Connect a repository
Sign in with Google or GitHub and connect your GitHub account. OpenRouting needs read access to list your repositories and clone them for scanning. Pick a repository and a branch.
How it works
Four steps, no agents to install, and your source code never leaves your control more than it must.
$ openrouting scan --explain ✓ 1 connect ✓ 2 sandbox ✓ 3 review ✓ 4 fix clone deleted when the scan ends $
Sign in with Google or GitHub and connect your GitHub account. OpenRouting needs read access to list your repositories and clone them for scanning. Pick a repository and a branch.
Each scanner runs in its own locked-down container with no network access, a read-only copy of your code, dropped privileges, and CPU, memory and time limits. Your code is read, never executed.
Proven scanners detect issues; then Claude reads each finding next to the surrounding code and decides whether it's real, with a confidence score, an explanation, and a suggested fix. Secrets are redacted before anything reaches the model.
Work through the findings that matter, mark false positives and accepted risk, and watch the open count fall over time. Fixed issues close themselves when a scan no longer sees them.
No. OpenRouting clones your repository and reads the files. It never installs dependencies, builds the project, or runs scripts from it. Scanners run in sandboxed containers with no network access.
Code flaws (Semgrep), leaked secrets including git history (Gitleaks), and infrastructure misconfigurations (Trivy). It also detects and reviews LLM-agent setups.
Only the lines around each finding, with secrets redacted first — never your whole repository. AI review runs on Amazon Bedrock.
A typical repository scans in under a minute for detection; AI review adds time proportional to the number of findings.
No. The clone is deleted when the scan finishes. OpenRouting stores each finding's flagged lines so you can review it, and nothing else from your code.