The platform

Everything it takes to close a ticket properly

Eight agents, a ranked context layer, six safety gates, a scanner suite and a dashboard that records every decision. Adopt the parts you need.

orchestrator · BUG-2847

Agent activity

Running
  • PlannerReading ticket BUG-2847
  • CoderIdle
  • ReviewerIdle
  • SecurityIdle
  • Test GenIdle
  • RegressionIdle

0

Specialised agents

0

Post-generation checks

0

Reasoning trace layers

0

Security scanners

AI agents

Eight specialists, not one general-purpose model

Each agent has a narrow brief and a model chosen for it. Planning runs on a fast model; anything that touches your code runs on a careful one.

01PlannerAgent

Claude Haiku 4.5

Analyses tickets and repository structure to produce implementation plans with exact file targets.

02CoderAgent

Claude Sonnet 5

Generates production-ready code in intelligent batches, with self-healing loops for test failures.

03ReviewerAgent

Claude Sonnet 5

Pre-merge review that catches logic errors, security flaws, breaking changes and N+1 queries.

04SecurityAgent

Claude Sonnet 5

Scans for OWASP-class vulnerabilities: injection, hardcoded secrets, XSS and more.

05RootCauseAgent

Claude Sonnet 5

Deep analysis of the ticket to find the underlying problem rather than the reported symptom.

06ImpactSimulation

Claude Sonnet 5

Models the expected behavioural change before any code is written, heading off side effects.

07TestGenAgent

Claude Sonnet 5

Creates test cases for generated code so correctness and coverage are proven, not assumed.

08RegressionAgent

Claude Sonnet 5

Identifies the risk of breaking existing behaviour and flags the areas that need attention.

Intelligence

The right files, every time

Feeding a model your whole repository is expensive and imprecise. EnsureFix ranks candidate files three ways and sends only what the change actually touches.

Dependency graph analysis
Imports, call sites and code dependencies, to understand the blast radius.
Semantic search
All-MiniLM-L6-v2 embeddings with cosine similarity find conceptually related files.
Code similarity
Pattern matching finds structurally similar code that should change consistently.
Repo intelligence layer
A per-repository knowledge base. Your naming, architecture and forbidden patterns, checked automatically.
context ranking · BUG-2847

Ranking weights

Dependency graph40%
Semantic search40%
Code similarity20%

Selected for this run

  • src/auth/middleware.ts0.94
  • src/auth/session.ts0.88
  • src/lib/tokens.ts0.71
  • tests/auth.spec.ts0.64

1,842 files in repository · 4 sent to the model

Enterprise safety

Six gates between a suggestion and your main branch

Generated code is guilty until proven innocent. Each gate can stop the run on its own, and every decision it makes is written down.

01

ExecutionGuard

Blocks suspicious changes: path security, a 1,500-line diff ceiling, file-count limits and syntax validation.

02

Plan quality guard

Validates the planner's output before a single line is generated, so architectural problems surface early.

03

Post-generation validator

Sixteen checks on the generated code: behaviour mismatch, overfit fixes, regression risk, runtime risk and more.

04

Decision engine

auto_apply, needs_review or block, with a confidence score. A human approves whenever risk is detected.

05

Commit policy controls

Set the mode, the maximum files, the acceptable risk levels, the blocked paths and the minimum confidence.

06

AES-256-GCM encryption

Repository credentials encrypted at rest. Every outbound URL validated against an allowlist.

Self-improving

Every review you write makes the next fix better

When you reject a diff, that outcome is recorded against the signals that produced it. Weights move, failing patterns get blocked, and the model stops proposing the thing your team keeps saying no to.

70%

Rejection threshold

A pattern rejected this often across three attempts is blocked outright

Pattern learning

Identifies successful code patterns from the fixes you accept. Seven pattern types detected automatically.

Weight calibration

Per-signal rejection rates calibrated from real outcomes, with a damped lift formula that prevents overcorrection.

Failure memory

Patterns rejected 70% of the time across three or more attempts get blocked and injected as DO NOT USE instructions.

Contextual weights

Three tiers: repo-specific at 20+ samples, problem-type at 10+, then global. The most specific tier wins.

Strategy boosting

Strategies that land gain +0.10 confidence; ones that miss lose 0.05. Tracked per problem type.

Reasoning patterns

Structural reasoning extracted from approved fixes, matched to future problems by Jaccard similarity.

Observability

Nothing happens that you can’t go back and read

Reasoning traces, cost breakdowns, worker health and a live activity stream. When an agent makes a call you disagree with, you can see exactly why it made it.

dashboard · acme/payments

Reasoning trace · 7 layers

  1. L1Root causeToken refresh races the clock check
  2. L2Graph pathsession.ts → tokens.ts → middleware.ts
  3. L3Impact simulation3 call sites, 0 public API changes
  4. L4Solution strategyAdd drift tolerance, keep contract
  5. L5Approach selectionGuard clause over retry wrapper
  6. L6Pattern recognitionMatches 4 accepted fixes in repo
  7. L7Exploration complianceWithin repo conventions

Cost by agent

Coder52%
Reviewer21%
Security13%
Test gen9%
Planner5%

Worker pool

Health and queue depth

Token efficiency

Spend per merged ticket

Activity stream live3s polling

PR review

Review on every pull request, not just the ones we wrote

Point EnsureFix at a repository and it reviews everything landing in it, across GitHub, GitLab, Bitbucket and Azure DevOps.

Inline code comments

Specific suggestions posted straight onto the diff, with line-level precision.

Security vulnerability detection

Injection flaws, XSS, hardcoded secrets and OWASP issues caught in every diff.

Best-practice enforcement

Language-aware checks for imports, naming, patterns and anti-patterns.

Auto-fix suggestions

One-click patches with a confidence level, applied straight from the review.

Review severity scoring

Every PR gets a decision of SAFE, REVIEW or BLOCK, with the reasoning attached.

PR summary generation

Descriptions written from the diff, with change context and impact analysis.

Security suite

Five scanners, one verdict

Static analysis, secrets, infrastructure, dependencies and licences, run together on every commit and rolled into the same severity call the reviewer makes.

Read the security overview
01SAST scannerStatic analysis with CWE tracking. Optional Semgrep integration for your own rules.
02Secret detectionEntropy plus pattern matching finds API keys, tokens, passwords, private keys and connection strings.
03Infrastructure-as-code scanningDockerfiles, docker-compose, Terraform, Kubernetes manifests and GitHub Actions.
04Dependency vulnerability scanningKnown vulnerabilities in your dependency tree, with severity ratings.
05Licence complianceDependency licences validated against your organisation's policy.

Analytics and more

Engineering intelligence, not just output

What it did, what it cost, and whether delivery actually improved, measured on the metrics your leadership already reports.

DORA metrics

Frequency, lead time, CFR, MTTR

Codebase Q&A

Answers with file references

Browser reproduction

Playwright, console, network

AI test generation

Targets uncovered edge cases

Cost analytics

Per ticket, per agent, per token

Execution replay

Re-run any job, inspect prompts

Try it on real work

Bring a ticket. We'll run it.

Thirty minutes, your codebase, a real item from your backlog, and the pull request at the end of it.