Start Free

Packet boundary

Codaegis turns one selected AI-assisted GitHub pull request into one governed packet with a verdict, missing proof, and a next action before a human merge decision. Codaegis is decision support only. It does not merge, deploy, approve, certify, enforce, warrant, replace human judgment, or include public API access in Starter.

Boundary stancePacket before authority

Visible uncertainty, narrow evidence, human-owned decisions.

What Codaegis commits to

Read-only first

The first paid path starts from PR-scoped evidence and names missing proof instead of silently widening the task.

No hidden authority

The governed packet can support a decision, but Codaegis does not merge, deploy, certify, or approve code.

One bounded offer

Free and Starter cover the same one-repo PR product. Neither adds public API, webhook, team, writeback, merge, deploy, or non-PR authority.

Held trust artifacts

Formal trust and compliance materials remain held; Codaegis only names safeguards that are true and evidenced today.

Visible uncertainty

When evidence is missing, the governed packet shows the gap and the next review action so buyers can inspect the limits.

No substitute packets

If setup, repo access, analysis path, or packet transport is unavailable, Codaegis explains the stop and recovery step instead of filling the gap with a fake answer.

What Codaegis does not claim

  • Codaegis is not a merge authority.
  • Codaegis is not a deployment authority.
  • Codaegis is not legal, security, or compliance approval.
  • Codaegis does not claim perfect safety.
  • Codaegis does not claim certification, audit approval, regulated-use approval, or trust-center admission.
  • Codaegis does not claim public API, webhook, team, writeback, adapter, or non-PR access in Free or Starter.

Measured quality

On 29 frozen internal pull-request metadata cases — 20 higher-risk, 9 clean — the recorded test produced 0 dangerous misses and 0 false stops.

Dangerous misses

0 of 20 higher-risk metadata cases

False stops

0 of 9 clean metadata cases

Verdict accuracy

0.897

Confidence calibration

0.959

This historical benchmark measured title/body summaries, filenames, and surrounding PR signals — not raw source patches. It is frozen replay, not production traffic or a guarantee. The provider is OpenAI; model version and routing remain internal. A source-grounded replacement requires separate published evidence.

Trust and data-handling FAQ

The operational questions a serious buyer asks before connecting a repository, answered only with what is true and evidenced today.

Data handling

What does Codaegis read from my repository?

Only what a selected pull-request check needs: a bounded, screened representation of the changed code, the pull request title and body, changed-file references, review, commit, and discussion summaries, and CI or status signals. The posture is read-only and scoped to one pull request, not the whole repository.

Data handling

Where does my code content go to produce a packet?

Codaegis sends only the bounded pull-request evidence needed for governed analysis through OpenRouter to an eligible model-hosting provider. The selected model is developed by OpenAI, but OpenRouter may use OpenAI or another eligible host under Codaegis's request controls. Likely secret values are withheld before that request, source coverage is recorded, and raw source is not copied into the governed packet, exports, or webhooks. Model version, detailed routing, and prompts remain private engine configuration.

Data handling

Do you train models on my code?

No. Codaegis does not use customer packet, repository, or code content for broad model training without explicit opt-in or a later reviewed policy.

Data handling

How long is my packet history kept, and can I get it out?

Visible packet history is bounded by plan: Free shows 3 days and Starter shows 30 days. Starter can download each governed packet as JSON or Markdown; Free users can request legally applicable account data through support. Older records may be held outside the visible window while deletion controls remain release-gated, so do not rely on Codaegis as your long-term archive.

Data handling

Can I revoke access or request deletion?

Yes. You can revoke GitHub access at any time and request export or deletion where applicable through support@codaegis.com. Payments run through Stripe-hosted flows, and Codaegis does not store full card details.

Security

How do I report a security issue?

Responsible disclosure is live. A machine-readable contact is served at /.well-known/security.txt (RFC 9116) alongside a published security policy; report privately to support@codaegis.com and allow a reasonable remediation window before public disclosure.

Security

What is the governed packet not allowed to do?

The packet is decision support only. It does not merge, deploy, approve, certify, or enforce, and write access to your repository is not the default posture. A human owns the decision the packet supports.

Security

What formal compliance does Codaegis claim today?

Only safeguards that are true and evidenced today: read-only review posture, bounded packet retention, no merge or deploy authority, and Stripe-handled payment data. Formal compliance features and trust artifacts remain held; Codaegis claims no certification or audit approval.

Current proof limits

These limits are not fine print. They keep Free and Starter honest enough to evaluate before connecting a repository.

Public sample governed packets are synthetic.

This boundary keeps public explanation honest while the product continues under held public-surface evidence.

Local fixture proof is not live provider proof.

This boundary keeps public explanation honest while the product continues under held public-surface evidence.

Private proof evidence supports internal review confidence, not public hosting or production admission.

This boundary keeps public explanation honest while the product continues under held public-surface evidence.

Stripe handles payment details; Codaegis keeps only the billing records needed for access and support.

This boundary keeps public explanation honest while the product continues under held public-surface evidence.

Free and Starter do not include public API or webhook access.

This boundary keeps public explanation honest while the product continues under held public-surface evidence.

Formal trust artifacts remain held; no certification or audit claim is made.

This boundary keeps public explanation honest while the product continues under held public-surface evidence.

Team administration, non-PR work, repository writeback, merge, and deployment are not current features.

This boundary keeps public explanation honest while the product continues under held public-surface evidence.

Any proceed packet verdict remains decision support, not legal or security approval.

This boundary keeps public explanation honest while the product continues under held public-surface evidence.