Recurse ML
Recurse ML is a bug-detection service for teams shipping AI-written code. It reviews pull requests, local diffs and coding-agent output through a GitHub App, a command-line tool and an MCP server, flagging breaking changes before they reach production.
What is Recurse ML?
Recurse ML is a bug-detection service aimed squarely at the code that AI assistants now write in volume. It is built by Cerebral Adaptive Forecasting Ltd., a UK company trading as Recurse ML, and the vendor is careful to distinguish it from a wrapper around a general-purpose model: the claim is that its models are trained in-house on real bug patterns, and that the product is not just an LLM call.
The same engine reaches developers through three doors. A GitHub App reviews pull requests automatically and returns its findings roughly a minute after a PR opens. A command-line tool, rml, analyses unstaged changes locally before anything is committed. REMCP, an MCP server, plugs the analysis into Claude Code and Cursor so a coding agent can check its own work mid-task.
What it looks for goes beyond linting. Recurse ML says it identifies breaking changes and proposes fixes consistent with existing code, follows how components interact across an entire repository so it can surface problems both upstream and downstream of a change, and keeps current knowledge of external and internal libraries so every suggestion links back to the right documentation. Custom rules let a team encode its own conventions, naming patterns and sensitive areas. Reviewers can reply to a comment and get an immediate answer, dismiss a suggestion they disagree with so that later ones take the dismissal into account, and trigger a deeper analysis of any file in a pull request with a single click.
The vendor calls the tool language-agnostic; its GitHub Marketplace listing names ten languages, among them Python, TypeScript, Go, Rust, C, C++ and C#. Homepage figures claim more than 15,000 bugs resolved and 80% less time spent debugging, and the Marketplace listing shows 256 installations from a publisher GitHub has verified. Named customers include Continue.dev, Requesty, SurfSense, Robyn, Findlay Park, Vizval and Capture.Energy.
On data the position is unusually blunt: no training on customer code, a zero-retention policy on everything analysed, and no copy of a codebase kept. SOC 2 and Cyber Essentials are described as work in progress, not as achieved.
What it does
- Reviews every pull request automatically and posts findings about a minute after it opens
- Detects breaking changes and suggests a fix that stays consistent with the surrounding code
- Traces how components interact across the whole repository, catching bugs upstream and downstream of the diff
- Checks unstaged local changes from the terminal before anything is committed
- Feeds analysis back to Claude Code and Cursor through an MCP server, so the agent can fix its own mistakes
- Applies custom rules for project conventions, naming patterns and sensitive areas of the codebase
- Answers replies to its own review comments, and re-analyses a single file on demand
When to use Recurse ML / When not to
A quick filter to help you decide if Recurse ML is the right fit.
When to use Recurse ML
- Engineering teams that ship a high volume of AI-generated code and want a check that runs before merge, not after
- Small product teams and startups already living inside GitHub pull requests, where installation, sign-in and billing all pass through GitHub
- Developers working inside Claude Code or Cursor, who can wire the analysis into the agent's own loop through the REMCP server
- Open-source maintainers, since the vendor makes the tool free for life on open-source projects
- Teams with large, interconnected codebases, where a change can break something several files away from the diff
When not to use Recurse ML
- Teams hosting code outside GitHub: installation, authentication and payment all run through GitHub
- Windows-based developers, since the rml command-line tool is documented for Linux and macOS only
- Buyers looking for an application-security platform: the product is positioned on bugs and breaking changes, not on vulnerability scanning or compliance reporting
- Organisations whose procurement requires an obtained certification, a signed DPA and a published company address, none of which the vendor currently provides
- Developers who need a public, documented API to drive the analysis from their own tooling
How to use Recurse ML
A typical end-to-end flow, from setup to results.
