Greptile logo
Code Review Testing · Code Assistants

Greptile

Greptile is an AI code review agent that indexes your whole repository as a graph, then runs a swarm of agents on every pull request to catch multi-file bugs, security risks and standards violations before merge.

Active GDPR compliant Free plan · Free trial Freemium API available Verified by Guidaio
Overview

What is Greptile?

Greptile is an AI code reviewer that reads pull requests with the context of the whole repository behind it. Rather than looking at a diff in isolation, it first builds a graph index of the codebase, mapping files, functions, imports and dependencies. A swarm of parallel agents then reviews the change against that map, assessing its ripple effects on callers, shared modules and internal contracts, and flagging logic bugs, security risks, resource leaks and cross-file inconsistencies. A third layer keeps learning: Greptile reads other engineers' comments in GitHub and GitLab to absorb a team's coding standards, and suppresses the kinds of remarks that team routinely ignores. Every review comes back as a PR summary, a confidence score from 0 to 5, sequence diagrams, generated unit tests and inline comments, each of which can be sent to a coding agent for a one-click fix. A beta agent called TREX goes further and actually runs the branch in an isolated sandbox, attaching logs, screenshots, traces and videos to the comments it leaves. Teams shape the behaviour through plain-English rules in a .greptile/ folder or a greptile.json file, and Greptile also picks up existing CLAUDE.md, AGENTS.md and Cursor rules automatically. The company positions the product as an independent validation layer, deliberately tied to no single model, editor or coding agent, at a moment when much of the code under review is written by agents. Reviews can be triggered from a pull request, from the terminal with a local CLI, or from an editor through an MCP server and plugins for Claude Code and Codex. Greptile publishes figures of more than 22,000 teams, one million pull requests and three billion lines of code reviewed each month, and names Brex, Substack, PostHog and Bilt among its customers. It runs either as a SOC 2 Type II cloud service or self-hosted on Docker Compose, Kubernetes or air-gapped infrastructure, with the option of bringing your own LLM.

What it does

  • Review every pull request automatically on GitHub and GitLab
  • Index an entire repository as a graph of files, functions and dependencies
  • Flag multi-file logic bugs, security risks and resource leaks that a diff alone hides
  • Run the branch in a sandbox and write tests against it with TREX (beta)
  • Produce a PR summary, a 0-5 confidence score and sequence diagrams for every change
  • Hand any finding to Claude Code, Codex, Cursor, Devin or Conductor for a one-click fix
  • Enforce house rules written in plain English and auto-approve clean, low-risk pull requests
Audience

When to use Greptile / When not to

A quick filter to help you decide if Greptile is the right fit.

When to use Greptile

  • Engineering teams merging a high volume of pull requests on GitHub or GitLab
  • Organizations shipping agent-written code from Claude Code, Cursor, Codex or Devin who want an independent validation layer
  • Regulated enterprises in defense, healthcare or financial services that need self-hosted, air-gapped deployment with SSO and audit logs
  • Solo developers and open-source maintainers, covered by the free Starter tier and the OSI open-source program
  • Pre-Series A startups under 2M USD of revenue, eligible for the 50% discount

When not to use Greptile

  • Anyone wanting a mobile companion: there is no iOS or Android app
  • Teams whose code does not live on GitHub, GitLab, Bitbucket or Azure
  • People looking for a general-purpose assistant: Greptile only reviews code
  • Growing teams hoping to stay free, since the Starter tier caps at one active developer and 50 credits a month
  • Non-English-speaking teams, as the interface and documentation are English only
Get started

How to use Greptile

A typical end-to-end flow, from setup to results.

