The change sets the scope.
A review starts with the final diff and the context you select: callers, types, configuration, and nearby code. Your agent shows a manifest before sending local files. For a public or connected repository, the service can retrieve the diff and available context at the reviewed ref.
The goal is not to audit every line. It is to understand what this change can break, including effects outside the edited files.
Your agent prepares the change.
Review passes propose bugs. A skeptic tests each claim.
Your agent checks the evidence. You decide.
Find a failure. Then try to disprove it.
The protocol looks for different kinds of failure. In the orchestrated path, reviewers work independently; other engine paths use separate passes. Engines and models may change, but every finding still has to show a concrete failure.
- LogicConditions, boundaries, calculations, and defaults.
- StateRaces, retries, lifecycle, and cleanup.
- ContractsCallers, data shapes, nulls, and compatibility.
- Error pathsFailures, authorization gaps, and unsafe inputs.
- CalibrationClaims, limits, and tests that disagree with the code.
Duplicate candidates are combined. The skeptic checks reachability, guards, and missing context. A plausible story is not enough; a finding needs a concrete scenario grounded in the code.
Every finding is something you can check.
Each result names the location, severity, and failure scenario. Your coding agent checks it against the repository and returns REAL, NOT_REAL, or UNCLEAR, with a reason. Finding a possible bug and confirming it are separate steps.
Two requests spend the same credit.
Both requests read the balance before either writes the debit. Each proceeds with the same available credit.
- LOCATION
- Balance check → debit write
- TRIGGER
- Two concurrent requests on one account
- VERIFY
- Check whether a transaction or lock makes that sequence impossible.
The standard charge is $10 when a review has at least one confirmed medium-or-higher bug, no matter how many. Minor-only, rejected, unclear, and clean results cost $0. Your first bug-finding review is free. Billing happens when verdicts are submitted.
An isolated workspace, not open access.
Each review runs in its own VM on Sprites by Fly.io. Network access is limited to model inference and the OhMyBug API. Review code never runs in your production environment.
Fast review
The diff and selected files anchor the review. The reviewers can ask for more context while it runs.
Optional deep review
After a fast review, we may offer a full-repository review when more context could help—for example, after a clean or incomplete run. It needs your approval and repository access. The reviewed diff still sets the scope.
Temporary input is not zero retention.
We do not keep a permanent repository copy. We keep some review records so you can inspect results and we can investigate failures.
| Material | What happens to it |
|---|---|
| Submitted diff and files | Removed from the database after the sandbox receives them. A retry may temporarily store them again. |
| Repository snapshot | Temporarily cached while parallel reviews seed their sandboxes. The retention and seeding limits are in the privacy policy. |
| Run transcript | Kept for 7 days after a completed review; 30 days after a failed review. |
| Report and findings | Kept in your review history until account deletion. They can quote code. |
We do not use submissions to train models. Inference providers process them under their API terms. See the privacy policy for processors, regions, retention, and deletion requests.
More evidence, not proof.
Reviewers can miss bugs or be wrong. Missing files, time budgets, and model limits affect the result. Independent passes reduce reliance on one reading; they do not remove model errors.
Keep CI, tests, human judgment, and any specialist security review your system needs. Re-review meaningful fixes on the new diff. A clean review means this run found no supported bug—not that none exists.
Ready for a second look?
Send your next diff.
This note describes the review workflow, not a warranty or benchmark. FAQ · Terms · Privacy policy