inside your VPC, or fully on-premises for regulated environments.

Enterprise access controls

SSO via SAML and OIDC, SCIM provisioning, role-based access, IP allowlists and exportable audit logs.

Pricing

Simple pricing that scales with your team

Start free, upgrade when you need continuous audits on every pull request, and talk to us for private deployments.

Starter

For small teams shipping their first services.

$0free forever

No credit card required

  • Up to 3 repositories
  • One full audit per repository per day
  • OWASP Top 10 and CWE Top 25 coverage
  • GitHub Action with merge gating
  • Community support
Most popular

Team

Continuous audits for growing engineering organizations.

$39per developer / month

Billed annually · 14-day free trial

  • Unlimited repositories and audits
  • Audit every pull request in CI
  • Autonomous remediation PRs with verified tests
  • Business-logic and architecture drift detection
  • Slack, Jira and Linear integrations
  • Email support with 1 business day response

Enterprise

Private deployments, SSO and custom security policies.

Custom

Annual contract · volume pricing

  • Everything in Team
  • Private cloud or on-premises deployment
  • SSO, SCIM and role-based access control
  • Custom policies and architecture rules as code
  • SOC 2 report, DPA and security questionnaire support
  • Dedicated solutions engineer and 99.9% uptime SLA

FAQ

Questions engineering and security leaders ask us

Those tools match patterns and taint rules inside single files. CodeArmor reasons over the whole repository with Claude: it follows data across service boundaries, understands what the code is supposed to do, and finds flaws in ordering, isolation and authorization logic that no rule can express. It also fixes what it finds instead of filing a ticket.

Put a senior AppSec engineer on every pull request.

Start free with up to three repositories, or book a walkthrough with our team. We will run CodeArmor against a repository of your choice and show you what your current tooling missed.

Prefer email? Reach the team at admin@codearmor.site