Qodo
Qodo is an AI code review and quality governance platform for engineering teams. Specialized agents reason over the entire codebase, not the diff alone, applying the same rules across the IDE, Git pull requests and the command line.
What is Qodo?
Qodo is an AI code review and quality governance platform published by Codium Ltd. of Tel Aviv, the company previously known as CodiumAI. Its home page states the ambition in one line: govern code at the speed AI writes it. Qodo does not generate code. It positions itself as the quality counterweight to the agents that do.
The product lives on two main surfaces governed by the same rules. In the IDE, changes are validated in real time before the commit. On the Git pull request, review arrives with severity levels and structured remediation. A CLI carries the same checks into CI/CD pipelines. Three pillars sit underneath: a Multi-Agent Fabric, a Context Engine and Rules Lifecycle Management.
The Context Engine is where the differentiation is claimed. It draws on four sources at once: your rules, the structure of the codebase, the pull request history with its diffs, comments, discussions and corrections, and business requirements taken from tickets and specs. That context is what allows Cross Repo Review to reason over interdependent repositories, including repositories hosted on different Git providers, and to flag a breaking change on the pull request before it is merged.
Rules are not written by hand. Rules Miner turns recurring pull request comments into enforceable rules, which are then measured continuously, checked for conflicts and allowed to expire when they stop earning their place. Skill Review Standards extends the same governance to the skill files that steer AI coding agents, with analytics, one-click activation and attribution on every finding. Above all of it sits a governance portal offering risk intelligence, an audit trail, repository mapping and a system of record for quality history.
Qodo claims the best F1 score on its own AI Code Review Benchmark, and quotes NVIDIA's Jensen Huang crediting its context engine for agentic code search and retrieval. The published numbers are large: over one million installs, roughly one hour saved per pull request, 90% of the initial review handled before a human steps in, two to four times faster delivery and more than 450,000 engineering hours saved a year. Marketplace ratings are 4.7 from 492 reviews on VS Code and 4.5 from 184 on JetBrains. Intel, HiBob, Macmillan, monday.com and Sansan appear as customers. The founders are Itamar Friedman (CEO) and Dedy Kredo (CPO).
What it does
- Review every pull request automatically with specialized agents
- Surface real bugs, duplicated logic, requirement gaps and rule violations
- Review across interdependent repositories, even on different Git providers
- Validate code in real time inside the IDE, before the commit
- Mine enforceable coding rules automatically from pull request history
- Track findings, resolution rates and risk concentration on a governance dashboard
- Keep an audit trail of every issue and every compliance signal
When to use Qodo / When not to
A quick filter to help you decide if Qodo is the right fit.
When to use Qodo
- Engineering teams reviewing large volumes of code written by coding agents such as GitHub Copilot, Cursor, Windsurf or Amazon Q
- Organizations with many interdependent repositories that need cross-repo review and dependency mapping, even across different Git providers
- Companies under compliance pressure who need SOC 2 Type II, an audit trail, BYOK and on-premise or air-gapped deployment
- Teams whose coding standards are stranded in outdated wikis, since Rules Miner extracts enforceable rules from past pull requests
- Developers already working in VS Code, JetBrains or Visual Studio on GitHub, GitLab, Bitbucket or Azure DevOps
When not to use Qodo
- Developers looking for a code generator: Qodo is deliberately the quality counterweight to generation agents, not one of them
- Anyone needing a permanently free tool, since only the 14-day trial and the open source program cost nothing
- Teams above 30 users, who must leave the self-serve Pro Team plan for Enterprise and a sales conversation
- Organizations that need SSO/SAML, audit logs, BYOK, single-tenant, on-premise or Gerrit support without an Enterprise contract
- Users expecting a mobile app or a public API: Qodo lives only in the IDE, the Git platform and the CI pipeline
How to use Qodo
A typical end-to-end flow, from setup to results.
