Hyrax logo
Code Review Testing · Security Code Scanning

Hyrax

Hyrax is a hosted platform that maps a GitHub codebase, runs a six-agent audit across security, correctness, maintainability, performance, architecture and operations, then ships each approved fix as a verified pull request an engineer merges.

Active GDPR compliant Free plan Freemium API available 18+ Verified by Guidaio
Overview

What is Hyrax?

Hyrax is a hosted code-audit and remediation platform built by Hyrax AI, LLC, a subsidiary of Iru, Inc., based in Coral Gables, Florida. It presents itself as the codebase architect: where coding agents have multiplied the volume of code a team produces, Hyrax is meant to give that output structure, context and a path to review. The site leans on an NBER working paper (35275, 2026, more than 100,000 developers) showing autonomous agents raising lines of code by 1,700% while releases rose only 30%.

The product runs four workflows over a single repository context graph. Scan begins with Discovery, which reads the whole repository once and commits a HYRAX.md file plus a .hyrax/ directory holding the architecture, the conventions with their occurrence counts, the environment variables and the team's definition of done. Audits then run continuously: six specialised agent groups, covering security, correctness, maintainability, performance, architecture and operations, work alongside a deterministic scanner, and every finding carries a severity, a confidence level and an exact file and line, ranked P0 to P3.

Fix turns a finding into code. Hyrax writes the change in an isolated Git worktree and puts it through thirteen verification stages: baseline tests, a diff-size guard capped at 20 files or 2,000 lines, test regression, build, auto-formatting, lint, a cross-project test, a scanner pass over its own diff, a second agent's review and a post-fix audit. Only if all thirteen pass does a [Hyrax] pull request open on a hyrax/ branch. Improve keeps architectural guidance out of the must-fix queue, and Govern reviews incoming pull requests and posts a check run that can gate the merge.

Inference runs on Anthropic's Claude models through Amazon Bedrock in Hyrax's own AWS account, with no API key to supply. The audit covers eighteen or more languages, GitHub is the only source-control platform supported at launch, and Linear is the only ticketing integration. A REST API with an OpenAPI 3.1 document and an MCP server ship with both plans. Hyrax never merges its own pull requests and never writes to a production branch.

What it does

  • Map an entire repository: architecture, dependencies, conventions and constraints
  • Publish that context back into the repository as a HYRAX.md file and a .hyrax/discovery directory
  • Audit every file continuously with six specialised agent groups and a deterministic scanner
  • Rank each finding from P0 to P3 with its exact file and line
  • Write the fix in an isolated worktree and put it through thirteen verification stages
  • Open the change as a [Hyrax] pull request on a dedicated branch for a human to merge
  • Review incoming pull requests automatically and post a Hyrax Review check run that can block a merge
Audience

When to use Hyrax / When not to

A quick filter to help you decide if Hyrax is the right fit.

When to use Hyrax

  • Engineering teams shipping on GitHub that generate more code than they can realistically review
  • Teams already running Cursor, Claude Code or GitHub Copilot and looking for a governance layer above them
  • Platform and application security teams whose SAST backlog grows faster than it is cleared
  • Organisations that must produce change-management evidence for PCI DSS, SOC 2 or SOX audits
  • Solo developers and small teams, since the free plan is the full product and public repositories connect by URL alone

When not to use Hyrax

  • Teams hosting code anywhere other than GitHub, as GitLab, Bitbucket and Azure DevOps are not supported
  • Anyone looking for dependency, container, infrastructure-as-code or DAST scanning, all placed outside the product's scope
  • Buyers who need self-hosting, an air-gapped deployment or a command-line client
  • Jira-based delivery teams, since Linear is the only ticketing integration available today
  • Users located outside the United States and anyone under 18, both excluded by the privacy policy and the terms
Get started

How to use Hyrax

A typical end-to-end flow, from setup to results.

  1. Create a workspace at app.hyrax.dev/signup, with no credit card required
  2. Sign in without a password, through GitHub, Google or a one-time email code, with two-factor authentication mandatory on every account
  3. Install the Hyrax GitHub App on the repositories to analyse, which takes about two minutes
  4. Let Discovery run: it profiles the codebase in ten to twenty minutes and opens a first pull request carrying HYRAX.md and the .hyrax/ directory
  5. Or add a public repository by URL alone, read-only and anonymously, without installing the App
  6. Launch an audit and triage the findings, which arrive ranked P0 to P3 with file and line
  7. Ask Hyrax to fix a finding, then review and merge the pull request it opens
  8. Enable automatic pull-request review on a repository and, if wanted, make the Hyrax Review check required for merging
  9. Connect Linear as an admin or owner by storing a Linear API key in the workspace settings
  10. Create an API key for the REST API or the MCP server, optionally with rate, spend, expiry and IP-range limits
Quick read

