Free
- 30 PR reviews per month
- Public and private repos
- All 3 agents (correctness, security, style)
- Up to 2 concurrent reviews
- Inline PR comments
The only code review tool with a dedicated security agent. Correctness, security, and style run simultaneously and synthesize into one unified report. Under 2 minutes per PR.
One PR event triggers three parallel checks. No config required to start.
GitHub sends a webhook. TriRev acknowledges within 200ms and starts analysis in the background. Your workflow is never blocked.
Correctness catches logic bugs and edge cases. Security scans for OWASP Top 10 and exposed credentials. Style checks conventions and readability. Each agent focuses on one thing.
Results are synthesized into a single PR comment with inline annotations. No duplicates. No noise. Severity levels (critical / high / medium / low) on every finding.
Logic bugs, null safety, edge cases, potential regressions. Covers JS/TS, Python, and Go.
OWASP Top 10, exposed secrets, dependency vulnerabilities, weak crypto patterns. CVE references included.
Naming, readability, documentation gaps, convention drift. Adapts to your existing codebase patterns.
| Feature | TriRev | CodeRabbit | Copilot |
|---|---|---|---|
| Specialized parallel agents | 3 dedicated agents | Single agent | Single agent |
| Dedicated security review | Full OWASP scan | Basic | Basic |
| Unified synthesis report | Yes | No | No |
| Zero code retention | Diff-only, never stored | Configurable | Telemetry opt-out |
| Private repos on free plan | Yes | Public only | Paid plan |
Simple, per-developer pricing. No seat minimums on Free or Pro.
.reviewbot.yml configAll plans include zero code retention. We analyze diffs only - your source code is never stored or used for training.
TriRev processes only the PR diff. Your source code is never stored, logged, or used in any form after the review is complete.
We request the minimum GitHub permissions necessary. No access to your full repository history, branches, or unrelated files.
Each review is an independent job. No cross-PR correlation, no user profiling, no model training on your code.
Every review is logged with a delivery ID for debugging. Review metadata (repo, PR number, timestamp, status) is retained, not the code contents.
TriRev never inserts promotional content into your PR comments. Your workflow is not an advertising channel. Review comments contain findings only.
Read our full security posture - what data we access, what we store, and our incident response process.
Install in under a minute. Works on any repo, any language in the supported set.
Install TriRev on GitHubFree plan, no credit card required.