placeholder image
Detecting Malicious Intent Across AI-Generated Pull Requests: A Governance Framework for Engineering Leaders
No single pull request has to look malicious to create a serious security problem. One adds logging. Another introduces a background job. A third...
AI Code Review Is Not Enough: How Engineering Leaders Should Gate AI-Generated Code
The easiest pull requests to approve are often the ones that deserve the closest inspection. AI-generated code tends to arrive well formatted, well...
A Global CX Software Company Closed 1,200 Security Issues with 90% Accuracy Using Codacy
This customer operates in a security-sensitive environment and has requested anonymity; all figures and quotes are as provided. The company scales...
placeholder image
Why this Fintech Chose Codacy Over SonarQube, Semgrep, and GitHub Advanced Security
Given the compliance-sensitive nature of financial services, this customer chose to share their story anonymously. Learn how this fintech platform...
Deterministic Static Analysis for AI Coding Workflows: How to Cut Token Cost Without Weakening Code Review
An AI coding agent opens a pull request. Another agent reviews it, searches the repository, reads a few irrelevant files, pulls more context into the...
Why Engineering Teams Keep Building In-House AI Code Review Tools, and What It Really Costs
LLMs made internal AI code review tools easy to prototype. They did, however, not make them easy to operate.

Subscribe to our blog

Stay updated with our monthly newsletter.