# CodeRabbit

> Reads every change in a pull request, comments on it line by line and proposes corrections before a human starts reviewing.

- Vendor: CodeRabbit, Inc.
- Canonical URL: https://www.convios.com/en/toolbox/coderabbit
- Language version: https://www.convios.com/de/werkzeugkasten/coderabbit
- Area: Product & engineering · Cluster: testing and review
- Role: Off-the-shelf product · Origin: AI-native
- As of: 2026-09-08 · Reviewed: 2026-09-08 · Author: Dr. Oliver Gausmann, Convios GmbH
- Toolbox: https://www.convios.com/en/toolbox — Markdown: https://www.convios.com/en/toolbox.md

## Verdict

Prevents falling behind: Teams writing code with assistants produce more changes than human review can absorb. The bottleneck moves from writing to approving, and anyone working without a machine pre-check notices it first in the cycle time of their pull requests. No edge comes out of this: a competitor can sign the same subscription on the same day. What makes a difference are the rules the reviewer is given, and the question of who answers for a finding that was missed.

## Suitability by company size

- Solo: suitable — Twenty-four dollars a month billed annually, thirty billed monthly. Public repositories are reviewed free of charge, and billing only covers people who open pull requests themselves.
- Mid-market: suitable — Twenty-four to seventy-two dollars per developer per month. One question decides the tier: if a security review is needed on every pull request, a seat costs seventy-two dollars instead of twenty-four, three times as much for the same developers.
- Enterprise: suitable with caveats — Conditional, and the condition is the plan. Single sign-on, role-based permissions, logging, self-hosting and running in an EU environment all sit in the enterprise tier, which carries no list price. Anyone who needs those five points to clear procurement negotiates a contract rather than ordering a subscription.

## Vendor staying power

Funded: CodeRabbit started in 2023 and is therefore too young for the established classification. Audited accounts are not available, profitability is not documented, and every customer and volume figure comes from the company itself. Three consecutive rounds within two years support the funded classification, most recently USD 143m in August 2026 at a valuation of USD 1.5bn. That valuation is the price agreed in a private round, not a market quote. The round is a primary transaction: the company names international expansion plus research and product development as the use of proceeds, so the money goes into the company. Ongoing operation is documented independently of that, because the subprocessor list in the trust centre carries dated change notices and the vendor has publicly worked through a January 2025 security incident with a timeline.

- Series C: USD 143m at a USD 1.5bn valuation: USD 143m, co-led by Atomico and Smash Capital, with BMW i Ventures, Datadog, Hirtle Callaghan, SineWave Ventures and Scenic Management as new investors and CRV, Scale Venture Partners, Flex Capital, Pelion Venture Partners, Harmony Partners and Engineering Capital as existing ones. Valuation USD 1.5bn. The figures come from the company announcement. (source: https://www.coderabbit.ai/newsroom, as of 2026-08-12)
- Series B: USD 60m: USD 60m, eleven months before the Series C. Taken together the two rounds show a shortening gap between financings, which points to capital requirements as much as to demand for shares. From the outside there is no way to decide which of the two readings holds. (source: https://www.coderabbit.ai/newsroom, as of 2025-09-16)
- Founded 2023, volume figures stated by the vendor: Founded in 2023. In its press kit the vendor states more than 17,000 customers, more than 2m pull requests reviewed per week and more than 75m code issues found. All three figures are company statements with no disclosed methodology and no external audit. (source: https://www.coderabbit.ai/press-kit, as of 2026-09-08)
- January 2025 security incident, publicly addressed: On 24 January 2025 researchers from Kudelski Security reported through the vendor's disclosure programme that the RuboCop linter was running outside the sandboxed environment. By the vendor's account the service was switched off within one hour, all affected credentials were rotated within three hours and the fix shipped within twelve hours; no access to customer data was identified. The chief executive's statement is dated 19 August 2025, around seven months after the report. The incident touched exactly the product's core exposure, namely running someone else's code. (source: https://www.coderabbit.ai/blog/our-response-to-the-january-2025-kudelski-security-vulnerability-disclosure-action-and-continuous-improvement, as of 2025-08-19)
- Subprocessor change notices in practice: The trust centre carries dated change notices for the subprocessor list, most recently on 4 August 2026 with three additions and on 29 April 2026 with twelve additions and two removals. The thirty-day advance notice promised in the data processing addendum is therefore demonstrably in operation rather than a mere contractual formula. The two notices give different contact addresses for objections. (source: https://trust.coderabbit.ai/subprocessors, as of 2026-08-04)

## Cost of leaving

Low: The findings sit as comments in the pull requests of your own version control and stay there when the subscription ends. What is left behind is the setup work: learned preferences, custom pre-merge checks and the history of security findings do not travel to the next vendor. A switch therefore costs days of configuration, and no data has to be recovered for it.