  1. Create an account on the Greptile web app and start the 14-day trial, no credit card required
  2. Connect GitHub or GitLab and pick the repositories to cover; the quickstart is advertised at five minutes
  3. As an alternative, install the CLI with curl, npm, pnpm, bun or brew and run the onboarding command from the terminal
  4. Let Greptile index the codebase and build its graph
  5. Open a pull request: the review fires automatically, or on demand by mentioning the bot
  6. Read the PR summary, the 0-5 confidence score, the diagrams and the inline comments
  7. Send a finding to your coding agent with Fix with your Agent, or dispatch them all with Fix All
  8. React with emoji or reply to a comment to train the learning system on your team's preferences
  9. Tune strictness, comment types and ignored file patterns in greptile.json or a .greptile/ folder
  10. To try it before signing up at all, paste a GitHub pull request link on the public review page
Quick read

Pros & Cons

Pros

  • Reviews with the whole codebase in view, which is what lets it catch bugs spread across several files
  • Genuine self-hosting: Docker Compose, Kubernetes, air-gapped environments, and the option to bring your own LLM
  • Opt-out from AI training is documented and actionable from the account settings
  • SOC 2 Type II, HIPAA and GDPR compliance claimed, with a public trust center and reports available on request
  • Low barrier to trial: a permanent free tier, a 14-day trial without a credit card, and a demo that needs no account at all
  • Published benchmark with an open methodology and verifiable public repositories, alongside comparison pages against named competitors
  • Deliberate work on signal over noise, with nitpick filtering and learning from the team's own review habits

Cons

  • Training on de-identified customer data is on by default; switching it off is left to the customer
  • No postal address is published anywhere on the site, and no Article 27 EU representative or DPO is named despite the GDPR claim
  • The hosted service is United States only, so EU data residency means going self-hosted
  • The subprocessor list is not on the site itself: the page points to a separate trust center
  • The free tier is narrow, at one active developer and 50 credits a month, and heavy use adds credits at 1 USD each
  • TREX and auto-approval are still in beta, and the terms explicitly disclaim any warranty on beta services
  • No mobile app, English-only interface and documentation, and prices published in US dollars only
Pricing

Pricing & Plans

Greptile offers a permanent free plan, Starter, limited to one active developer with 50 credits per month. The cheapest paid tier is Pro, at 30 USD per seat per month, preceded by a 14-day free trial that requires no credit card. Enterprise pricing is quoted on request, and annual or multi-year contracts are priced individually.

Starter - free - for individual developers
  • unlimited repositories
  • 50 credits per month
  • one active developer
Enterprise - custom pricing - for organizations at scale
  • optional self-hosting in your own infrastructure
  • security and compliance controls
  • SSO/SAML
  • GitHub Enterprise support
  • dedicated Slack support channel
  • custom invoicing
  • custom DPA and terms of service
Credit unit
  • 1 credit buys one standard review
  • 3 credits buy one TREX review
Annual and multi-year contracts
  • priced individually on request
Plan 6
  • Cancellation available at any time from the account settings
Special offers — Open-source program: free reviews for public GitHub or GitLab repositories under an OSI-approved license, granted on application · Startup discount: 50% off for pre-Series A companies with less than 2M USD of revenue over the past twelve months · Dedicated page for Y Combinator portfolio companies · Permanent free Starter tier for one active developer · 14-day free trial with no credit card required · Custom pricing on annual and multi-year contracts
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Greptile handles your data.

GDPR overview

Greptile claims GDPR compliance in plain words: the enterprise FAQ states the product is SOC 2 Type II, HIPAA and GDPR compliant. The privacy notice carries a dedicated section for the European Union, EEA, Switzerland and the United Kingdom, naming the legal bases relied on (consent, performance of a contract, legal obligation, legitimate interest) and committing to standard contractual clauses for transfers outside that region. Access, deletion, correction, objection, withdrawal of consent and the right to complain to a supervisory authority are all listed; requests go to support@greptile.com or to a US phone number. The company states it does not sell personal data, does not disclose it for cross-context advertising, and performs no profiling or automated decision-making. Two gaps remain: no Article 27 representative and no data protection officer are named, and the hosted service runs in the United States only.

Who owns the data?

Under the Terms and Conditions, customers keep what they bring: all Customer Data is treated as proprietary to the customer, and Greptile may use it only to perform the services or as the customer authorizes. Everything else stays with the vendor. Tabnam, Inc. retains all rights to the platform, along with any derivative work, modification or enhancement of it, and customers assign any feedback or suggestion they contribute. De-identified, aggregated data and the AI training and learnings derived from it are owned solely and exclusively by Greptile, though the underlying customer code is not. Staff access to stored code is restricted, permission-controlled and logged.

