AUTOMETRIC
AI governance control plane

Your agents ship most of the code now. Prove it was reviewed.

Autometric reviews every pull request with specialist agents and static analysis, computes readiness from what it found rather than what you asserted, and seals every gate decision into a hash-chained, append-only record.

credit based · no seatszero-config first reviewself-host available
framework SOC 2 Type II common criteria · security & change 2 gaps open
posture · computed from findings 94%
61 of 64 controls verified · 1 unverified · 2 failing
CC8.1 Changes authorized, tested and reviewed before deployment 412 recorded reviews verified
CC7.1 Vulnerabilities identified and evaluated on every change 288 recorded reviews verified
CC7.2 Anomalous activity monitored across the pipeline no scan in 30d unverified
CC6.1 Logical access restricted to authorized identities 4 open findings failing
CC4.1 Control operation monitored and evaluated continuously 96 recorded reviews verified
posture computed from findings every control state backed by recorded reviews recomputed after every review
5
starter rule sets you can adopt in one click — nothing is ever enabled without you
8
source-control platforms, from GitHub and GitLab to Gerrit and Perforce
13
specialist agent roles across the review pipeline, judges included
0
gate decisions editable after the fact — append only, hash chained
the gap

Velocity went up. Accountability did not follow.

Four coding agents on one repository, opening pull requests faster than any team can read them. Your review process was designed for humans who could be asked what they were thinking, and it does not scale to the volume now arriving.

blind spot

The gate is a rubber stamp

An approval means someone clicked approve. Nothing records which rules ran, at what version, or why the merge was allowed.

blind spot

Review scales worse than generation

Agents open pull requests faster than any team can read them. The queue is the bottleneck, so the queue gets skipped.

blind spot

The auditor asks and you guess

Proving a control was enforced on a specific change means reconstructing it from CI logs that rotated out 30 days ago.

the rule engine

Controls are only as good as the rules underneath them.

Every control maps to detection classes, and every detection class is a rule that reads the diff — its dependencies, its data flow, its blast radius — not just its text. Starter sets ship ready to adopt in one click; the builder writes the rest without anyone learning a query language.

  • starter sets and framework packs, versioned — a finding always names the version that raised it
  • the builder composes detection classes, scope and action; no query language to learn
  • rules roll out shadow → advisory → warn → block, with measured precision before they gate
rule no-unvetted-dependency v3 critical · blocking
when a diff adds an import or manifest entry the agent has not resolved before
check internal allowlist · public registry age · download history · postinstall scripts
then block the merge, quarantine the package, notify #sec-eng
unless an owner downgrades or disables the rule — recorded in the audit log either way
matched acme/payments-api · #4471
package.json:41 + "@acme/retry-policy": "^2.1.0"

No such package on the internal registry. The nearest public name was registered 6 days ago, has 0 prior downloads and a postinstall script. The agent cited it in three files as though it had always existed.

unresolved dependencyslopsquat candidate3 call sites
merge blocked 1 critical unresolved · override requires owner seal 0x9f4c…21ab
the console

One control room for review, governance and cost.

Twelve surfaces, one shell. Everything below is a real screen in the product.

Every pull request, triaged before you open it

Findings are grouped by severity and detection class, with the rule that raised each one and its version on the row. Gate state is decided before a human looks.

  • severity, blast radius and owning team on one row
  • every finding names the rule and version that raised it
  • blocked merges carry the rule version that blocked them
route /reviews12 open · 90d
open
12
blocked
3
median review
11m
acme/payments-api #4471blocked1 crit
acme/web-app #1194blocked2 crit
acme/ingest-worker #882review4 high
acme/design-system #310passedclean
acme/infra-tf #2051review1 high
ledger

Every decision, written once.

Every review's gate decision lands in an append-only, hash-chained record: the verdict, the blocking threshold, and the exact version of every rule that ran. Each entry commits the hash of the one before it, so nothing can be edited after the fact.

gate record · acme tenant
0x9f4c…21ab payments-api #4471 blocked · 1 critical unresolved · 34 rule versions sealed
0x7d18…c093 web-app #1194 passed · 0 findings · 34 rule versions sealed
0x4a02…8fe1 ingest-worker #882 passed with warnings · 4 high, advisory
0x1bd7…33c4 design-system #310 passed · clean · chained to the decision before it

each decision commits the prior hash · verdict, threshold and rule versions sealed together · append only

compliance

Answer the audit in an afternoon.

Controls map to detection classes, detection classes map to findings on real pull requests. Readiness is computed, never asserted — and the gap view shows exactly which controls are missing evidence.

SOC 2 Type II

94%
61 of 64 controls 2 gaps

ISO 27001

91%
89 of 98 controls 3 gaps

FedRAMP

78%
31 of 40 controls 4 gaps

PCI DSS 4.0

88%
44 of 50 controls 0 gaps

HIPAA Security

82%
37 of 45 controls 2 gaps

NIST 800-53

86%
38 of 44 controls 1 gap

GDPR

89%
52 of 58 controls 1 gap
pricing

You buy credits, not seats.

A credit is a unit of model work. How far a credit goes depends on the model profile you set — as an org default, or per repository. Commit to a monthly credit volume, pay for it up front at a discount, and roll whatever you do not use into next month. Invite the whole company; seats are free.

estimate your burn

profilebalanced· change it in the cards above

credits / month200
prepaid at $0.015/cr≈ $3/mo
pay-as-you-go at $0.022/cr≈ $4/mo

20 credits per review on balanced · prepay 200 credits a month and they cost 32% less · a quiet month rolls the remainder forward, a busy one bills the overage at $0.022 in arrears

Metered

One plan. Prepay a monthly amount and your credits cost less; run past your balance and the overage bills in arrears at the pay-as-you-go rate — no penalty, no cut-off. Unused credits roll over month to month.

self serve
$0.015per prepaid credit · 32% under the $0.022 pay-as-you-go rate
two prices, no tiers
prepaid$0.01532% offa monthly amount you set, billed up front; unused credits roll forward
pay-as-you-go$0.022what runs past your balance, billed in arrears — no penalty, no cut-off
  • +unlimited members — no seat licences
  • +unlimited repositories
  • +adoptable starter rule sets + rule builder
  • +per-repository review gates and severity thresholds
  • +SOC 2 framework mapping — full catalogue on Enterprise
  • +tamper-evident record of every gate decision
  • +SSO/SAML sign-in and enforced 2FA
  • +all integrations, no add-on pricing
start free — no card required
Enterprise

A negotiated per-credit rate, plus the deployment and paperwork your security team is going to ask for.

Customnegotiated rate
  • +a negotiated per-credit rate for your organisation
  • +self-host, private cloud or air-gapped
  • +the full framework catalogue — HIPAA, PCI DSS, FedRAMP, NIST 800-53, ISO 27001, GDPR
  • +SCIM provisioning and custom control mappings
  • +audit support alongside your auditor
  • +99.95% SLA with service credits
  • +named success engineer, invoicing on your terms
talk to sales

no seats, no platform fee · unused credits roll over month to month and never expire while the account is active · raise or lower your monthly prepay at any time, effective the next cycle · overage bills at $0.022/cr in arrears · self-host and air-gapped deployments quoted separately

connects to your source control
GitHub cloud · enterprise server
GitLab saas · self-managed
Bitbucket cloud · data center
Gerrit self-hosted

Bring one repository. See the first review in minutes.

Read-only access and a zero-config first review. Adopt starter rule sets in one click, switch on compliance frameworks when you are ready — nothing is ever enabled without you.

no card requiredrevoke access anytimedata stays in your region
book a walkthrough

30 minutes, live console, your repository if you want it.