## Regulation and data

| Point | Finding | Evidence | As of |
|---|---|---|---|
| Data processing agreement | yes, publicly available and automatically part of the contract via the terms of service — Clause 7.4 of the terms of service expressly incorporates the data processing addendum into the agreement, so no separate signature is required for it to apply. The vendor provides a signed version on request. The addendum covers all plans. | evidenced | 2026-09-08 |
| Storage location | US by default; operation in an EU environment is offered on the enterprise plan only — The privacy policy dated 10 December 2025 places the servers in the United States. The pricing page lists EU SaaS deployment in the enterprise tier only. The processing chain matches: of thirty listed subprocessors, twenty-nine sit in the US, and the only one based in Europe handles documentation review. An EU location is therefore reachable, but it is neither the default nor available without negotiating a contract. | partially evidenced | 2026-09-08 |
| Subprocessors | yes, complete public list with purpose and country, readable without an access request — Annex III of the data processing addendum points to the trust centre, and the list is readable there without a login and without a non-disclosure agreement. As of the retrieval date it carries thirty entries with purpose and country, among them Anthropic and OpenAI for the models, Google Cloud, Cloudflare and Vercel for operations, and LanceDB as the vector database. Twenty-nine entries name the US, one names Germany. Anyone reading only the vendor's privacy policy will not find this chain. | evidenced | 2026-09-08 |
| Third-country transfer | yes, transfer to the US; covered by the EU standard contractual clauses inside the data processing addendum — Clause 8.2 incorporates the standard contractual clauses and assigns modules one, two and three to the respective roles; the addendum's annexes complete the annexes of the clauses. For transfers out of the United Kingdom, either the data privacy framework or the same clauses apply. A law firm in Bonn is named as representative under Article 27 of the General Data Protection Regulation, and a company in Peterborough for the United Kingdom. The transfer clause reaches further than the country list: it permits processing anywhere the vendor or its subprocessors operate. | evidenced | 2026-09-08 |
| Training on customer data | model training contractually excluded, including for the model providers; storage of code content as vectors runs by default with a right to opt out — Clause 3.3 of the terms of service commits that neither the vendor nor the model providers it uses will train models on customer code, and names OpenAI and Anthropic under a zero data retention arrangement; the corresponding evidence sits in the trust centre. The privacy policy describes a second use alongside this: the vendor stores data to improve reviews, mainly as vector embeddings, and that storage is switched on until the customer opts out. The contract therefore governs training while the privacy policy governs reuse, and the two statements live in different documents. Anyone wanting to keep code out entirely has to switch the storage off. | partially evidenced | 2026-09-08 |
| Retention and deletion | return or deletion after contract end on request; backups expressly excluded, no period stated — Clause 6 of the data processing addendum promises return or deletion, but ties it to a customer request. Data in backup systems is expressly excluded and removed according to the vendor's deletion practices, with no period stated. A deletion certificate likewise reaches the customer only on request. The section of the privacy policy whose heading covers retention and proprietary code puts figures only against personal data. | partially evidenced | 2026-09-08 |
| Certifications | SOC 2 Type II, ISO/IEC 27001:2022, SOC 3, a GDPR audit report and a penetration test; the reports themselves only after an access request — The trust centre lists the attestations with standard and version, the reports themselves sit behind an access request, and the scope stays undisclosed. The annex to the data processing addendum is worded more cautiously than the portal: it states that the vendor operates a management system that complies with the requirements of ISO/IEC 27001:2022. A compliance statement and a certification are two different things, and without sight of the report there is no way to settle which wording matches the facts. | partially evidenced | 2026-09-08 |
| EU AI Act, Article 50 | the vendor names the regulation in its contracts and shifts compliance to the customer; a statement about its own duties is missing — Clause 4.2 of the terms of service prohibits uses matching the practices banned under Article 5; the partner version additionally prohibits deployment in high-risk systems within the meaning of the regulation. The vendor says nothing about its own role or about the transparency duties in Article 50. For German employers a different clause in the same section matters more: the vendor expressly prohibits using the tool or its analytics for decisions about employment relationships, for allocating tasks by personal characteristics, or for evaluating the performance of employees. Turning the tool's metrics into a developer appraisal therefore breaches the contract, before any question of works council codetermination even arises. | partially evidenced | 2026-09-08 |
| Audit logging | enterprise plan only; scope, retention period and export are not publicly stated — The pricing page lists logging together with role-based permissions and single sign-on in the enterprise tier and names it in none of the three list-price tiers. What the log captures, how long it is kept and whether it can be exported into your own systems appears nowhere in the public documents. Anyone who has to plan for evidentiary obligations cannot do so from the published information and depends on the contract negotiation. | partially evidenced | 2026-09-08 |

## Cost

- Entry: Essentials at twenty-four dollars per developer per month billed annually, thirty billed monthly. Team at forty-eight or sixty, Advanced at seventy-two billed annually. The enterprise plan carries no list price. Public repositories are reviewed free of charge, and billing only covers people who open pull requests. (as of 2026-09-08)
- Where it gets expensive: In two places. Every plan includes a number of reviews per developer per hour; beyond that each reviewed file costs twenty-five cents, added to the monthly invoice. The cloud and Slack agents bill at forty cents per agent minute. Both items can be capped with a monthly spending limit, and without that cap the invoice grows with the number of changes rather than the number of seats.

