Review what matters. Enforce your standards with AI.
Every pull request is reviewed against your team's standards, written as rules in plain Markdown. When a reviewer dismisses a finding, OpenTremor remembers that decision on the next scan.
Every pull request is reviewed against your team's standards. Reviewer decisions carry over to the next scan.
- GitHub App
- Self-hosted or Cloud
- Open source
100 free analyses on Cloud. Or self-host it: unlimited, forever. No sales call either way.
opentremor / reviewPending: waiting for a person to decideDirect resource instead of approved module
aws_iam_role.deploy skips your IAM module, so its permission boundary never applies.
Missing required tags
aws_s3_bucket.reports has no cost-center or team tag.
Cost increase potential
aws_instance.worker: low confidence, so the check waits for a person instead of guessing. Sent to #platform-reviews in Slack.
S3 bucket allows public read access
aws_s3_bucket.static_site: suppressed by a reviewer on #471 (“public by design”). Still suppressed on this scan.
Agents now write pull requests faster than your team can read them. Reviewer time didn't grow with them.
So define what matters once, and apply it to every PR. Your engineers start on the changes that actually need them.
So define what matters once, and apply it to every PR.
Agent-written code also brings a new risk: text written for the next bot that reads it, not for you. Every added line is checked for it. This check is deterministic and free on every plan.
How it works
One review gate. Security, policy and style are just rules inside it.
You aren't buying a code reviewer plus an IaC scanner plus a governance platform. It's one check on every pull request, and your rules decide what it looks for.
- 1
Define your standards once
Write each rule as a Markdown paragraph, the way you'd explain it to a new engineer. Your rules apply alongside the built-in security rules, which every org has on by default.
Each rule is a plain Markdown paragraph, applied alongside the built-in security rules.
## Platform standards
- **PLAT-001 (CRITICAL/HIGH):** an added line declares a raw `aws_iam_role` instead of our `iam-role` module, which applies the permission boundary.
- 2
Every pull request is reviewed
Install the GitHub App once. It needs no workflow file and no setup per repo.
Install the GitHub App once. Low-confidence findings wait for a reviewer.
- Each change is analyzed by the pack for its file type, against the rules that apply to it.
- Findings appear in the pull request, as a comment and as a GitHub check.
- When it isn't confident, it doesn't guess: the check waits for a reviewer to decide.
- The reviewer who needs to decide gets a Slack message or webhook, even if they aren't watching the PR.
- 3
Decide once. OpenTremor remembers.
A reviewer can acknowledge, suppress or mark a finding as a false positive, in the app or by replying on the PR. The decision holds on the next scan, and it's recorded against the rule that raised the finding.
Dismiss a finding once and the next scan remembers.
AcknowledgeSuppressFalse positiveEvery decision is recorded against its rule, so you can see which rules your reviewers actually trust. Findings are never suppressed automatically.
Push a plan or PR
Covered today: Terraform plans (terraform-plan), Terraform diffs (terraform-code-change) and Python diffs (python-code-change). Each pack is a plain Python package, and you can register your own. Terraform and Python. See packs
Already running Semgrep, Checkov, SonarQube or GitHub Advanced Security?
Keep them. OpenTremor reviews what traditional scanners can't express.
Scanners are good at known-bad syntax. Most of your standards aren't syntax. They live in a wiki, and today a human checks them by hand on every PR.
| Question | Pattern-based scanners | OpenTremor |
|---|---|---|
| A rule is | A pattern or policy written in the tool's query language or code | A Markdown paragraph that anyone on the team can write and review in a PRPlain Markdown, not a query language |
| It catches | Known-bad constructs: a public ACL, a wildcard IAM action, a hardcoded key | Intent against your conventions: a raw role where your module belongs, a query missing tenant scoping, a blocking call in an async pathYour engineering conventions, not just known-bad syntax |
| When unsure | Always gives a pass or fail | Reports its confidence. Low-confidence findings keep the PR check pending and notify a person.Waits for a person instead of guessing |
| Your decisions | Dismissed one finding at a time | Recorded against the rule, so you can see which rules to rewrite or drop |
| Agent-written code | Mostly out of scope | Checks every added line for text aimed at your review bots, not at you |
They work well side by side. OpenTremor isn't a linter or a SAST replacement. The Python pack says so itself: ruff and mypy already cover style, so it doesn't.
Built to pass your security review
Your infra, your LLM, your SSO.
Try OpenTremor
Start today, without a procurement process.
Cloud
100 free analyses
- Create an org and install the GitHub App
- Every pack and every feature. Nothing is gated by plan.
- After that, a dedicated instance with usage-based pricing
Self-hosted
Unlimited, forever
- Open source under the AGPL v3
- Runs with Docker Compose on your own machine
- Your LLM key, your network, your data retention
Need a support contract, a dedicated instance, or a pack built for your internal formats? See Enterprise & Services