ScanDrix AI Inc.

We build the review layer.

ScanDrix is an engineering company building deterministic AST analysis for pull requests — so the bugs that span files stop slipping through review.

Founded
2025
Focus
AST security review
Deployment
Cloud or self-hosted
Data policy
Zero retention

What we believe

Four commitments.

These constrain the product. Where a feature conflicts with one of them, the feature does not ship.

Your code is not our data

Zero code retention is an architectural constraint, not a policy page. Diffs are parsed in ephemeral workers and evicted as soon as a review is posted. We have no business model that depends on reading your source code, and we do not train models on it.

Deterministic before probabilistic

Pattern and taint analysis decide what is a finding. Models explain and draft patches. Keeping those layers separate is why results are reproducible and why the false-positive rate stays under 2.1% instead of in the tens of percent.

Honest benchmarks

We publish the category where we do badly as prominently as the one where we do well. Comparisons are run on a fixed corpus with a manual audit of every finding, and we report the methodology rather than just the headline.

Built for the reviewer, not the dashboard

A finding is only useful where the developer already is. Findings land as line-precise review comments with a commit button, not as a ticket waiting to be triaged.

How we got here

The short version.

01

The problem we hit

Our own review queue was the evidence. Every tool we tried either flooded us with false positives or went quiet on exactly the bugs that spanned files. Static rules could not see architecture, and AI review could not see the code that was not in the window.

02

The engine

So we built the missing layer: compile the codebase to an AST, propagate taint across file boundaries, evaluate deterministic rules, and only then hand candidates to a model for intent and patch drafting. Cross-file taint tracking shipped first because it was the largest gap.

03

Where we are

ScanDrix now reviews pull requests on GitHub, GitLab, Bitbucket, Azure Repos, and Forgejo, with reviews designed for sub-minute turnaround. The work now is depth: more languages, more Drixy rules, and better explanations for the findings we already catch.

Talk to the team

We read every message.

Questions about the engine, a security review, or a self-hosted deployment — reach the people who built it.