ShipGuardeRELEASE CLEARANCE BUREAU
How it worksUse casesDocsPricing
THE REGISTERS

Two registers
of examiners.
One signature.

7 examiners read the pull requests you flag. 11 more open the running app. Every run ends in one verdict, with findings by category and a replayable trace.

Join the free 30-day pilotSee the registers
CODE EXAMINERS7
VISUAL EXAMINERS11
VERDICTS POSSIBLETHREE
SIGNATURES PER RUNONE
CODE EXAMINERS

7 checks on the pull requests you flag.

Scoped to what the diff introduces, so a green run means this change is clean, not that your backlog is.

01 Code Review

Correctness, security and contract defects introduced by the change, each with a concrete failing scenario named.

02 Lint

New linter issues on the changed lines only. Your pre-existing backlog stays quiet.

03 Security

Leaked secrets and static-analysis findings on the diff.

04 Dependencies & License

Known-advisory audit and license-policy checks on changed dependencies.

05 Schema Drift

Database schema staying consistent with the ORM and client surface.

06 Migration Safety

Risky migrations flagged: drops, non-concurrent indexes, unbounded writes.

07 Bundle Budget

JS bundle size measured against a budget you set.

VISUAL EXAMINERS

11 checks on your running app.

They run in parallel on every page the flow visits, and one slow check never holds up the rest.

01 Visual QA

Navigates and completes real user flows end to end.

02 Visual Regression

Pixel-diffs each screen against a baseline.

03 Console & Network

JS errors, failed requests, 4xx and 5xx responses.

04 Broken Links

Crawls every link for dead ends.

05 SEO & Meta

Titles, canonicals, and structured data.

06 Accessibility

WCAG AA: contrast, focus order, and labels.

07 Performance

LCP, CLS, and long tasks against budgets.

08 Content & Copy

Typos, tone, and placeholder text left in.

09 Cookie & Privacy

Consent, trackers, and compliance.

10 Vision Defect

A vision pass for layout and rendering bugs a DOM check misses.

11 Runtime Security

Security headers, mixed content, and secrets exposed in the bundle.

WORKFLOW & CONTROL

It fits your process, and you stay in charge.

OPT-IN TRIGGERS

A run starts only when you ask: the shipguarde label, an @shipguarde comment, or CI. Never a drive-by on every push.

PLAIN ENGLISH

Ask it to review the PR and test a URL together and it does both. No config language to learn.

REPLY TO RESOLVE

Reply “fixed” and it re-checks the file at the new commit, verifies the fix, and resolves the thread natively.

OPT-IN MERGE GATE

A block is advisory until you turn it on, then it fails a required check so branch protection can hold the merge.

ACTION & API

Trigger a run from any workflow, wait for the verdict, and gate the job exit code independently of the check.

APP MEMORY

Confirmed behaviours and your feedback become durable guidance that sharpens every future run, per project.

NOTHING RUNS, AND NOTHING BLOCKS, UNLESS YOU SAY SO
SECURITY

Safe access to your repo and preview.

“Do you run my code?”

No. We never run your repository’s own scripts, tests, or build. Your code is analyzed in an isolated, secret-starved sandbox using only our own tools, with a short-lived token scoped to the one repo and read-only. The GitHub App key and other tenants’ data never enter that sandbox, and its network access is limited to GitHub and package registries.

Secret-starved sandbox

Analysis runs in an isolated service that holds none of the platform’s keys.

Repo-scoped, read-only token

It gets a short-lived token scoped to the one repo, read-only. Never the GitHub App key.

Our tools only

We never run your repo’s scripts, tests, or build. No postinstall, no arbitrary execution.

Locked-down egress

Network access is limited to GitHub and package registries. No internal services, no metadata.

THE PLATFORM

The details that make it dependable.

MODEL-AGNOSTIC

The best model per task: a fast one for breadth, a stronger one for the quality gate. Swappable by configuration.

MERGE-BASE ACCURACY

Diffs are computed against the merge base, so a branch behind its target is reviewed for its real changes, nothing more.

RUN PROFILES

Quick, Standard and Thorough trade depth for speed, and large PRs are scoped to the highest-signal changes.

EMAIL & SLACK

A run-completion certificate by email, plus per-run recipient lists and Slack for the people who need the ruling.

AUDITABLE TRACES

Every step an examiner took is replayable, so a verdict is something you can inspect, not a black box.

NATIVE TO GITHUB

Status checks, inline comments, sticky summaries, thread resolution and check re-runs, inside the flow you already use.

A VERDICT YOU CAN INSPECT, NOT A BLACK BOX
Join the free 30-day pilotSee pricing

Code review checks the diff. ShipGuarde also checks the running product, so a release does not ship on the hope that nothing broke.

Join the free 30-day pilotStart a 7-day trial

NO CREDIT CARD · CONNECT GITHUB IN UNDER FIVE MINUTES · CANCEL ANY TIME

ShipGuarde

RELEASE CLEARANCE BUREAU
ISSUING AUTHORITY FOR SOFTWARE RELEASES
[email protected]

PRODUCT

  • Features
  • PR Reviews
  • Visual QA
  • Compare
  • Integrations
  • Pricing

RESOURCES

  • Docs
  • How it works
  • Use cases
  • Sample report
  • Founding pilot
  • Blog
  • Changelog
  • FAQ
  • Support

COMPANY

  • About
  • Security
  • Status
  • Contact us
  • Privacy
  • Terms
  • Refunds
  • Sub-processors
FILED · SG-482 · ACME-COMMERCEEST. 2026