VibeCop
Code analytics, review and intelligenceInsights and intelligence at platform-engineer level.
Get up to 25% of developer hours back.
Why VibeCop
Agents write code faster than teams can read it, so VibeCop reviews each change against your whole codebase.
- 0-100
- one integrity score
- 4 axes
- 25 points each
- 9 agents
- on every pull request
Why a diff is not enough
- A reviewer reading forty changed lines cannot see the module three directories away.
- Each AI change is locally reasonable: a second HTTP wrapper, a third date helper.
- Drift compounds quietly, because no single change looks wrong.
Who it fits
- Best for
- teams whose code volume outran review
- Clear signal
- most PRs are agent-written, approved on trust
- Less useful on
- green-field code with no patterns yet
- Never does
- merge; a person still does that
Capabilities
Eighteen agents produce findings on a run: nine architectural, and nine static hygiene checks.
- 25
- agents built in
- 478
- checks, plus a live CVE feed
What they catch
- Layers and wrappers that add indirection without value.
- The same problem solved differently in three places.
- Cycles, heavy coupling, and modules nothing imports.
- A finding that matches an issue your team already fixed.
Coverage
- Weakness types (CWE)
- 26
- OWASP Top Ten 2021
- 7 of 10
- Secret-detection rules
- 23
- Lockfile formats parsed
- 8
Reports
Each review posts a check, a summary comment listing every finding, and notes on the lines themselves.
- 10
- inline comments per review
- P1-P4
- severity on every finding
on the pull request
Check: VibeCop
Integrity 78/100 · P1 0 · P2 2 · P3 5 · P4 1
### High (P2)
- Second HTTP client wrapper added
src/billing/http.ts
- Migration adds NOT NULL without a default
supabase/migrations/212_billing.sql
What you do with a finding
- Resolve it as fixed, or dismiss it with a reason.
- Act on one, or on a batch at once.
- Resolving returns the points to the live score.
- A worker writes a fix prompt you can hand to your agent.
How it works
Connect a repository once. Webhooks, schedules and your own agent trigger everything after that.
- 4
- steps to a first score
- 0
- changes to your CI
Connect to score
- Authorize GitHub and pick a repository.
- A quick scan runs at once, with no model calls, to inventory the code.
- Confirm one prompt and the full pass runs over the repository.
- VibeCop reads your stack and patterns, then computes the first score.
What runs without you
- Opening or updating a pull request queues a review.
- Critical findings also open a summary issue on the repository.
- Stalled runs are cleaned up, and each repository has a daily cap.
- A repository is actively connected to one project at a time.
Security
Your repository is streamed into memory for a scan. Source is never written to our disk or database.
- AES-256-GCM
- tokens and stored text
- 48 hours
- cancellable grace before deletion
Stored, and not stored
- File paths and symbol names
- stored
- Source code, in any table
- not stored
- Finding text and severity
- stored
- The code a finding points at
- not stored
Limits we publish
- Secret detection records the file, line and pattern type, never the value.
- Vulnerability lookups send dependency names and versions only.
- Data at rest is in Singapore; other regions are an enterprise conversation.
- No third-party certification such as SOC 2 has been undertaken.
Pricing
VibeCop is free for everyone while pricing is being reworked, and no card is required.
- Free
- until December 31, 2026
- No card
- required to start
What free includes
- Every detector, the code graph, and pull-request reviews.
- No payment details to connect a repository and scan it.
- Nothing starts billing without being announced first.
Common questions
- What are AI credits?
- the model cost of scans
- Do I pay for them?
- no, a monthly allowance is included
- If they run out?
- scans pause until the reset
- Enterprise terms
- contact@maiife.ai
VibeCopGradusLens-11
Selected product
VibeCop
Dev tools, code analytics & review.