Moderne
Moderne sequences enterprise codebases into a compiler-accurate Lossless Semantic Tree, then runs deterministic recipes that fix vulnerabilities and migrate frameworks identically across one repository or a hundred thousand, with every diff reviewed by your own engineers.
What is Moderne?
Moderne is an enterprise platform for changing code at the scale of an entire software estate. Its premise is that a codebase has a genome. Sequence every repository into a Lossless Semantic Tree, a compiler-accurate model in which types, relationships, comments and formatting are all resolved and preserved, and the code becomes something a machine can edit with certainty rather than probability.
On top of that model sit recipes: deterministic programs that walk the tree, rewrite a precise pattern and re-emit source without disturbing a comment or a blank line. Recipes are composable, testable and repeatable, so the same one produces the same diff whether it touches one repository or a hundred thousand. The catalogue passes ten thousand recipes across more than forty domains and ten languages, and the company cites a single Log4Shell recipe applied to four hundred repositories that corrected thirty-eight thousand call sites with no regressions.
A third layer targets AI coding agents. Rather than compete with them, Moderne positions itself as the deterministic harness between the agent and the code. Trigrep provides symbol-aware search over the estate, Prethink supplies pre-computed architectural context, recipes perform the edit and Changelog governs the resulting pull requests, all delivered over the Model Context Protocol so that Claude Code, Cursor, GitHub Copilot, OpenAI Codex, Windsurf and Cline reach the same tooling. Moddy, a multi-repository agent, takes plain-language instructions such as upgrading to a given Spring Boot release.
Three delivery models exist. The hosted Moderne Platform runs multi-tenant or single-tenant, is SOC 2 Type 2 compliant and integrates with GitHub, GitLab, Bitbucket, Artifactory, Nexus and SSO. Moderne DX runs air-gapped inside the customer network, with no source code crossing the perimeter. The Managed Service adds forward-deployed engineers who own the outcome. Beneath all three sits OpenRewrite, the Apache 2.0 open-source engine Moderne maintains, free to use for Java, Kotlin and Groovy.
Human review is structural rather than optional: the platform produces diffs and pull requests, and nothing merges until a developer approves it.
What it does
- Sequence every repository into a compiler-accurate Lossless Semantic Tree
- Run one deterministic recipe across a single repository or a hundred thousand at once
- Remediate CVEs, zero-days and OWASP Top 10 findings at the source in every affected repository
- Migrate frameworks and language versions, from Spring Boot and Jakarta EE to the JDK, .NET and JUnit
- Search the whole estate by type and symbol with Trigrep
- Feed coding agents pre-resolved codebase context through Prethink and the Moderne MCP server
- Open, review and govern pull requests across every source control system from one Changelog surface
When to use Moderne / When not to
A quick filter to help you decide if Moderne is the right fit.
When to use Moderne
- Platform and developer-experience teams responsible for migrations that span thousands of repositories
- Application security engineers remediating CVEs, SCA and SAST findings at the source rather than on a dashboard
- Enterprise and solutions architects planning JDK, Spring, Jakarta EE or .NET upgrades across a large estate
- Engineering leaders who want coding agents governed by deterministic, auditable tooling instead of free-form generation
- Java, Kotlin and Groovy teams that can start free with the open-source OpenRewrite engine before considering the platform
When not to use Moderne
- Solo developers and small teams, for whom the open-source OpenRewrite project already covers the need without the platform
- Buyers who need a published price or a self-serve signup, since every route runs through a booked demo
- Teams working in languages outside Java, Kotlin, Groovy, JavaScript, TypeScript, Python, C#, .NET, Scala, Go and COBOL
- Anyone looking for a tool that writes new features, as Moderne only transforms and remediates code that already exists
- European buyers who need documented GDPR compliance, a data processing agreement or a named subprocessor list off the shelf
How to use Moderne
A typical end-to-end flow, from setup to results.
