skip to content
// scan

A security review you can read_

Repository findings, evidence and the full trace.

Limited beta · read-only GitHub access

// what you provide

Connect a repository.

Choose repositories for the read-only GitHub app, then select a workflow and profile. Each review runs in a single-use sandbox.

// what the review does

Choose a workflow.

security-review · default

One repository pass. Findings with evidence.

goal-security-review

Threat model → parallel goals → two independent judges.

Both workflows are public at github.com/midkernel/playbooks. More about workflows →

// what you get

What workflows aim to report.

findings with evidenceLocation, root cause and severity reasoning.
the full traceRun graph, prompts and outputs.
scope and limitsReviewed scope and exclusions.

No sample report is published yet.

// what it costs

A fixed price, shown before you start.

Credit value
1 credit = $1
Charged
When the run starts
Failed runs
Automatically refunded
Cancelled runs
Not refunded
profilemodelsdefault time per stagecreditsuse it for
lowa fast modelup to 30 min10pull requests, triage
balanceda stronger modelup to 1 h25repository reviews
maxthe strongest modelup to 2 h50releases, audits

Fixed credits per run. Default time limits apply to each stage; adjustable before starting.

Pricing and credit packs

// limitations

What a review is not.

  • · AI findings require human triage.
  • · Coverage is time-bounded. Zero findings is a bounded result, not a guarantee.
  • · Repository review only; no live infrastructure testing.
// your code

Read this before you connect.

The repository stays in the sandbox during the run. Reports, logs and artifacts persist. Access, retention and data use →

// faq
What does a run cost?

A fixed whole number of credits per profile, shown before you start: low 10, balanced 25, max 50. 1 credit is $1. See pricing.

Do you store my code?

We don't keep a copy of your repository. Each run clones it into a fresh sandbox that ends with the run. The report and the run log — which can include excerpts of files the workflow read — are kept for 90 days; you can ask us to delete them sooner. Details on the trust page.

Which models do you use?

Commercial models chosen per profile and recorded on every run: a fast model on low, stronger models on balanced and max.

What is a workflow?

A file in a public repository: metadata that names the workflow plus instructions that tell the agents how to review. The two you can run today — security-review and goal-security-review — are open source at github.com/midkernel/playbooks. Read one before you run it.

Can I put it in CI?

Not yet. The platform is designed so an API can start runs from a pipeline. Continuous runs on every pull request, with comments, are further out. Write to hello@midkernel.com if you want that workflow.

Run one on your repo.

Limited beta