- Decide which of the three entry points fits: the GitHub App for pull-request review, the rml CLI for local checks, or REMCP for use inside a coding agent
- For the GitHub App, open the Recurse ML app page on GitHub and click Configure
- Choose where to install it, on a personal account or an organisation, then select all repositories or a specific list, and click Install
- Complete the GitHub authentication flow; the app is active on the selected repositories straight away
- Open a pull request in one of those repositories and wait about a minute for the analysis to come back
- For the CLI, run the one-line curl installer, move into a Git repository, and run rml on a file; by default it analyses the unstaged changes that git diff shows
- For REMCP, run its one-line installer, add the local bin directory to your PATH, then run remcp auth to authenticate through GitHub
- Follow the installation guide for Claude Code or for Cursor, after which the /remcp:review_code prompt becomes available to the agent
- Optionally add custom rules to enforce project conventions, naming patterns or extra scrutiny on sensitive areas, and configure GitHub status checks
- Start the 14-day trial from the GitHub Marketplace listing and manage seats from app.recurse.ml
Pros & Cons
Pros
- One engine, three entry points: pull request, terminal and coding agent, all covered by the same plan
- A strict and written data position: no training on customer code, zero retention, and no copy of a codebase kept
- A named list of subprocessors published with processing locations and the data each one handles
- Free for life on open-source projects, and no usage limits advertised on the paid plan
- Simple, legible pricing: a single plan at $25 per user per month, or $250 per year
- One-command installation for the CLI and the MCP server, and a few clicks for the GitHub App
- Publisher verified by GitHub, with named, checkable customer testimonials from identified companies
Cons
- Total dependence on GitHub: installation, authentication and billing all run through it
- The rml CLI is documented for Linux and macOS only, with no Windows procedure
- No postal address, no contact page and no dedicated legal contact anywhere on the site
- SOC 2 and Cyber Essentials are announced as in progress; neither has been obtained
- The Data Processing Addendum the terms say they incorporate points at a placeholder that was never replaced
- Legal documents live on Notion and have not been updated since November and December 2024
- A single paid tier, with no team or enterprise level, no SLA, and no public API
Pricing & Plans
A permanent free option exists, but it is conditional: Recurse ML is free for life for open-source projects. Outside that case there is a single paid tier, the Pro Plan, priced at 25.00 USD per user per month, or 250.00 USD per user per year against a 300.00 USD list price. A 14-day free trial precedes any charge. Billing runs through GitHub and is counted per user, meaning each pull-request author and each CLI login. Taxes are not included.
- 25.00 USD per user per month
- or 250.00 USD per user per year against a 300.00 USD list price
- presented by the vendor as two months free. Described as access to everything you need to grow your business
- and covering full codebase understanding
- expert knowledge of every library
- code written the way you want
- unlimited access to the rml CLI
- Claude Code and Cursor integration
- free for life
- with no named plan and no listed price. The vendor states that billing through GitHub is precisely what lets it offer this.
Data, GDPR & hosting
A consolidated view of how Recurse ML handles your data.
GDPR overview
GDPR is addressed concretely rather than in passing. The terms state that under the GDPR the vendor acts as a service provider, not a business or third party, and that they incorporate a Data Processing Addendum wherever the EU GDPR or UK GDPR applies. The privacy policy enumerates the rights it honours, deliberately extending them to all customers regardless of location: information, access, rectification, erasure, restriction, objection, portability, freedom from solely automated decisions, non-discrimination and the right to complain to a supervisory authority. Requests go to a single address, armin@recurse.ml, with identity verification and written consent for authorised agents. Two gaps are worth noting: no Article 27 EU representative and no data protection officer is named, and the DPA link in the terms was never filled in.
Who owns the data?
The terms are explicit that you keep everything. All materials submitted to the service remain yours, and the vendor takes only a limited licence to use them for the purpose of delivering the service. Source code is treated separately and more strictly: the privacy policy states that no copy of a codebase is ever made or retained, and that any code the product operates on is the sole property of its author. Cerebral Adaptive Forecasting Ltd. claims no ownership over customer content, does not sell personal data, and will not use a customer's name in marketing without permission. Staff access to content requires explicit consent, except for blocking incidents, abuse investigations or a legally binding order.
Reuse rights
You may reuse your own material freely: the vendor holds no ownership rights over it, only a limited service licence, and the privacy policy grants a right to portability so you can export your data and pass it to another party. Deletion is equally under your control, with the caveat that erasing account data may make the service unusable. What you cannot reuse is the product itself: the terms forbid duplicating or reusing any part of the site's HTML, CSS, JavaScript or visual design, and require written permission to use the company's logos. On the vendor's side, code is processed rather than stored, and passed to named subprocessors including OpenAI in the United States and Anthropic in Europe for model hosting.
