ShipGuardeRELEASE CLEARANCE BUREAU
How it worksUse casesDocsPricing
AI CODE REVIEW · ON DEMAND

Reviewed when
you ask.

Nothing runs until you ask, so there is no drive-by comment on every commit. One verdict, comments on the exact changed lines, and a merge gate only if you want one.

Join the free 30-day pilotWhat it looks for
GITHUBacme-commerce/storefront · pull/482
SHIPGUARDE COMMENTED2 min ago
VerdictDo not ship · 1 critical · 1 major
results.component.ts:42OnPush with an array filtered in place. The view will not update when the query changes.
Scope8 files reviewed · live checks on the preview
HOW YOU TRIGGER IT

You decide which PRs get reviewed.

Reviews are explicit by design. Four ways to ask, and nothing happens until you do.

THE LABEL

Drop the shipguarde label on a pull request and a review starts.

A COMMENT

@shipguarde run, or scope it: @shipguarde review src/api.

THE CHECK

Hit Re-run on the ShipGuarde check to review the latest commit.

CI

Call the GitHub Action or API with an sg_pat_… key and gate the job on the verdict.

NOTHING RUNS UNTIL YOU ASK
WHAT IT REVIEWS

Signals that catch real bugs, not style nits.

Code review focuses on what your diff introduces, validated in two passes to keep the noise down.

01 Code Review

Correctness, security and contract defects introduced by the change, with a concrete trigger named for each.

02 Lint

New linter issues the diff introduces. Pre-existing noise is ignored.

03 Security

Leaked secrets via gitleaks and SAST findings via semgrep.

04 Dependencies & License

Vulnerable packages and license-policy violations.

05 Schema Drift

OpenAPI and GraphQL surface changes flagged for explicit review.

06 Migration Safety

Risky SQL and Prisma migrations: drops, non-concurrent indexes, unbounded writes.

07 Bundle Budget

Changes that push the shipped bundle past the size you agreed to.

CONVERSATIONAL

Reply in the PR. It listens.

ShipGuarde reads replies to its own comments and acts on them, with no dashboard round-trip.

tell it once. it remembers next time.

DISMISS

Reply “false positive” or “intentional” and it suppresses the finding, and remembers it on future runs.

MUTE

@shipguarde ignore src/legacy stops findings under a path. ignore all mutes the project.

TEACH

Collaborators can leave durable project learnings it applies going forward.

LEARNINGS APPLY ON EVERY RUN AFTERWARDS
THE VERDICT

One decision, comments that land.

Every run ends in a single verdict, with inline comments anchored to the exact changed lines.

STATUS CHECK

A GitHub check carrying the verdict and a severity breakdown.

INLINE COMMENTS

Anchored to real diff lines. Off-diff findings go to the summary, never a random line.

STICKY SUMMARY

Severity counts, scope, and what is “fixed since last review”.

ADVISORY BY DEFAULT · OPT IN WITH failCheckOnBlock TO MAKE IT A HARD GATE
SECURITY

Safe access to your repo and preview.

“Do you run my code?”

No. We never run your repository’s own scripts, tests, or build. Your code is analyzed in an isolated, secret-starved sandbox using only our own tools, with a short-lived token scoped to the one repo and read-only. The GitHub App key and other tenants’ data never enter that sandbox, and its network access is limited to GitHub and package registries.

Secret-starved sandbox

Analysis runs in an isolated service that holds none of the platform’s keys.

Repo-scoped, read-only token

It gets a short-lived token scoped to the one repo, read-only. Never the GitHub App key.

Our tools only

We never run your repo’s scripts, tests, or build. No postinstall, no arbitrary execution.

Locked-down egress

Network access is limited to GitHub and package registries. No internal services, no metadata.

Install the app, drop the label, and the first verdict lands in about a minute.

Join the free 30-day pilotRead a sample report

Code review checks the diff. ShipGuarde also checks the running product, so a release does not ship on the hope that nothing broke.

Join the free 30-day pilotStart a 7-day trial

NO CREDIT CARD · CONNECT GITHUB IN UNDER FIVE MINUTES · CANCEL ANY TIME

ShipGuarde

RELEASE CLEARANCE BUREAU
ISSUING AUTHORITY FOR SOFTWARE RELEASES
[email protected]

PRODUCT

  • Features
  • PR Reviews
  • Visual QA
  • Compare
  • Integrations
  • Pricing

RESOURCES

  • Docs
  • How it works
  • Use cases
  • Sample report
  • Founding pilot
  • Blog
  • Changelog
  • FAQ
  • Support

COMPANY

  • About
  • Security
  • Status
  • Contact us
  • Privacy
  • Terms
  • Refunds
  • Sub-processors
FILED · SG-482 · ACME-COMMERCEEST. 2026