Skip to content
Our open-source security work.See the research

FAQ

Questions people ask before they connect a repo

Short answers on setup, pricing, data handling and what to do when a finding needs human context.

Product

What does Andesyte Code Security do?

Andesyte audits changed code in pull and merge requests, then posts inline findings with severity, CWE context and a suggested fix. It also checks dependencies against OSV.dev and scans added lines for common secrets.

How is this different from CodeRabbit, Snyk or Socket?

Andesyte is security-only. It looks for exploitable regressions in your own code and explains them where the change is reviewed. Dependency, supply-chain and general code-review tools cover different parts of the development lifecycle. See the comparison guides.

Setup

How do I install it?

Open Connect and choose GitHub or GitLab. The first audit appears on your next pull or merge request.

Do I have to write a config file?

No. Andesyte reads AGENTS.md, CLAUDE.md, .cursorrules and .github/copilot-instructions.md from your default branch, so existing suppression markers can apply to Andesyte too.

Pricing

How is Andesyte priced?

Public repositories are free. Pro is $19 per month for one developer working in private repositories. PAYG has no monthly base fee and charges measured model input and output tokens up to the monthly limit you set. Current plans, limits and credit rates live on the pricing page.

How is PAYG measured?

PAYG is based on measured AI work for one connected account, not headcount. The billing page shows settled usage, in-flight reservations and the amount remaining before your limit.

What happens at my usage limit?

Andesyte stops starting new billable AI work before the limit is exceeded. Eligible static, dependency and secret scanners continue independently.

Can Pro continue beyond its included allowance?

Not yet. Pro overage remains unavailable while its included allowance is calibrated. PAYG is available now for measured usage.

Data and security

Where does my code go?

Source code is processed for PR/MR review and is not used to train Andesyte models. Findings and operational metadata are retained so the product can show audit history and support suppressions. Read the security practices and current trust information.

Do model providers train on my code?

No. We use provider controls intended to prevent model vendors training on customer prompts and responses, and we do not train Andesyte models on your code.

Findings

Will Andesyte fill my code reviews with noise?

Andesyte is tuned for high signal. Best-practice and stylistic observations stay at information severity. Security regressions appear as inline review comments.

What if it gets a finding wrong?

Reply on the inline finding with @andesyteoss ignore to suppress that rule on that file for your installation.

Can I ask Andesyte questions about a finding?

Yes. Reply on an inline finding with @andesyteoss and your question. The answer lands in the same PR thread.

Working with us

Can your researchers review a system directly?

Yes. We run focused reviews across applications, cloud infrastructure, source control and release pipelines. See how our security reviews work.

How do I report a bug or vulnerability?

Bug or feature request: use the contact form. Security vulnerability: use vulnerability disclosure instead.

Still need an answer?

Send the question with enough context for a person to route it.