Overview
What is Diffnix?
Code review is where quality is decided, and it is usually the slowest step in shipping. Diffnix removes the wait. The moment a pull request is opened, its AI agent PRInspector reads the diff, understands the intent of the change and posts precise inline feedback, typically in under five seconds.
Unlike a linter, PRInspector performs deep semantic analysis. It recognises SQL injection paths, cross-site scripting, authentication bypasses and hard-coded credentials, and it understands cross-file dependencies so it can explain the real impact of a change in plain words instead of a bare rule ID.
Teams encode their own conventions as plain-English rules ("flag console.log in production code"), start from curated bundles such as Security First, and switch rules on per repository or per branch. Leaked secrets are marked Critical and fail the PR status check, so GitHub branch protection can stop them from ever merging.
Privacy is not an add-on. Diffnix runs its language models on self-hosted infrastructure, never sends source code to third-party AI providers and retains zero source code once a review completes. Enterprise teams can go further and run the models entirely on their own hardware.
- Inline PR comments in under 5 seconds
- Catches SQL injection, XSS, auth bypass and leaked secrets
- Team rules written in plain English, no YAML
Hard-coded live secret detected in
webhook.ts:14. Move it to an environment variable.Possible SQL injection: use a parameterised query for
id.