skip to content
// platform

From repository to report in one run_

Limited beta · read-only GitHub access

// how it works

Connect, pick, run, read.

// 01 Connect

Choose repositories. Grant read-only GitHub access.

The GitHub app requests read access to code and metadata for the repositories you choose. Nothing else. Organisations can install it once and select repositories later.

// 02 Pick

Choose a workflow and profile. Confirm the price.

The workflows are open source: open one and read its instructions before you run it. Profiles set the models and the time budget; the price is fixed per profile.

// 03 Run

A single-use sandbox. Runs continue with the tab closed.

Sandboxes are single-use. The repository is cloned only inside the sandbox with a short-lived read token, and the sandbox ends with the run.

// 04 Read

Review findings, evidence and the full trace.

The report stays attached to its run: the graph of stages, each stage's prompts and outputs, and the model that ran. Use the trace to check the report’s conclusions.

// profiles

Choose how hard it looks.

profilemodelsdefault time per stagecreditsuse it for
lowa fast modelup to 30 min10pull requests, triage
balanceda stronger modelup to 1 h25repository reviews
maxthe strongest modelup to 2 h50releases, audits

Fixed credits per run. Default time limits apply to each stage; adjustable before starting.

// the report

Run artifacts.

// what a run keeps
  • · report (Markdown)
  • · the run graph — every stage and its status
  • · each stage's prompts and outputs
  • · the workflow that ran, by name and profile
  • · the model and version that ran

No sample report is published yet.

// interfaces

The app first. MCP for agents.

Run reviews in the app. A hosted MCP endpoint starts Scan runs for OAuth or API clients — Scan MCP docs. REST API access remains available by request during beta. A packaged CLI is planned.

// limits
pricefixed per profile — low 10, balanced 25, max 50 credits — shown before the run starts
timedefault cap per stage: 30 min on low, 1 h on balanced, 2 h on max
sourcesGitHub repositories, through the read-only GitHub app
workflowstwo today — security-review and goal-security-review — with more planned
retentionreports, logs and artifacts are kept for 90 days and deleted on request

Time caps apply to each stage and can be adjusted before starting.

// later
// laterwatch — a workflow on every pull request · research — engagements with a private evaluation of your codebase
// faq
Do you store my code?

We don't keep a copy of your repository. Each run clones it into a fresh sandbox that ends with the run. The report and the run log — which can include excerpts of files the workflow read — are kept for 90 days; you can ask us to delete them sooner. Details on the trust page.

Which models do you use?

Commercial models chosen per profile and recorded on every run: a fast model on low, stronger models on balanced and max.

What does a run cost?

A fixed whole number of credits per profile, shown before you start: low 10, balanced 25, max 50. 1 credit is $1. See pricing.

Can I put it in CI?

Not yet. The platform is designed so an API can start runs from a pipeline. Continuous runs on every pull request, with comments, are further out. Write to hello@midkernel.com if you want that workflow.

Does it need write access?

No. The GitHub app requests read access to code and metadata only. Continuous runs, when they ship, will comment on pull requests through a separate, optional permission.

Can I run it on a private repository?

Yes; that is the normal case. The sandbox sees the repository only for the duration of the run.

What if a run fails?

Credits are charged when a run starts. If execution fails, the run is refunded automatically. Cancelling a run you started is not refunded.

Run one on your repo.

Limited beta · read-only GitHub access