Enterprise

Fixes you can trust, at organization scale.

Install the GitHub App on the organization. Codna reviews every pull request, opens fixes you approve, and never merges. Run the CLI and the Action on your own machines with your own keys.

Enterprise

ORG

One install

Install on the organization and pick the repositories. Link the install to one Codna account. Admins can turn automatic fixes off from the account page.

KEY

Your keys

Bring a model key and Codna calls your provider directly. Keys live in the OS keychain and are never printed. Or use the managed allowance.

PR

Every PR explains itself

Reviews post findings with severity and confidence and a clear verdict. Fix PRs state the issue, root cause, symbols and confidence. You merge.

SRV

Server licence

Run Codna on your own production servers under a per-Compute-Unit licence. Your hardware, your network, your keys.

Ways to run it

Choose where Codna runs.

Codna runs the same commands everywhere. Pick the surface that fits your controls; add another when you are ready.

On your machine

The CLI and the MCP server run locally with your own key. Understanding is offline and spends no tokens. No server to operate.

In your CI

thyn-ai/codna-action@v1 runs fix, review or secure on your own runners with your own key. It opens pull requests and never merges.

GitHub App

Hosted by Codna. Reviews every pull request, opens fixes from labels, comments and red checks, on the managed allowance or your key.

Server licence

Run Codna on your own production servers under a per-Compute-Unit licence. Talk to us for activation and terms.

Rollout

Adopt in stages.

You do not have to hand the agent the keys on day one. Widen the scope as trust is earned. Codna never merges, at any stage.

1

Review only

Install the App. Codna reviews every pull request read-only, with no write token and no shell. Findings carry severity, category and confidence. No code is changed.

2

Fix PRs you approve

Let collaborators with write access reply @codna fix on a finding, or label issues codna-fix. Each pull request states the issue, root cause, symbols and confidence. Your engineers review and merge.

3

Red checks open fixes

Let a failing check suite trigger a fix. Codna triages the failure first, so infrastructure failures cost nothing, and opens one fix per pull request head per day. Admins can turn automatic fixes off at any time.

Controls

What is real today.

Codna is a set of technical behaviours, not a certification. Here is what you can verify from the user's side of the screen.

What leaves your machine

Triage, the repository map and recall run offline. Only the evidence bundle or the diff reaches your model provider, with your key. During a review Codna also checks dependency claims against npm and PyPI, unless egress is fail-closed.

Every result explains itself

Reviews post findings with severity, category and confidence and end in a clear verdict. Fix PRs state the issue, root cause, symbols and confidence. Secrets are redacted in every output, and that cannot be turned off.

Least privilege

The App uses per-job, repository-scoped, short-lived tokens. The review agent holds no write token. Write tokens are scrubbed from environments that run repository code. @codna fix needs write access from the person who asks.

Your key, your provider

Bring a key from Anthropic, OpenAI, Google Gemini, Groq, Mistral, OpenRouter or xAI. Codna calls your provider directly. Your code is not used to train models unless you opt in.

Roll out in stages.

Start with review only. Add fix pull requests you approve. Then let red checks and labels open fixes, with the organization toggle in your hands.

Plan rollout

Frequently asked

Yes. The CLI and the GitHub Action run on your machines. Understanding runs locally for zero tokens. Only the evidence bundle or the diff reaches your model provider, with your key. The hosted GitHub App is optional.

No. With the CLI and the Action the key stays in your keychain or your CI secrets and Codna calls your provider directly. With the App you can use the managed allowance or add your own key on the account page.

Set privacy.egress to fail-closed in codna.yaml. Codna then runs your tests only when it can deny them network access at the kernel level, and makes no registry lookups during review. Secret redaction is always on. Write tokens are scrubbed from environments that run repository code.

Your code is not used to train models unless you opt in. See the privacy policy.

Per-job, repository-scoped, short-lived tokens. The review agent holds no write token. @codna fix requires write access from the person who asks. Admins can turn automatic fixes off for the organization. Every commit is authored by codna-ai[bot].

Codna ships as a CLI, an MCP server, a GitHub Action and a GitHub App, so teams adopt one surface at a time. Codna never merges: your branch rules, required checks and reviewers stay in charge.

Bring Codna to your organization.