The principle
Someone has to understand it.
AI writes the code in minutes and review became a formality. The fix isn't a louder bot — it's attaching a small, honest cost to the moment a person says this is fine to ship, and keeping a record of who said it.
01Connect your repo — read-only, your pick
Sign in with GitHub and install the app on exactly the repos you choose. It reads your code and writes nothing to it except its own status check and its own pull request comment. Revocable from GitHub at any time.
02Every pull request gets reviewed
When a PR opens — or when new commits land on it — the bot reads the diff plus the current content of every file the diff touches, and looks for the things that break production: authorization missing on a new path, a caller the change forgot to update, an edge case the code doesn't survive, a migration that breaks existing rows. Every finding has to name a concrete failure: what input produces what wrong outcome. A clean diff gets an empty list and says so.
03Findings become tracked work
Each finding lands on your board as an issue with a severity, a status, the file and lines it concerns, and a place to discuss it. Drag it through to do, in progress, blocked and done, or file your own issues alongside the bot's. Push any issue to GitHub Issues if that's where your team works — closing it there closes it here.
04The review generates a sign-off quiz
From the same diff, the bot writes five to seven multiple-choice questions about what this change actually does — what the changed function returns now, which flows it affects, what happens on the second concurrent call. Nothing answerable from the PR title or from general programming knowledge. The link goes straight onto the pull request.
05A human passes it, and only then can you merge
The quiz posts to GitHub as a check called "quiz sign-off". Make it a required status check in branch protection and the merge button stays off until someone with write access — and never the pull request's own author — scores 80% or better. Questions come one at a time, there's no going back, the correct answers never leave our server, and a failed attempt doesn't tell you which ones you missed.
06New commits clear the sign-off
Sign-off is bound to a commit, not to a pull request. Push again and the gate closes and a fresh quiz is generated on the new diff — because nobody can vouch for code they haven't seen.
What we optimize for
Findings you believe
A reviewer that always finds something is one you stop reading. Every finding has to describe a concrete failure, or it doesn't ship — and a clean diff is allowed to come back clean.
Accountability, not surveillance
We don't score your engineers or time their reviews. One question only: did a human understand this change before it merged, and who was it?
You hold the gate
The check is just a check until you make it required, and you choose which branches. The bot never merges, never pushes, never writes to your code.
See it on your next pull request.
Install it on one repo, open a PR, and watch what comes back. If the findings aren't worth reading, you've lost two minutes.