Pros & Cons

Pros

  • Goes all the way from finding to merge-ready pull request, where scanners stop at a report
  • Thirteen verification stages and a post-fix audit mean nothing ships if a single check fails
  • The human keeps control: Hyrax never merges and never writes to a production branch
  • Persistent codebase context is committed into the repository, where Cursor, Copilot and Claude Code can read it
  • Two-minute setup, with no rules to author and no change to the existing CI pipeline
  • The free plan is the full product, with a $30 starting credit and up to 100 pull-request reviews a month
  • Unusually detailed security documentation, from sandbox design to retention windows and a named sub-processor list

Cons

  • GitHub only: GitLab, Bitbucket and Azure DevOps are not supported
  • Linear is the sole ticketing integration, with Jira only on the roadmap
  • No dependency, container, infrastructure-as-code or DAST scanning, and no test-coverage tracking
  • The privacy policy restricts the service to users located in the United States while the documentation claims GDPR compliance, and the two do not agree
  • SOC 2 Type II is not yet issued: the observation window only opened on 22 June 2026, and interim evidence is available under NDA alone
  • Running cost is hard to forecast, with audits from $1 to $35 and fixes from $1 to $10 metered on top of the seat price
  • Credits expire monthly with no rollover, no cash value and no refund, and an account left inactive for 30 consecutive days can be closed
Pricing

Pricing & Plans

Hyrax offers a permanent free plan rather than a time-limited trial. It carries the complete product, a $30 starting credit, $10 of credits every month and up to 100 pull-request reviews a month, with no credit card required. The lowest paid entry point is $30 (USD) per user per month, which adds $30 of monthly credits per seat. Compute is metered in credits on top of the seat price, at roughly $5 to $10 for a one-off Discovery, $1 to $35 for a full audit and $1 to $10 per fix.

Free - $0 per month
  • the complete product
  • a $30 starting credit
  • $10 of credits every month and up to 100 pull-request reviews a month
  • without a credit card
Paid - $30 per user per month
  • everything in Free
  • plus $30 of credits per user each month and opt-in overage under a budget cap the customer sets
Special offers — A $30 starting credit granted to every new workspace · $10 of credits every month on the free plan, renewed automatically · Up to 100 pull-request reviews a month at no cost, on both plans · No credit card required to start · No student, non-profit, open-source or annual-commitment discount is published
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Hyrax handles your data.

GDPR overview

Hyrax's compliance documentation states GDPR compliance in plain terms: the customer is the data controller, Iru (Hyrax) acts as processor, and the vendors in the published sub-processor catalogue are sub-processors. An Article 28 data-processing agreement covering Hyrax is available on request, with standard contractual clauses where applicable, alongside a lawful-bases statement. CCPA and CPRA are listed as compliant too. The privacy policy, however, never mentions the GDPR and states that the service is offered only to users located in the United States; its rights section rests on US state law and directs requests to legal@hyrax.dev. No Article 27 EU representative and no data protection officer is named anywhere on the site. European buyers should therefore treat the documentation's claim as the opening of a conversation with the vendor rather than a settled position.

Who owns the data?

Under section 5 of the terms, the customer keeps all right, title and interest in its Customer Data, and also owns the Output that Hyrax generates for it, subject to Hyrax's own technology and to any third-party or open-source rights carried by that output. The customer grants Hyrax and its sub-processors a worldwide, non-exclusive licence, limited to the contract term, to host, process and display that data only as needed to run and secure the service. Hyrax, for its part, owns the Usage Data and the De-Identified Data derived from operations, provided neither contains identifiable customer code.

Reuse rights

The customer may reuse its own code and the fixes Hyrax produces without asking permission, since it owns both. The terms add only a caution: outputs are not unique, may resemble or incorporate third-party or open-source material, and must be reviewed for provenance, security, licence obligations and fitness before use. On the vendor's side, repository code is processed in memory, the working clone is deleted when a job ends, and model-processing logs record request metadata and token counts alone. The terms rule out intentionally using identifiable customer code to train generalised third-party foundation models, and the site's FAQ says plainly that Hyrax does not train on customer code. The technical documentation is more guarded, declining to make an independent no-training claim and pointing instead to the model provider's own data terms, since inference runs on Amazon Bedrock. Usage Data and De-Identified Data, by contrast, belong to Hyrax and are used for analytics, benchmarking, product improvement, prompt tuning and model evaluation.

