Every PR reviewed.
Before it merges.

The agents read every diff with full codebase context: data flows, missing auth checks, framework misconfigs. A named researcher verifies. Finding = file:line + PoC, not scanner output.

  • Every PR and merge request
  • Full codebase context, not just the diff
  • Findings close when the fix merges

every PR

reviewed before merge, GitHub and GitLab

file:line + PoC

per finding, verified by a named researcher

+€5,000/yr

flat, part of the standing hunt

the review, in your PR

What lands as a PR comment: the file, the line, the data flow, and a PoC you can run yourself.

api/orders/[id].tsPR #214 · new order endpoint

+export async function GET(req: Request, { id }: Props) {

+ const session = await getSession(req)

+ const order = await db.orders.find({ id })

+ return Response.json(order)

+}

critical · idorline 44 · db.orders.find({ id })

session → GET /v1/orders/{id} → find({ id }): no ownership check. Any authenticated customer reads any order, items, addresses, payment references.

poc.sh: enumerates 1001–1010, all return 200

verified by a named researcher · closes when the fix mergesthe full bundle: sample report

How the review runs

01

Repo access

GitHub or GitLab. The agents index the code, build call graphs, read the logic.

02

Every PR reviewed

Data flows, missing auth checks, race conditions, payment & checkout. Finding with file:line + PoC, inline in the PR.

03

Tuning

Triage comments and rules for the parts only your team knows. Fewer false positives after every review.

One review for all of application security

business logic · injection: SQL, XSS, SSRF, XXE · prompt injection · memory safety · authn & authz · IaC · supply chain · secrets

One review covers all eight. The sample report shows a finding end to end: PoC, fix, retest.

See the sample report

A general AI reviewer lets an authorization bug ship.

General AI reviewer
  • Style, naming, patterns
  • Lists what might be there
  • You triage every flag yourself
Rheono review
  • Exploitability, with a data-flow trace
  • PoC per finding, in the PR
  • Business impact, named and prioritized

Pricing

Part of the standing hunt: +€5,000/yr, flat; on the deep audit: +€1,500, one-off. In writing before we start.

How is this different from SAST?+

SAST matches known rules and lists. We check exploitability: authz flaws that map to no rule, with a data-flow trace and a PoC.

Which platforms?+

GitHub and GitLab. Findings land as PR comments, fixes as branches.

What happens to our code?+

Repo access and data handling are written into the contract. Details: Trust & security.

Put us on the next pull request.

Repo access, first reviews, then flat. Or start with the free check.