AI-generated code

One verdict per change. Before it becomes a commit.

AI agents write fast and with confidence, including when they are wrong. codafort vet looks only at the change the agent just made, separates what must be fixed from what is just a warning and says what it could not check. The team reviews less and trusts more of what gets merged.

Pre-launch: codafort is not available to install yet. Join the waitlist →

what it checks

The mistakes AI makes that slip past review.

New security flaws

Only what the change introduced, with the path to the dangerous spot. What is confirmed blocks; what is suspected becomes a warning.

Errors CI already reported

It reuses what the pipeline already produced, such as compiler and test output, and ties each error to the line the change touched.

Tests that test nothing

A test that passes without checking the result: the most common way for an agent to "make the tests pass".

Broken public contract

A public function or interface removed or renamed that another module or team relies on.

A change bigger than asked

How many files and lines changed, and whether the change touched critical areas such as authentication, payments or infrastructure.

Hard-to-maintain code

The complexity of the functions touched. It is only a warning and never blocks.

where it runs

In the agent, in the terminal and in the PR, with the same result.

The agent checks the verdict before calling the task done. In the PR, the change is compared with the target branch, and you decide whether a blocking verdict fails the pipeline.

it becomes evidence

The buyer sees that AI-written code was reviewed, and how.

Each verdict can go into the counter-signed declaration you hand to your customer, with what was checked and what was left out. An item that was not checked shows up as not checked, never as passed.

The counter-signed declaration →

Questions

Does vet replace human review?

No. It takes off the reviewer's plate what a machine checks better, and hands the reviewer a verdict that says what was and was not checked.

Does it send my code to a server?

No. The analysis runs on the machine, including reading what CI already produced. What may leave it is listed at /telemetry, and each item can be turned off.

What if the agent "fixes" it by silencing the alert?

Every silenced alert is recorded and shows up in the report and in the counter-signed declaration. With codatrace, if the problem still happens while the app runs, the declaration fails.