
Greptile
Greptile is an AI code review agent that indexes your whole repository as a graph, then runs a swarm of agents on every pull request to catch multi-file bugs, security risks and standards violations before merge.
What is Greptile?
Greptile is an AI code reviewer that reads pull requests with the context of the whole repository behind it. Rather than looking at a diff in isolation, it first builds a graph index of the codebase, mapping files, functions, imports and dependencies. A swarm of parallel agents then reviews the change against that map, assessing its ripple effects on callers, shared modules and internal contracts, and flagging logic bugs, security risks, resource leaks and cross-file inconsistencies. A third layer keeps learning: Greptile reads other engineers' comments in GitHub and GitLab to absorb a team's coding standards, and suppresses the kinds of remarks that team routinely ignores. Every review comes back as a PR summary, a confidence score from 0 to 5, sequence diagrams, generated unit tests and inline comments, each of which can be sent to a coding agent for a one-click fix. A beta agent called TREX goes further and actually runs the branch in an isolated sandbox, attaching logs, screenshots, traces and videos to the comments it leaves. Teams shape the behaviour through plain-English rules in a .greptile/ folder or a greptile.json file, and Greptile also picks up existing CLAUDE.md, AGENTS.md and Cursor rules automatically. The company positions the product as an independent validation layer, deliberately tied to no single model, editor or coding agent, at a moment when much of the code under review is written by agents. Reviews can be triggered from a pull request, from the terminal with a local CLI, or from an editor through an MCP server and plugins for Claude Code and Codex. Greptile publishes figures of more than 22,000 teams, one million pull requests and three billion lines of code reviewed each month, and names Brex, Substack, PostHog and Bilt among its customers. It runs either as a SOC 2 Type II cloud service or self-hosted on Docker Compose, Kubernetes or air-gapped infrastructure, with the option of bringing your own LLM.
What it does
- Review every pull request automatically on GitHub and GitLab
- Index an entire repository as a graph of files, functions and dependencies
- Flag multi-file logic bugs, security risks and resource leaks that a diff alone hides
- Run the branch in a sandbox and write tests against it with TREX (beta)
- Produce a PR summary, a 0-5 confidence score and sequence diagrams for every change
- Hand any finding to Claude Code, Codex, Cursor, Devin or Conductor for a one-click fix
- Enforce house rules written in plain English and auto-approve clean, low-risk pull requests
When to use Greptile / When not to
A quick filter to help you decide if Greptile is the right fit.
When to use Greptile
- Engineering teams merging a high volume of pull requests on GitHub or GitLab
- Organizations shipping agent-written code from Claude Code, Cursor, Codex or Devin who want an independent validation layer
- Regulated enterprises in defense, healthcare or financial services that need self-hosted, air-gapped deployment with SSO and audit logs
- Solo developers and open-source maintainers, covered by the free Starter tier and the OSI open-source program
- Pre-Series A startups under 2M USD of revenue, eligible for the 50% discount
When not to use Greptile
- Anyone wanting a mobile companion: there is no iOS or Android app
- Teams whose code does not live on GitHub, GitLab, Bitbucket or Azure
- People looking for a general-purpose assistant: Greptile only reviews code
- Growing teams hoping to stay free, since the Starter tier caps at one active developer and 50 credits a month
- Non-English-speaking teams, as the interface and documentation are English only
How to use Greptile
A typical end-to-end flow, from setup to results.