- Sign in with GitHub, Google or an email address; the 14-day trial needs no credit card
- Install the Qodo Git Marketplace App, which requires admin access on your Git provider
- Select the repositories to cover; reviews start immediately, with no platform migration
- Let Qodo mine your pull request history to build a first set of coding rules automatically
- Review, edit and extend those rules from the central rules portal
- Install the IDE extension for VS Code, JetBrains or Visual Studio for real-time validation
- Add the CLI to your CI/CD pipelines to run the same quality checks automatically
- Read the findings on each pull request, with severity levels and structured remediation
- Watch the dashboard for credit balance and burn rate, alongside findings and resolution rates
- Change credit pack or plan at any time from the dashboard, effective at the next billing cycle
Pros & Cons
Pros
- Reasons over the whole codebase rather than the diff alone, which Qodo presents as the reason for fewer false positives
- The same rules and the same agents apply in the IDE, on the pull request and in the CLI
- Cross-repo and cross-provider review, which Qodo's own comparison page describes as rare on this market
- Rules are mined automatically from pull request history instead of being written and maintained by hand
- Setup takes minutes per repository with no platform migration, and there is no limit on repositories or reviews
- Deployment options run from shared SaaS to air-gapped, with BYOK, SOC 2 Type II and a public Trust Center
- A public DPA naming each subprocessor and its hosting region, free access for qualified open source projects, and a 14-day trial with unlimited credits and no credit card
Cons
- No permanent free tier outside the open source program
- Credits expire at the end of each monthly cycle and never roll over
- The self-serve Pro Team plan is capped at 30 users
- SSO/SAML, audit logs, BYOK, single-tenant, on-premise, advanced self-learning, custom agentic workflows and Gerrit support are Enterprise-only, and Enterprise pricing is unpublished and gated behind a demo
- The zero training promise on the home page sits awkwardly beside the training license granted in section 4.4 of the Terms of Service
- No Article 27 EU representative, and audit logging is handled through a Google Cloud tool whose interface is not exposed to users
- No public API is documented, no dedicated legal notice page exists, and the only postal address appears in the privacy policy rather than on the page titled Company Information
Pricing & Plans
Qodo does not offer a permanent free plan; the pricing FAQ states plainly that no permanent free tier exists. A 14-day free trial is available with unlimited reviews and unlimited credits and without a credit card, and qualified open source projects can obtain free access on application. The lowest paid entry point is the Pro Team plan at USD 30 per month, billed monthly with no annual commitment, for up to 30 users. Usage is metered in credits at USD 0.012 each, pooled across the team and sold in packs of 2,500, 5,000 or 20,000 credits. Overage is charged at the same unit rate, up to a monthly cap the customer sets. Enterprise pricing is quoted on request.
- unlimited reviews
- unlimited credits and unlimited users for the duration of the trial
- no credit card required
- USD 30 per month for up to 30 users
- including agentic pull request review
- an unlimited rules system
- Git and IDE integrations
- pre-PR review skills
- dashboard and analytics
- cross-repo capabilities
- strict data retention
- quote-based
- from 30 users
- adding SSO/SAML
- audit logs
- the governance dashboard
- advanced self-learning
- BYOK
- single-tenant SaaS or on-premise and air-gapped deployment
- free for qualified open source projects
- on application
Data, GDPR & hosting
A consolidated view of how Qodo handles your data.
GDPR overview
GDPR implementation is contractual rather than declarative. Qodo publishes a dedicated Data Processing Addendum stating that, with effect from 25 May 2018, it processes personal data in accordance with the GDPR requirements directly applicable to its activities. The DPA incorporates the EU Standard Contractual Clauses of implementing decision 2021/914, Module Two (controller to processor) and Module Three (processor to processor), under Irish law and Irish courts, plus a separate UK GDPR track under Article 46 and the Data Protection Act 2018. Breaches are notified within 72 hours at most, and customers may audit once a year at their own cost with 30 days' notice. The privacy policy, revised on 20 February 2025, sets out access, rectification, erasure, restriction, objection and portability rights, exercised through info@qodo.ai, with separate CCPA commitments not to sell or share personal data. No Article 27 EU representative is named anywhere on the site.
Who owns the data?
Section 4.3 of the Terms of Service leaves every intellectual property right in Customer Data with the customer or its licensors, covering what you provide and what Qodo pulls from your account. Section 4.1 goes further: Qodo relinquishes any right it might hold in the Output the platform generates and assigns it to the customer. Two carve-outs matter. Usage Data and Aggregated Data stay with Qodo, which may publish them anonymized provided no customer is identified, and section 4.6 makes any feedback you send Qodo's property outright. Under the DPA the customer is controller and Qodo processor; the Trust Center states that all customer data is treated as confidential, with restricted and authorized access.
Reuse rights
Because the Output is assigned to the customer, you can reuse, ship and commercialize what Qodo produces without asking anyone's permission. What Qodo does with your code is where the published record contradicts itself, and both sides deserve to be read. The home page promises zero data retention: code is analyzed and discarded, with nothing stored, logged or used to train models. The pricing FAQ answers the training question with a flat no, adding that your code is used only to generate reviews for your team. Section 4.4 of the Terms of Service says something else: the customer grants Qodo and its affiliates a non-exclusive, royalty-free, worldwide license, limited to the duration of the engagement, to use all Customer Data both to deliver the service and to train and improve the platform, the Qodo Models and the services, and to develop new products. Nothing published on the site reconciles the two. Around that core, the Trust Center notes that IDE extensions extract minimal code snippets and send a representation of them to the backend to generate tests and suggestions, and that a zero-retention agreement is in place with OpenAI for paying customers. The privacy policy separately allows personal data to be used for research, technical diagnostics, personalization and analytics in order to train and improve the services. Enterprise customers can sidestep the question altogether with BYOK, using OpenAI, Anthropic, Azure OpenAI or self-hosted models, and with single-tenant, on-premise or air-gapped deployment that keeps code out of shared infrastructure. Everyone else should settle the point in writing.