- Start free with OpenRewrite if Java, Kotlin or Groovy is all you need, since the engine is Apache 2.0 and publicly documented
- For the platform itself, book a demo or fill in the contact form, as there is no self-serve signup
- Bring a real migration or refactoring problem to the demo so Moderne can run it against your own code
- Connect your source control, whether GitHub, GitLab or Bitbucket, along with Artifactory or Nexus and your SSO provider
- Let the platform ingest your repositories and build a Lossless Semantic Tree for each one
- Pick a recipe from the catalogue, or author your own in declarative YAML, Refaster templates or imperative Java
- Use the Recipe Builder or the IntelliJ IDEA plugin to develop and debug custom recipes
- Run the recipe across the repositories you selected, from the web platform or from the local Moderne CLI
- Review every diff in DevCenter, then open pull requests in your own source control system
- Wire your coding agents into the MCP server so Trigrep, Prethink, recipes and Changelog become agent tools
Pros & Cons
Pros
- Determinism is the core promise: the same recipe yields the same diff on every run and in every repository
- Scale is documented rather than merely claimed, with one Log4Shell recipe fixing 38,000 call sites across 400 repositories without regressions
- Human review is built into the workflow, since output arrives as diffs and pull requests that nothing bypasses
- The underlying engine, OpenRewrite, is open source under Apache 2.0 and can be evaluated without any contract
- Three deployment models, including a fully air-gapped one that keeps source code inside the customer perimeter
- SOC 2 Type 2 compliance, single-tenant isolation and customer-managed encryption keys for regulated buyers
- Named a Leader in the first Gartner Magic Quadrant for AI-Augmented Code Modernization Tools, with named customers in finance, insurance, retail, hospitality and healthcare
Cons
- No price is published anywhere on the site, so budgeting is impossible without entering a sales cycle
- There is no self-serve signup and no advertised trial: every route to the platform runs through a booked demo
- The GDPR is never mentioned, and there is no Article 27 representative, no published data processing agreement and no subprocessor list
- No hosting country or region is disclosed, and the promise of any major cloud provider or region of your choice remains uncorroborated
- The privacy policy and the terms both carry an effective date of 1 January 2022 and have not been revised since
- Security, technology-insight and major migration recipes are proprietary and reserved for customers, well outside the open-source offer
- The terms restrict use to internal, personal, non-commercial purposes, which sits oddly with a product sold to enterprises
Pricing & Plans
Moderne publishes no pricing. There is no pricing page on the site, no rate card and no stated entry price: every call to action leads to a booked demo or to the contact form, which indicates an enterprise sales motion with quotations agreed case by case. No free trial and no free tier of the platform is advertised either. The only genuinely free route is OpenRewrite, the open-source engine Moderne maintains under the Apache 2.0 licence, which covers Java, Kotlin and Groovy. Source-available recipes may be read and run but not used to build commercial products, while security, technology-insight and major migration recipes are proprietary and reserved for Moderne customers.
- LST engine
- full recipe catalogue
- CLI
- IDE plugins
- Moddy
- agent tooling
- DevCenter
- telemetry and expert services
- Moderne DX
- an air-gapped deployment run through the CLI inside the customer network
- with no source code leaving the perimeter
- Managed Service
- the platform plus forward-deployed Moderne engineers who write and run the recipes and own the outcome on an ongoing basis
- Backpatch Alliance
- an enterprise offer built around critical fixes backported into unsupported open-source library versions
- OpenRewrite
- the free Apache 2.0 open-source engine for Java
- Kotlin and Groovy
- maintained by Moderne
- No price is attached to any of these plans on the site
Data, GDPR & hosting
A consolidated view of how Moderne handles your data.
GDPR overview
There is no mention of the GDPR anywhere on the site. Across every page collected, from the privacy policy and terms of service to the product and documentation pages, the regulation is never named, and no European representative is designated under Article 27. The framework invoked is entirely American: the California Consumer Privacy Act, California Civil Code sections 1798.83 to 1798.84 and the Nevada right to opt out of data sales. The terms are governed by federal law and the law of the State of California, with binding arbitration and a class-action waiver. No data processing agreement is published or offered, no subprocessor list appears, and no data-localisation commitment is made for the European Union. Privacy questions go to a single address, team@moderne.ai. European buyers should treat all of this as ground for contract negotiation rather than published guarantees.
Who owns the data?
The published terms never state who owns source code ingested by the platform, and the privacy policy covers only website and account data: names, e-mail addresses, account identifiers and web analytics, all of which it says are shared with no third party. What the product pages do commit to is custody. On the hosted Moderne Platform, code travels over encrypted connections, is encrypted at rest and sits in a SOC 2 Type 2 compliant environment, while single-tenant deployments isolate the tenant and support customer-managed encryption keys. Moderne DX removes the question altogether by running air-gapped, with no source code leaving the customer's own network.