Reuse rights

What the service produces is the customer's to reuse without asking: reviews, PR summaries, generated diagrams, unit tests and suggested fixes can be applied freely, and the terms state that all decisions based on the output remain the customer's own. Customer code and data stay the customer's throughout, a copy is returned within thirty days of termination, and administrators can trigger deletion of everything at any point during the subscription. The restrictions concern the platform itself, not the results: reselling it, making it available to third parties, running it on a time-sharing or service-bureau basis, reverse engineering it, or using it to build or offer a competing product are all forbidden.

Data retention & training

Retention summary
The privacy notice sets no fixed duration: personal information is kept as long as needed to do business with you, to meet the purposes it describes and to satisfy legal obligations. Code is treated more precisely. It stays cached on Greptile's machines until access is revoked in GitHub or GitLab, and is then deleted. An administrator can delete all customer data at any time during a subscription, with hard deletion from production systems within 24 hours and backups destroyed within 30 days, a window that may be extended during an incident investigation. After termination, a copy of customer data is returned within thirty days and deleted thereafter, subject to archival copies. Chat logging can be turned off entirely. Anonymized de-identified data falls outside this schedule and remains the vendor's property.
Trains on customer data
Configurable
Training opt-out available
Yes
Subprocessors disclosed
Yes
DPA available
Yes
GDPR contact

Hosting summary

The hosted service runs in the United States. The privacy notice states plainly that the site is hosted there and that personal information may be transferred to the United States and other jurisdictions, with standard contractual clauses covering transfers out of the EU, EEA, Switzerland and the United Kingdom. Infrastructure is provided by Amazon Web Services and Microsoft Azure. Customer code sits on an encrypted filesystem and stays cached until access is revoked in GitHub or GitLab, at which point it is deleted; vector embeddings of file paths, documentation and generated docstrings live in a vector database, and chat logs in an AWS DynamoDB database. Cloud inference is handled through the OpenAI and Anthropic API platforms. Customers who self-host keep everything inside their own servers or cloud environment, logs included, and may run their own LLM. The contract is governed by the law of the State of Delaware, and the full subprocessor list is published on a separate trust center.

Hosting countries
🇺🇸 United States
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Greptile.

  • Automation lulls attention: auto-approving pull requests rated 5/5 can quietly remove the last human read on a real change
  • False confidence in coverage: the vendor's own benchmark reports 58% detection on critical bugs, so roughly half still slip through
  • Skill erosion: leaning on an automated reviewer can starve junior engineers of the peer review that teaches them the codebase
  • Silent data exposure: training on de-identified data is on by default, so without an explicit opt-out company code feeds the vendor's models
  • Conversation logs are stored on the vendor's infrastructure unless the customer turns logging off
  • Third-party dependency: the cloud offering routes inference through OpenAI and Anthropic, adding a subcontracting chain to audit
  • Single point of friction in the merge pipeline: an outage or a beta feature misbehaving slows the whole delivery chain
Setup

Setup & Integrations

Technical difficulty

Easy for the cloud version, hard for the self-hosted one. In the cloud, you connect GitHub or GitLab, pick repositories and let the indexing run: the quickstart is advertised at five minutes, no credit card is needed, and a public page even reviews a pasted pull request with no account. The CLI is a single install command. Self-hosting is another matter, needing Docker Compose on a Linux server or Kubernetes via a Helm chart, a customer-managed PostgreSQL with pgvector, Redis, and SSO wiring. The audience is developers throughout.

Deployment

Web appAPIPluginDesktop app

Integrations

GitHub GitLab Bitbucket Azure DevOps Jira Confluence Linear Notion Zapier Claude Code Cursor OpenAI Codex Devin Conductor Windsurf VS Code
Company

Behind Greptile

Company name
Tabnam, Inc.
Founded
04/12/2021
Country of origin
🇺🇸 United States
UBO
Daksh Gupta
UBO country
🇺🇸 United States
Domain registrar country
🇺🇸 United States
Support contact

Fundraising

Seed round of 4.1M USD announced on 9 June 2024, led by Initialized Capital, with angel investors Rich Aberman (WePay) and JJ Fliegelman (WayUp)
Series A of 25M USD announced on 23 September 2025, led by Benchmark Capital, with continued support from Cory Levy, Y Combinator and Initialized Capital

Social

Official links

Resources

All the official URLs gathered for verification and reference.

