Stop mergingunreviewed AI code.
CodeVetter is a desktop review cockpit for the diffs your agent ships. Catch what Cursor, Claude Code, and Devin missed — vulnerabilities, regressions, and silent drift. Runs entirely offline.
Token concatenated directly into query body. Allows arbitrary read/write against sessions table.
Built for the way agents ship code.
Cursor, Claude Code, Devin — they merge fast and miss things. CodeVetter is the second pair of eyes that runs on your laptop.
Diff-aware review engine
Parses your patch, traces affected call sites, and feeds the LLM a focused context window. No shotgun prompts, no hallucinated files.
Bring your own key
Anthropic, OpenAI, OpenRouter. Keys live in your OS keychain. Zero proxying through us.
Runs offline
Tauri binary. SQLite under the hood. No backend, no signup.
Git-native
Staged diffs, ranges, branches. Drop into any repo.
Severity-tiered
Critical → high → medium. Mapped to CWE & OWASP.
Patch suggestions, not pep talks
Every finding ships with a concrete code edit you can apply or discard. Reasoning is shown, not narrated.
Three steps. Zero ceremony.
No accounts, no setup wizards, no SaaS dashboard. Open the app, plug in a key, ship safer code.
Drop in your diff
Stage changes, paste a patch, or hand it a branch range. CodeVetter parses files, hunks, and call-sites locally.
Pick the model
Choose Claude, GPT, or anything OpenRouter routes. Switch per-review. Token usage is live-tracked, never proxied.
Triage the verdict
Findings ranked by severity, mapped to CWE, with concrete patch diffs. Apply, edit, or dismiss with one keystroke.
Any model. Your key.
CodeVetter is provider-agnostic. Test the same diff across models, pin one per repo, or rotate as new releases land.
Anthropic
Recommended for security review
OpenAI
Fast diffs · robust reasoning
OpenRouter
300+ models · single API key
Local LLMs
100% private · air-gapped
Free for solo. Honest above it.
No tokens, no per-review fees. We don't see your code, so we can't bill on it.
The full desktop binary. Bring your own LLM key. Use forever, no strings attached.
Shared review presets and org policy rules. Everything stays on each machine.
Air-gapped installs, custom model routing, and dedicated security engineering.
Stop trusting agents blindly.
Install in 30 seconds. First review in under a minute. Your code never leaves your machine.