Data retention & training
Hosting summary
Qodo runs its SaaS on major cloud providers, and Exhibit A of the DPA names each subprocessor with its hosting zone. Google Cloud Platform hosts the service in the United States or the EU, at the customer's election. Amazon Web Services, Inc. and Amazon Web Services EMEA SARL host in the United States, the EU or Australia, again at the customer's election. Two further subprocessors sit in the United States: Slack, used for internal communication that may contain customer data, and Google Workspace for internal mail and collaboration. Exhibit B covers the hosting of customer employee email addresses in the service database, noted as Firebase on GCP. The Trust Center adds that hosting is with a major cloud provider only, inside a private VPC, with disaster recovery on a different cloud region. International transfers are framed by the EU Standard Contractual Clauses and a separate UK track. These regions are contractual options rather than defaults, so location is a decision made at contract time. Enterprise customers can remove the question entirely with single-tenant, private cloud, on-premise or air-gapped deployment inside their own infrastructure.
Things to keep in mind
Risks and trade-offs to weigh before adopting Qodo.
- Section 4.4 of the Terms of Service grants Qodo a worldwide license over Customer Data that explicitly covers training and improving its models, which contradicts the zero data retention promise on the home page and the flat no in the pricing FAQ. Get this settled contractually before sending proprietary code.
- Usage Data and Aggregated Data remain Qodo's property and may be published in anonymized form, and any feedback you send becomes Qodo's outright.
- Qodo claims that 90% of the initial review is handled before a human steps in. Teams that read this as permission to stop reading code themselves gradually lose the review skill and the shared understanding of the codebase that make the tool worth having.
- Credits expire every month without rolling over, and overage is billed automatically up to the cap you set, so that cap deserves a deliberate decision on day one rather than after the first invoice.
- Subscriptions renew automatically and must be cancelled at least 14 days before the term ends, and Qodo reserves the right to suspend or terminate an account at its sole discretion.
- Governing law is Israel outside North America and the State of New York within it, with exclusive jurisdiction in the corresponding courts; no Article 27 EU representative is designated, and customer audits are limited to once a year, at the customer's expense, with 30 days' notice.
- IDE extensions send a representation of code snippets to the backend to generate tests and suggestions; where security rules forbid that, Qodo points to the VPC deployment instead.
Setup & Integrations
Technical difficulty
Low for the standard path. Qodo states that setup takes minutes per repository, with no platform migration. You sign in with GitHub, Google or email, install the Git Marketplace App (admin rights required on the Git provider) and pick the repositories; other engineers need no Qodo account of their own. The IDE extension is a separate, equally simple install, and rules are mined from pull request history rather than written first. Two things raise the bar: allowlisting Qodo's IP addresses and servers for cloud or VPC assets, and Enterprise on-premise or air-gapped deployment, which is a project in itself.
Deployment
Integrations
Behind Qodo
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement Qodo.
Frequently asked questions
What is Qodo?
Is there a free plan?
How much does Qodo cost?
What is a credit, and what happens if I run out?
Do unused credits roll over?
Does Qodo train its models on my code?
Which Git providers, IDEs and languages are supported?
Can Qodo run inside our own infrastructure?
Where is the data hosted?
Is there a public API or a mobile app?
Should you pick Qodo?
Qodo has picked a clear lane. It does not write your code; it aims to be the quality layer that catches what coding agents get wrong, and every design decision follows from that choice. The differentiators are specific rather than rhetorical: cross-repo context that spans different Git providers, rules mined from your own pull request history instead of hand-written, and the same agents enforcing the same rules in the IDE, on the pull request and in the CLI.
On the enterprise side the file is solid. SOC 2 Type II, a public Trust Center, a published DPA naming every subprocessor and its hosting region, deployment options running all the way to air-gapped, and BYOK for teams that will not send code to a third-party model. The company is well funded, with USD 120 million raised in total and a USD 70 million Series B in March 2026, and it claims more than a million installs alongside marketplace ratings of 4.7 and 4.5.
The main reservation is a contradiction Qodo has not resolved. The home page and the pricing FAQ promise zero data retention and no model training, while section 4.4 of the Terms of Service grants a worldwide license over Customer Data that explicitly includes training. Both statements are published by the same company. Anyone sending proprietary code should have that settled in writing before rollout.
The secondary reservations are commercial: no permanent free tier outside the open source program, credits that expire monthly without rolling over, a 30-user ceiling before Enterprise, and Enterprise pricing available only through a demo. For everyone else, the 14-day trial costs nothing, needs no credit card and installs in minutes per repository, which makes a test on a real repository the cheapest way to judge the review quality.
- Choosing a selection results in a full page refresh.
- Opens in a new window.