- Create an account on the Greptile web app and start the 14-day trial, no credit card required
- Connect GitHub or GitLab and pick the repositories to cover; the quickstart is advertised at five minutes
- As an alternative, install the CLI with curl, npm, pnpm, bun or brew and run the onboarding command from the terminal
- Let Greptile index the codebase and build its graph
- Open a pull request: the review fires automatically, or on demand by mentioning the bot
- Read the PR summary, the 0-5 confidence score, the diagrams and the inline comments
- Send a finding to your coding agent with Fix with your Agent, or dispatch them all with Fix All
- React with emoji or reply to a comment to train the learning system on your team's preferences
- Tune strictness, comment types and ignored file patterns in greptile.json or a .greptile/ folder
- To try it before signing up at all, paste a GitHub pull request link on the public review page
Pros & Cons
Pros
- Reviews with the whole codebase in view, which is what lets it catch bugs spread across several files
- Genuine self-hosting: Docker Compose, Kubernetes, air-gapped environments, and the option to bring your own LLM
- Opt-out from AI training is documented and actionable from the account settings
- SOC 2 Type II, HIPAA and GDPR compliance claimed, with a public trust center and reports available on request
- Low barrier to trial: a permanent free tier, a 14-day trial without a credit card, and a demo that needs no account at all
- Published benchmark with an open methodology and verifiable public repositories, alongside comparison pages against named competitors
- Deliberate work on signal over noise, with nitpick filtering and learning from the team's own review habits
Cons
- Training on de-identified customer data is on by default; switching it off is left to the customer
- No postal address is published anywhere on the site, and no Article 27 EU representative or DPO is named despite the GDPR claim
- The hosted service is United States only, so EU data residency means going self-hosted
- The subprocessor list is not on the site itself: the page points to a separate trust center
- The free tier is narrow, at one active developer and 50 credits a month, and heavy use adds credits at 1 USD each
- TREX and auto-approval are still in beta, and the terms explicitly disclaim any warranty on beta services
- No mobile app, English-only interface and documentation, and prices published in US dollars only
Pricing & Plans
Greptile offers a permanent free plan, Starter, limited to one active developer with 50 credits per month. The cheapest paid tier is Pro, at 30 USD per seat per month, preceded by a 14-day free trial that requires no credit card. Enterprise pricing is quoted on request, and annual or multi-year contracts are priced individually.
- unlimited repositories
- 50 credits per month
- one active developer
- unlimited repositories
- 50 credits included per seat
- additional credits at 1 USD each
- unlimited users
- custom rules
- unlimited external app connections
- optional self-hosting in your own infrastructure
- security and compliance controls
- SSO/SAML
- GitHub Enterprise support
- dedicated Slack support channel
- custom invoicing
- custom DPA and terms of service
- 1 credit buys one standard review
- 3 credits buy one TREX review
- priced individually on request
- Cancellation available at any time from the account settings
Data, GDPR & hosting
A consolidated view of how Greptile handles your data.
GDPR overview
Greptile claims GDPR compliance in plain words: the enterprise FAQ states the product is SOC 2 Type II, HIPAA and GDPR compliant. The privacy notice carries a dedicated section for the European Union, EEA, Switzerland and the United Kingdom, naming the legal bases relied on (consent, performance of a contract, legal obligation, legitimate interest) and committing to standard contractual clauses for transfers outside that region. Access, deletion, correction, objection, withdrawal of consent and the right to complain to a supervisory authority are all listed; requests go to support@greptile.com or to a US phone number. The company states it does not sell personal data, does not disclose it for cross-context advertising, and performs no profiling or automated decision-making. Two gaps remain: no Article 27 representative and no data protection officer are named, and the hosted service runs in the United States only.
Who owns the data?
Under the Terms and Conditions, customers keep what they bring: all Customer Data is treated as proprietary to the customer, and Greptile may use it only to perform the services or as the customer authorizes. Everything else stays with the vendor. Tabnam, Inc. retains all rights to the platform, along with any derivative work, modification or enhancement of it, and customers assign any feedback or suggestion they contribute. De-identified, aggregated data and the AI training and learnings derived from it are owned solely and exclusively by Greptile, though the underlying customer code is not. Staff access to stored code is restricted, permission-controlled and logged.
Reuse rights
What the service produces is the customer's to reuse without asking: reviews, PR summaries, generated diagrams, unit tests and suggested fixes can be applied freely, and the terms state that all decisions based on the output remain the customer's own. Customer code and data stay the customer's throughout, a copy is returned within thirty days of termination, and administrators can trigger deletion of everything at any point during the subscription. The restrictions concern the platform itself, not the results: reselling it, making it available to third parties, running it on a time-sharing or service-bureau basis, reverse engineering it, or using it to build or offer a competing product are all forbidden.