Reuse rights
The terms grant end users no reuse rights over data held by Moderne, and instead restrict use of the Services to the customer's own internal purposes. On its own side, Moderne states that it processes personal data to deliver, support, personalise and improve the Services, to market them, to fight fraud and to meet legal obligations. It names Google LLC among its analytics providers, discloses that data may transfer to an acquirer in a merger, acquisition or bankruptcy, and reserves the right to create aggregated, de-identified or anonymised data and share it with third parties for its own business purposes. Nothing on the site states whether customer code or customer data is ever used to train AI models, and no opt-out is documented.
Data retention & training
Hosting summary
Moderne names no hosting country and no hosting region. The documentation states only that a private SaaS can be created in any major cloud provider or region of the customer's choosing, which describes an option rather than a current location. What is asserted is the security envelope: source code travels over encrypted connections, is encrypted at rest and is held in a SOC 2 Type 2 compliant environment. The hosted platform comes either multi-tenant, on shared infrastructure with strong tenant isolation, or single-tenant, as a hybrid SaaS with a private isolated tenant and customer-managed encryption keys. Moderne DX sidesteps hosting altogether by running air-gapped inside the customer's own network, so no source code leaves the perimeter. On jurisdiction, the company is incorporated in the United States, based in Miami, and its terms are governed by Californian law. Note that the public website resolves to an Amazon CloudFront edge node in Zurich; that is content delivery, not data storage, and says nothing about where customer code would be processed.
Things to keep in mind
Risks and trade-offs to weigh before adopting Moderne.
- No published pricing means the cost of an engagement stays unknown until you are already inside a sales process
- The terms impose binding arbitration and waive class actions under Californian law, and opting out requires a posted letter to the Miami address within a limited window
- Liability is capped at the greater of one hundred US dollars or the amounts paid over the preceding twelve months
- Sending source code to a hosted platform concentrates intellectual property with a third party, which is precisely why the air-gapped DX option exists
- The site never says whether customer code or data is used to train AI models, and documents no opt-out, so the question has to be settled contractually
- Legal documents dated January 2022 have not followed the product or the move from moderne.io to moderne.ai, so check which domain and which version govern your contract
- Deterministic tooling can breed over-confidence, since a recipe reproduces the same change everywhere including the same mistake, which is why the mandated human review of every diff must not become a formality
Setup & Integrations
Technical difficulty
Moderate, and it depends on the route taken. Everyday use needs no code: the documentation states that anyone can run recipes, open pull requests and generate reports without writing a line. The real work is upfront, connecting GitHub, GitLab or Bitbucket, Artifactory or Nexus and SSO, then letting the platform ingest every repository and build its semantic trees. Writing custom recipes in YAML, Refaster templates or Java calls for developer skills, eased by the Recipe Builder and the IntelliJ plugin. Moderne DX adds an in-network installation, while the Managed Service shifts almost all of this onto Moderne's engineers.
Deployment
Integrations
Behind Moderne
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
What does Moderne actually do?
Which programming languages does it cover?
Can a change be merged without our review?
How is our source code handled?
What deployment options are available?
How does Moderne relate to OpenRewrite?
How much does it cost?
Does it work with the coding agents we already use?
Is there an API?
What does the site say about the GDPR?
Should you pick Moderne?
Moderne occupies a narrow but demanding niche: changing code across an entire enterprise estate rather than one repository at a time. Its argument is coherent and unusually concrete for the category. Because every repository is first sequenced into a compiler-accurate model, a recipe is neither a regular expression nor a prompt but a program whose output is identical on every run, a claim backed by figures the company is willing to name, such as thirty-eight thousand call sites corrected across four hundred repositories with no regressions.
The positioning is equally deliberate. Rather than shipping yet another coding agent, Moderne sells the deterministic layer beneath the agents customers already run, reachable over MCP from Claude Code, Cursor, Copilot and others. For organisations worried that agentic refactoring is fast but unaccountable, that framing answers the right objection, and the mandatory pull-request review reinforces it.
The reservations are commercial and legal rather than technical. Nothing about pricing is public, there is no self-serve path, and evaluation begins with a sales conversation. The legal documentation is thinner than the product deserves: the privacy policy and the terms both still carry a January 2022 effective date, the GDPR is never mentioned, and no data processing agreement or subprocessor list is published, gaps a European buyer will have to close in contract rather than find on the site.
There is, however, an honest way to try before committing. OpenRewrite, the Apache 2.0 engine Moderne maintains, is free and covers Java, Kotlin and Groovy. Any team can measure the approach on its own code first, and only then judge whether the platform's scale, security posture and recipe catalogue justify an enterprise engagement.
- Choosing a selection results in a full page refresh.
- Opens in a new window.