## Three routes compared

### SonarQube from Sonar

Static analysis is the grown answer to the same question and bills by lines of code, in the cloud from thirty-four dollars a month for a hundred thousand lines, plus SonarQube Server for running it in your own data centre. Large companies stay with it for three reasons: in-house operation is available without negotiation, billing by lines of code decouples cost from headcount, and the same code produces the same finding on every run. That repeatability is what evidentiary obligations hang on. What it lacks is any grasp of intent: a rule recognises a pattern, not a flaw in the reasoning of a process.

### Greptile and the other AI-native reviewers

Greptile charges thirty dollars per seat per month, placing it between the Essentials and Team tiers; self-hosting there is likewise reserved for the enterprise plan. The price gap inside this group is small, and the choice turns on other things: how many repositories are looked at together, and whether custom checks apply before merging. What the whole group gives up is repeatability. Two runs over the same code can differ, and the rule base belongs to the vendor, who can change it without notice.

### Your own review step in the build chain

Feasible with Claude Code as the build tool in the pipeline, LiteLLM as the model gateway, Langfuse for logging model calls and GitHub or GitLab as the anchor for the comments. Reckoning with ten to fifteen person-days for a first dependable version and half a day a month for recalibration, at a daily rate of 800 euros the build comes out above a Team subscription for ten developers in the first year and does not close the gap in the second either. It pays off where the review rules come from inside the house and no code may leave the network. Failure rarely comes from the technology and usually from calibration: a reviewer that reports too much gets clicked away within two weeks, and the work of matching its criteria against real human judgements never ends.

Recommendation by size:

- Solo: Take it. Free on public repositories, otherwise the cheapest route to a second pair of eyes.
- Mid-market: Take it and settle in the same move who signs off on a finding and what never gets merged without human approval. Switch off the storage of code content if it is unwanted.
- Enterprise: Negotiate before procurement on the enterprise plan: EU environment, the scope and retention of logging, and the scope of the attestations, all in writing. Involve the works council in parallel, because the tool collects metrics per developer.

## Context

- Implements method: [DORA Delivery Diagnostic](https://www.convios.com/en/methods/dora-delivery-diagnose) — The diagnosis measures throughput and stability as a pair, and a machine reviewer acts exactly there: it shortens the lead time of a change, while the change failure rate shows whether the gained tempo is real or merely displaced.
- Implements method: [Calibrated Evaluation Loop for AI Outputs (Criteria Drift)](https://www.convios.com/en/methods/eval-calibration) — An automatic reviewer is only worth having once its criteria are matched against human judgements, and the finding list from the first few weeks is precisely the material that reveals which rules hold up with the team and which get clicked away as noise.
- Implements method: [Leading AI Agents as Team Members](https://www.convios.com/en/methods/ai-agents-as-team-members) — The method requires a written role for every agent and a human who signs off, and a reviewer that applies fixes with one click is the point where that sign-off is either named or quietly passes to the agent.
- Implements method: [DORA AI Capabilities Model (Seven AI Capabilities)](https://www.convios.com/en/methods/dora-ai-capabilities) — A clear stance on AI ranks high among the seven capabilities, and the decision about storing code content and about the place of processing forces a company to put that stance in writing for the first time.
- Alternative: [Claude Code](https://www.convios.com/en/toolbox/claude-code)
- Displaces: A second developer's first pass over routine changes, Separately procured subscriptions for linters and static security scanning in smaller teams

## Evidence

- Plans, prices, usage-based add-ons, and which of single sign-on, logging, self-hosting and EU environment sit in the enterprise tier — https://www.coderabbit.ai/pricing (as of 2026-09-08)
- Data processing addendum: incorporation of the standard contractual clauses, subprocessor rules, return and deletion, and the security annex with the ISO/IEC 27001:2022 statement — https://www.coderabbit.ai/legal/dpa (as of 2026-09-08)
- Terms of service: the training exclusion covering the model providers, incorporation of the data processing addendum, the AI Act clauses and the prohibition on performance evaluation — https://www.coderabbit.ai/legal/terms-of-service (as of 2026-09-08)
- Privacy policy dated 10 December 2025: server location, storage of vector embeddings to improve reviews including the opt-out, and the Article 27 representatives — https://www.coderabbit.ai/privacy-policy (as of 2026-09-08)
- Trust centre: subprocessors with purpose and country, attestations with standard and version, dated change notices — https://trust.coderabbit.ai/subprocessors (as of 2026-09-08)
- Funding rounds with date, amount and investors — https://www.coderabbit.ai/newsroom (as of 2026-08-12)
- Year of founding and the vendor's volume figures on customers, pull requests reviewed and code issues found — https://www.coderabbit.ai/press-kit (as of 2026-09-08)
- The vendor's account of the January 2025 security incident with a timeline — https://www.coderabbit.ai/blog/our-response-to-the-january-2025-kudelski-security-vulnerability-disclosure-action-and-continuous-improvement (as of 2025-08-19)
- Price and self-hosting of the AI-native comparison product Greptile — https://www.greptile.com/pricing (as of 2026-09-08)
- Pricing by lines of code and self-managed operation of the off-the-shelf product SonarQube — https://www.sonarsource.com/plans-and-pricing/ (as of 2026-09-08)
