How it works

From connected repo to fixable findings

Four steps, no agents to install, and your source code never leaves your control more than it must.

$ openrouting scan --explain
✓ 1 connect pick a GitHub repo + branch
✓ 2 sandbox no network, read-only, non-root
✓ 3 review a specialist agent per finding
✓ 4 fix triage, track, re-scan
clone deleted when the scan ends
$ 
1

Connect a repository

Sign in with Google or GitHub and connect your GitHub account. OpenRouting needs read access to list your repositories and clone them for scanning. Pick a repository and a branch.

2

Scan in an isolated sandbox

Each scanner runs in its own locked-down container with no network access, a read-only copy of your code, dropped privileges, and CPU, memory and time limits. Your code is read, never executed.

3

AI review of every finding

Proven scanners detect issues; then Claude reads each finding next to the surrounding code and decides whether it's real, with a confidence score, an explanation, and a suggested fix. Secrets are redacted before anything reaches the model.

4

Fix and track

Work through the findings that matter, mark false positives and accepted risk, and watch the open count fall over time. Fixed issues close themselves when a scan no longer sees them.

Questions

Does OpenRouting run my code?

No. OpenRouting clones your repository and reads the files. It never installs dependencies, builds the project, or runs scripts from it. Scanners run in sandboxed containers with no network access.

What does it scan?

Code flaws (Semgrep), leaked secrets including git history (Gitleaks), and infrastructure misconfigurations (Trivy). It also detects and reviews LLM-agent setups.

Is my code sent to an AI model?

Only the lines around each finding, with secrets redacted first — never your whole repository. AI review runs on Amazon Bedrock.

How long does a scan take?

A typical repository scans in under a minute for detection; AI review adds time proportional to the number of findings.

Do you keep a copy of my code?

No. The clone is deleted when the scan finishes. OpenRouting stores each finding's flagged lines so you can review it, and nothing else from your code.

Ready to try it?

Get started free