The platform
Everything it takes to close a ticket properly
Eight agents, a ranked context layer, six safety gates, a scanner suite and a dashboard that records every decision. Adopt the parts you need.
Agent activity
- Planner
- Coder
- Reviewer
- Security
- Test Gen
- Regression
0
Specialised agents
0
Post-generation checks
0
Reasoning trace layers
0
Security scanners
AI agents
Eight specialists, not one general-purpose model
Each agent has a narrow brief and a model chosen for it. Planning runs on a fast model; anything that touches your code runs on a careful one.
01PlannerAgent
Claude Haiku 4.5
Analyses tickets and repository structure to produce implementation plans with exact file targets.
02CoderAgent
Claude Sonnet 5
Generates production-ready code in intelligent batches, with self-healing loops for test failures.
03ReviewerAgent
Claude Sonnet 5
Pre-merge review that catches logic errors, security flaws, breaking changes and N+1 queries.
04SecurityAgent
Claude Sonnet 5
Scans for OWASP-class vulnerabilities: injection, hardcoded secrets, XSS and more.
05RootCauseAgent
Claude Sonnet 5
Deep analysis of the ticket to find the underlying problem rather than the reported symptom.
06ImpactSimulation
Claude Sonnet 5
Models the expected behavioural change before any code is written, heading off side effects.
07TestGenAgent
Claude Sonnet 5
Creates test cases for generated code so correctness and coverage are proven, not assumed.
08RegressionAgent
Claude Sonnet 5
Identifies the risk of breaking existing behaviour and flags the areas that need attention.
Intelligence
The right files, every time
Feeding a model your whole repository is expensive and imprecise. EnsureFix ranks candidate files three ways and sends only what the change actually touches.
- Dependency graph analysis
- Imports, call sites and code dependencies, to understand the blast radius.
- Semantic search
- All-MiniLM-L6-v2 embeddings with cosine similarity find conceptually related files.
- Code similarity
- Pattern matching finds structurally similar code that should change consistently.
- Repo intelligence layer
- A per-repository knowledge base. Your naming, architecture and forbidden patterns, checked automatically.
Ranking weights
Selected for this run
- src/auth/middleware.ts0.94
- src/auth/session.ts0.88
- src/lib/tokens.ts0.71
- tests/auth.spec.ts0.64
Enterprise safety
Six gates between a suggestion and your main branch
Generated code is guilty until proven innocent. Each gate can stop the run on its own, and every decision it makes is written down.
ExecutionGuard
Blocks suspicious changes: path security, a 1,500-line diff ceiling, file-count limits and syntax validation.
Plan quality guard
Validates the planner's output before a single line is generated, so architectural problems surface early.
Post-generation validator
Sixteen checks on the generated code: behaviour mismatch, overfit fixes, regression risk, runtime risk and more.
Decision engine
auto_apply, needs_review or block, with a confidence score. A human approves whenever risk is detected.
Commit policy controls
Set the mode, the maximum files, the acceptable risk levels, the blocked paths and the minimum confidence.
AES-256-GCM encryption
Repository credentials encrypted at rest. Every outbound URL validated against an allowlist.
Self-improving
Every review you write makes the next fix better
When you reject a diff, that outcome is recorded against the signals that produced it. Weights move, failing patterns get blocked, and the model stops proposing the thing your team keeps saying no to.
70%
Rejection threshold
Pattern learning
Identifies successful code patterns from the fixes you accept. Seven pattern types detected automatically.
Weight calibration
Per-signal rejection rates calibrated from real outcomes, with a damped lift formula that prevents overcorrection.
Failure memory
Patterns rejected 70% of the time across three or more attempts get blocked and injected as DO NOT USE instructions.
Contextual weights
Three tiers: repo-specific at 20+ samples, problem-type at 10+, then global. The most specific tier wins.
Strategy boosting
Strategies that land gain +0.10 confidence; ones that miss lose 0.05. Tracked per problem type.
Reasoning patterns
Structural reasoning extracted from approved fixes, matched to future problems by Jaccard similarity.
Observability
Nothing happens that you can’t go back and read
Reasoning traces, cost breakdowns, worker health and a live activity stream. When an agent makes a call you disagree with, you can see exactly why it made it.
Reasoning trace · 7 layers
- L1Root cause
- L2Graph path
- L3Impact simulation
- L4Solution strategy
- L5Approach selection
- L6Pattern recognition
- L7Exploration compliance
Cost by agent
Worker pool
Token efficiency
PR review
Review on every pull request, not just the ones we wrote
Point EnsureFix at a repository and it reviews everything landing in it, across GitHub, GitLab, Bitbucket and Azure DevOps.
Inline code comments
Specific suggestions posted straight onto the diff, with line-level precision.
Security vulnerability detection
Injection flaws, XSS, hardcoded secrets and OWASP issues caught in every diff.
Best-practice enforcement
Language-aware checks for imports, naming, patterns and anti-patterns.
Auto-fix suggestions
One-click patches with a confidence level, applied straight from the review.
Review severity scoring
Every PR gets a decision of SAFE, REVIEW or BLOCK, with the reasoning attached.
PR summary generation
Descriptions written from the diff, with change context and impact analysis.
Security suite
Five scanners, one verdict
Static analysis, secrets, infrastructure, dependencies and licences, run together on every commit and rolled into the same severity call the reviewer makes.
Read the security overviewAnalytics and more
Engineering intelligence, not just output
What it did, what it cost, and whether delivery actually improved, measured on the metrics your leadership already reports.
DORA metrics
Codebase Q&A
Browser reproduction
AI test generation
Cost analytics
Execution replay
Try it on real work
Bring a ticket. We'll run it.
Thirty minutes, your codebase, a real item from your backlog, and the pull request at the end of it.