Your AI writes the code.Who checks the code?
Automated trust scoring for every pull request. Catch AI-generated patterns, hallucinated dependencies, and security vulnerabilities — before they ship.
Trust Score: 72/100
Grade C — 3 findings
Threats hiding in AI-generated code·285 detected today
Features
Watch us catch threats in real time
Catch fake packages instantly
Real-time validation against npm, PyPI, Go, and RubyGems. Hallucinated packages get flagged before they become supply chain attacks.
{
"dependencies": {
}
}
Catch fake packages instantly
Real-time validation against npm, PyPI, Go, and RubyGems. Hallucinated packages get flagged before they become supply chain attacks.
{
"dependencies": {
}
}
Detect AI-generated code
AST analysis and ML heuristics identify AI-generated patterns — repetitive error handling, generic naming, clipboard boundaries.
AI-generated pattern — 94% confidence
Repetitive error handling, generic variable names
Block vulnerabilities at the gate
Automated vulnerability detection across every pull request. Policy gates enforce minimum trust scores before code ships.
Trust Score: 34/100
Grade F — blocked by policy
Trust scores you can act on
Every PR gets an A–F grade based on code quality, security, AI patterns, and dependency health. Track your codebase health over time.
Auto-fix with one click
AI suggests safe, context-aware fixes for every finding. Review the diff, accept or reject — your code, your call. No blind auto-merges.
Enforce governance policies
Set custom rules that match your team's standards. Block merges that don't meet your minimum grade, restrict AI-generated code ratios, or require review on critical paths.
1 rule failed — merge blocked until resolved
Full audit trail
Every analysis, finding, fix, and policy decision is logged with who, what, and when. Meet compliance requirements with exportable audit reports.
How It Works
Three steps to trusted code
From install to insight in minutes. No config, no CLI, no overhead.
Veriva
wants access to your repositories
Install the GitHub App
One click, zero config. Works with GitHub.com and Enterprise.
Open a pull request
Every push triggers a 3-layer analysis automatically.
Trust Score: 94
Get your Trust Score
An A-F grade as a GitHub check. Policy gates block bad code.
GitHub Integration
Results where you already work
Veriva posts results as GitHub check runs and PR comments — no context switching.
main from fix/authVeriva Analysis — Grade C (72/100)
| Dimension | Score |
|---|---|
| Security | 62/100 |
| Quality | 85/100 |
| Practices | 78/100 |
| Dependencies | 64/100 |
7 findings — 2 critical, 3 high, 2 medium
Top Issues
Hallucinated package: bcrypt-utils ( auth-service.ts:3 )
The package "bcrypt-utils" does not exist in the npm registry. This may be a slopsquatting attack.
Fix: Use bcryptjs (the real package) instead.
+ 6 more findings — view full report
Powered by Veriva · AI Code Governance
Developer Tools
Scan everywhere you code
Real-time scanning in your editor, local analysis from the terminal, and automated checks in CI.
Pricing
Simple, transparent pricing
Start free. Upgrade when you need more. No hidden fees.
Hobby
For open source projects and solo developers.
- Up to 3 repositories
- 50 PR analyses per month
- Static code analysis
- Trust scores & grades
- GitHub check runs
- 7-day audit log
- Community support
Pro
For teams shipping AI-assisted code at scale.
- Up to 25 repositories
- Unlimited PR analyses
- AI-powered code review
- Auto-fix suggestions (50/day)
- Inline PR comments
- 10 team members
- Up to 10 custom policies
- 30-day audit log
- Email support
Ultra
For engineering orgs that take code governance seriously.
- Unlimited repos & members
- Unlimited PR analyses
- AI-powered code review
- Unlimited auto-fixes
- Cross-PR pattern analysis
- Unlimited custom policies
- 90-day audit log
- Priority support
Enterprise
For organizations with advanced security requirements.
- Everything in Ultra
- SSO / SAML
- Self-hosted deployment
- Custom rules engine
- Unlimited data retention
- SLA guarantee
- Dedicated support
FAQ