Compare

Alternatives

Tools that compete with or complement Greptile.

C CodeRabbitC Cursor BugBotC CopilotG GraphiteQ QodoA Augment CodeS SonarQubeS Semgrep
FAQ

Frequently asked questions

How does Greptile pricing work?
Starter is free for one active developer and includes unlimited repositories and 50 credits per month. Pro costs 30 USD per seat per month and includes 50 credits per seat. One credit buys a standard review, three credits buy a TREX review, and extra credits cost 1 USD each. Enterprise pricing is quoted on request.
Can Greptile be self-hosted?
Yes. It can run in your own AWS environment, on Docker Compose for a single Linux server, on Kubernetes for larger installs, or in an air-gapped environment. Self-hosted customers can also point Greptile at their own LLM providers by supplying a base URL and keys.
Which source control platforms does it support?
GitHub and GitLab, including GitHub Enterprise and self-hosted GitHub or GitLab. The MCP tools reference also lists Bitbucket and Azure as repository remotes.
Which programming languages does Greptile cover?
Python, JavaScript, TypeScript, Go, Elixir, Java, C, C++, C#, Swift, PHP and Rust are fully supported. Most other mainstream languages work too, with slightly lower response quality.
Is my code used to train Greptile's models?
By default it can be, in aggregated and anonymized form: the terms allow Greptile to build de-identified data and use it for AI training. An opt-out exists and is documented, set from the AI training preferences in your account, and the security team answers questions about it by email.
Is there an API?
Yes. The homepage FAQ mentions discounted bulk pricing for API use, arranged through support, and the documentation publishes a full reference for the tools exposed by the Greptile MCP server, covering pull requests, reviews, comment search, custom context and knowledge bases.
Which certifications does Greptile hold?
Greptile states it is SOC 2 Type II compliant, with the report available on request, and the enterprise FAQ adds HIPAA and GDPR. Security documentation, compliance reports and the full subprocessor list are published on a separate trust center.
Can I try it without creating an account?
Yes. A public page lets you paste a GitHub pull request link and get it reviewed on the spot, and it works on public and private repositories. There is also a 14-day free trial with no credit card required.
Are there free or discounted options?
Public GitHub or GitLab repositories under an OSI-approved license can apply to the open-source program for free reviews. Pre-Series A companies with less than 2M USD of revenue over the past twelve months can claim a 50% discount.
What happens to my code when I stop using Greptile?
A copy of customer data is returned within thirty days of termination, after which it is deleted. During a subscription, an administrator can delete everything at any time: hard deletion from production systems happens within 24 hours, and backups are destroyed within 30 days.
Conclusion

Should you pick Greptile?

Greptile is a narrow product done seriously. It does one thing, reviewing pull requests, and its differentiator is architectural rather than cosmetic: it indexes the entire repository as a graph before a swarm of agents ever looks at a diff, which is what allows it to raise bugs living in the seams between files, services and shared dependencies. The surrounding evidence is unusually concrete for this market. There is a published benchmark with an open methodology and reproducible public repositories, comparison pages against named competitors, real bugs shown in well-known open-source projects, and named customers including Brex, Substack, PostHog and Bilt. Two funding rounds and 30M USD raised suggest the company will still be there next year. Operationally it is mature. SOC 2 Type II, a public trust center, working self-hosting on Docker Compose, Kubernetes or air-gapped infrastructure, the option of bringing your own LLM, SSO and audit logging: the enterprise checklist is genuinely covered, and the entry cost stays low, with a permanent free tier and 30 USD per seat per month above it. The reservations are worth weighing. Training on de-identified customer data is enabled by default and it is up to you to switch it off. GDPR compliance is claimed, yet no Article 27 representative and no data protection officer are named, no postal address appears anywhere on the site, and the hosted service runs only in the United States, so EU data residency means self-hosting. TREX and auto-approval are still beta, and the terms disclaim any warranty on beta services. Finally, a benchmark published by the vendor itself, showing 58% detection on critical bugs, is a reminder that this is a second pair of eyes, not a replacement for human review.