Data retention & training
Hosting summary
The picture the vendor paints is European, with a British legal home and one unreconciled inconsistency. The security overview states that primary data centres are in Europe and that Google Cloud Platform is used; the terms describe a UK company with all data infrastructure located in the EU. The privacy policy, however, says products and web properties are operated in the United Kingdom and that information provided is transferred to and stored there. Both statements appear in the vendor's own documents. On the subprocessor side, Google LLC is declared for cloud services with a European processing location, Anthropic for model hosting in Europe, and OpenAI L.L.C. for model hosting in the United States, meaning source code does cross the Atlantic in at least one path. Protection is described in detail: TLS in transit, encryption at rest, encrypted backups, each personal-data field encrypted with its own key, two-factor authentication for remote server access, and all access logged by IP address.
Things to keep in mind
Risks and trade-offs to weigh before adopting Recurse ML.
- The homepage pricing block reads $25 one-time payment, while the FAQ, the terms and the GitHub Marketplace listing all describe a monthly per-user subscription; check what you are actually signing up for
- The terms declare a Data Processing Addendum incorporated, but the link was never filled in and reads literally as a placeholder, so no DPA document is reachable online
- SOC 2 and Cyber Essentials are described as being pursued, never as obtained; treating them as certifications in a procurement file would be a mistake
- Source code is passed to third-party model providers, OpenAI in the United States and Anthropic in Europe, both listed as subprocessors handling source code
- The privacy policy places data infrastructure in the EU in one section and describes transfer and storage in the United Kingdom in another; both statements coexist and neither is reconciled
- No postal address, no contact page and no legal contact are published, and no Article 27 EU representative is designated despite the vendor serving EU customers
- An automated reviewer that answers back is easy to defer to; treating its silence as proof that a change is safe, or merging on its approval without human reading, replaces one blind spot with another
Setup & Integrations
Technical difficulty
Low, for anyone already on GitHub. The GitHub App takes a few clicks and needs no configuration; the vendor advertises it as zero-config with smart defaults, and the first result comes back about a minute after a pull request opens. The rml CLI and the REMCP server each install with a single curl command, though REMCP also asks you to add a directory to your PATH and to authenticate. Prerequisites are a GitHub account, a Git repository, and for the CLI a Linux or macOS machine. Custom rules are optional and documented.
Deployment
Integrations
Behind Recurse ML
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement Recurse ML.
Frequently asked questions
What exactly does Recurse ML do?
How is it different from a general-purpose AI code reviewer?
Which programming languages are supported?
What does it cost, and is there a free option?
Is my code stored or used to train models?
Who else gets to see the code?
How long is data kept after I cancel?
Is Recurse ML certified SOC 2?
What are the usage limits?
Can I use it without GitHub, or on Windows?
Should you pick Recurse ML?
Recurse ML has a clear thesis: the bottleneck in AI-assisted development has moved from writing code to checking it, so the check should be automatic and should run wherever the code is. Delivering one engine as a GitHub App, a local CLI and an MCP server for Claude Code and Cursor is a genuinely useful shape, and the one-command installs make it cheap to try.
Its data posture is the strongest part of the offer. Not training on customer code, keeping no copy of a codebase, publishing a named subprocessor list with processing locations, and spelling out deletion windows are commitments many vendors in this space leave vague. Pricing is equally plain: one plan at 25.00 USD per user per month, 250.00 USD a year, 14 days free, and free for life on open source.
The reservations are about maturity more than about the product. Everything runs through GitHub, so teams elsewhere are out. The CLI is documented for Linux and macOS only. There is no published postal address, no contact page and no dedicated legal contact. SOC 2 and Cyber Essentials are stated as in progress, never obtained, and the Data Processing Addendum the terms say they incorporate points at a placeholder that was never filled in. The legal documents themselves have not moved since late 2024. And the homepage pricing block labels the 25 USD a one-time payment, which the FAQ, the terms and the Marketplace listing all contradict.
For a small team already living inside GitHub pull requests, and leaning hard on coding agents, the trade is reasonable and the trial costs nothing. For a regulated buyer who needs certifications, a signed DPA and a company address on the website, this is not yet the moment.
- Choosing a selection results in a full page refresh.
- Opens in a new window.