Annual independent security audits verify our controls meet AICPA Trust Service Principles for security.
Comprehensive data privacy measures ensuring full compliance with EU data protection regulations.
Request accessCodeRabbit communicates with LLM providers to generate code reviews. We send code diffs along with contextual data about the code to improve code reviews and provide better suggestions. The data is encrypted in transit using transport layer security (TLS). Proprietary code is never used to train or improve the models in any way. Queries to the LLMs are ephemeral, and no data is stored or logged by the LLMs.
Upon starting a new review, CodeRabbit starts in an isolated environment. Upon finishing the review and finally posting the review comments, CodeRabbit disposes of the environment and no traces of the code are stored on CodeRabbit’s servers. This flow ensures that no parts of the codebase are available outside of the scope and duration of the code review.
CodeRabbit is SOC 2 Type II certified, with a new report released annually. The report describes CodeRabbit's security controls and examines how those controls meet the AICPA Trust Service Principles. It provides an independent assessment of how well CodeRabbit manages data with respect to security, availability, and confidentiality.
CodeRabbit uses LLMs to identify vulnerable coding patterns in real-time during code reviews, suggesting secure alternatives before code is submitted to a PR.
Our platform offers robust security tools for code scanning, secret scanning, and vulnerability detection, helping to identify issues like hardcoded keys, credentials, and SQL injections to safeguard your codebase.
CodeRabbit verifies the absence of insecure coding patterns before posting code review PRs, ensuring compliance and protecting your code from threats.
Metadata
Code
Metrics
Learnings
Issues
Still have questions?
Contact us