Data retention & training
Hosting summary
The hosted service runs in the United States. The privacy notice states plainly that the site is hosted there and that personal information may be transferred to the United States and other jurisdictions, with standard contractual clauses covering transfers out of the EU, EEA, Switzerland and the United Kingdom. Infrastructure is provided by Amazon Web Services and Microsoft Azure. Customer code sits on an encrypted filesystem and stays cached until access is revoked in GitHub or GitLab, at which point it is deleted; vector embeddings of file paths, documentation and generated docstrings live in a vector database, and chat logs in an AWS DynamoDB database. Cloud inference is handled through the OpenAI and Anthropic API platforms. Customers who self-host keep everything inside their own servers or cloud environment, logs included, and may run their own LLM. The contract is governed by the law of the State of Delaware, and the full subprocessor list is published on a separate trust center.
Things to keep in mind
Risks and trade-offs to weigh before adopting Greptile.
- Automation lulls attention: auto-approving pull requests rated 5/5 can quietly remove the last human read on a real change
- False confidence in coverage: the vendor's own benchmark reports 58% detection on critical bugs, so roughly half still slip through
- Skill erosion: leaning on an automated reviewer can starve junior engineers of the peer review that teaches them the codebase
- Silent data exposure: training on de-identified data is on by default, so without an explicit opt-out company code feeds the vendor's models
- Conversation logs are stored on the vendor's infrastructure unless the customer turns logging off
- Third-party dependency: the cloud offering routes inference through OpenAI and Anthropic, adding a subcontracting chain to audit
- Single point of friction in the merge pipeline: an outage or a beta feature misbehaving slows the whole delivery chain
Setup & Integrations
Technical difficulty
Easy for the cloud version, hard for the self-hosted one. In the cloud, you connect GitHub or GitLab, pick repositories and let the indexing run: the quickstart is advertised at five minutes, no credit card is needed, and a public page even reviews a pasted pull request with no account. The CLI is a single install command. Self-hosting is another matter, needing Docker Compose on a Linux server or Kubernetes via a Helm chart, a customer-managed PostgreSQL with pgvector, Redis, and SSO wiring. The audience is developers throughout.
Deployment
Integrations
Behind Greptile
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement Greptile.
Frequently asked questions
How does Greptile pricing work?
Can Greptile be self-hosted?
Which source control platforms does it support?
Which programming languages does Greptile cover?
Is my code used to train Greptile's models?
Is there an API?
Which certifications does Greptile hold?
Can I try it without creating an account?
Are there free or discounted options?
What happens to my code when I stop using Greptile?
Should you pick Greptile?
Greptile is a narrow product done seriously. It does one thing, reviewing pull requests, and its differentiator is architectural rather than cosmetic: it indexes the entire repository as a graph before a swarm of agents ever looks at a diff, which is what allows it to raise bugs living in the seams between files, services and shared dependencies. The surrounding evidence is unusually concrete for this market. There is a published benchmark with an open methodology and reproducible public repositories, comparison pages against named competitors, real bugs shown in well-known open-source projects, and named customers including Brex, Substack, PostHog and Bilt. Two funding rounds and 30M USD raised suggest the company will still be there next year. Operationally it is mature. SOC 2 Type II, a public trust center, working self-hosting on Docker Compose, Kubernetes or air-gapped infrastructure, the option of bringing your own LLM, SSO and audit logging: the enterprise checklist is genuinely covered, and the entry cost stays low, with a permanent free tier and 30 USD per seat per month above it. The reservations are worth weighing. Training on de-identified customer data is enabled by default and it is up to you to switch it off. GDPR compliance is claimed, yet no Article 27 representative and no data protection officer are named, no postal address appears anywhere on the site, and the hosted service runs only in the United States, so EU data residency means self-hosting. TREX and auto-approval are still beta, and the terms disclaim any warranty on beta services. Finally, a benchmark published by the vendor itself, showing 58% detection on critical bugs, is a reminder that this is a second pair of eyes, not a replacement for human review.
- Choosing a selection results in a full page refresh.
- Opens in a new window.