Data retention & training

Retention summary
Source code is never kept: the working clone is deleted when a job ends, on success, failure or cancellation, and staged copies on the processing infrastructure expire within seven days as a backstop. Finding metadata and job history, meaning titles, priorities, file locations and captured build and test output, stay with the workspace while it is active and are erased when it is purged. Model-processing logs hold request metadata and token counts only. Encrypted database backups are kept up to 35 days, then rotated out automatically. Tamper-evident security and deletion records live in write-once storage for up to two years. Deleting a workspace is reversible for about thirty days, and purging it is the permanent step, leaving only a deletion receipt.
Trains on customer data
No
Subprocessors disclosed
Yes
DPA available
Yes
GDPR contact

Hosting summary

Hyrax runs entirely in the United States. Code and data are processed and stored on Amazon Web Services in the us-east-1 region, and all model inference runs on Amazon Bedrock inside Hyrax's own AWS account. Each workspace is partitioned at the database level rather than by application logic, so two workspaces auditing the same public repository keep completely separate findings and history. Traffic is encrypted in transit with TLS and data is encrypted at rest with managed keys. The production database is continuously backed up and replicated across several availability zones, with encrypted point-in-time recovery and a tested restore procedure. The sub-processor catalogue names AWS, GitHub, WorkOS, Stripe, PostHog, Linear, Loops.so and Resend, and states what each one receives. Google Ads and Reddit Ads tags are disclosed separately as independent controllers rather than Article 28 sub-processors. The site itself resolves to 76.76.21.21, an anycast address on Amazon's network geolocated in the United States.

Hosting countries
🇺🇸 United States
Hosting regions
North America
Availability

Where Hyrax works

Country-level availability.

Available in

🇺🇸 United States

Not available in

The privacy policy states that the service is intended for, and offered only to, users located in the United States, and that Hyrax does not market, sell or knowingly offer it to individuals located elsewhereCountries and territories under comprehensive US sanctions administered by OFAC, and any party named on the Specially Designated Nationals list, are excluded by the termsThe restriction is contractual rather than technical, as no geographic blocking is documented
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Hyrax.

  • Approval fatigue: a steady stream of verified pull requests can push reviewers into rubber-stamping changes they have not really read
  • The terms state plainly that findings and fixes are advisory only, and are not a security audit, penetration test or compliance certification
  • Source code leaves your infrastructure for the model provider, and the documentation declines to guarantee non-retention on that provider's side
  • Hyrax owns the usage and de-identified data derived from your workspace and uses it for benchmarking, product improvement and model evaluation
  • Delegating architectural judgement to an audit tool can erode a team's own feel for its codebase over time
  • Costs are metered, so a busy workspace with overage enabled can consume credits faster than expected, although a budget cap is available
  • An account left inactive for thirty consecutive days can be closed, on the free plan as well as the paid one
Setup

Setup & Integrations

Technical difficulty

Low. Installing the GitHub App takes about two minutes, and Discovery then profiles the repository on its own in ten to twenty minutes. There is nothing to configure first, no rules to author, no personal access token to paste and no change to the existing CI pipeline. Sign-in is password-free, through GitHub, Google or a one-time email code. A public repository can be added by URL alone, without the App. Only the optional pieces ask more: connecting Linear needs an admin and an API key, and API keys can carry rate, spend, expiry and IP-range limits.

Deployment

Web appAPI

Integrations

GitHub Linear Cursor Claude Code GitHub Copilot
Company

Behind Hyrax

Company name
Hyrax AI, LLC
Founded
10/01/2024
Country of origin
🇺🇸 United States
Headquarters
2811 Ponce de Leon, PH 1, 13th Floor, Coral Gables, Florida 33134
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States
Legal contact

Fundraising

No funding round has been announced for Hyrax AI, LLC itself; the company presents itself as An Iru Company and, in its legal documents, as a subsidiary of Iru, Inc.
The careers page claims the funding and engineering depth of a premier security ecosystem behind the team, without naming an amount
Off-site research, not first-party: Iru, Inc. is Kandji renamed in October 2025, with roughly $289 million raised across seven rounds and a $100 million Series D led by General Catalyst in July 2024

Social

Official links

Resources

All the official URLs gathered for verification and reference.

Compare

Alternatives

Tools that compete with or complement Hyrax.

C CodeRabbitG GreptileQ QodoG GraphiteB BugbotB BazC Claude CodeG GitHub CopilotC CodexS SnykS SonarQubeS SemgrepC CodacyQ QodanaA AikidoC CursorD DevinF Factory AIW WindsurfA Augment CodeP PixeeV v0L LovableB Bolt
FAQ

Frequently asked questions

Which source-control platforms does Hyrax support?
GitHub only at launch. GitLab, Bitbucket and Azure DevOps are not supported. On the ticketing side, Linear is the single integration available, with Jira announced on the roadmap.
Which programming languages does the audit cover?
More than eighteen, including Python, TypeScript, JavaScript, Go, Rust, Java, Kotlin, Ruby, PHP, Swift, C and C++. Autonomous fix execution targets the languages where accuracy is reliable, and coverage expands over time.
Can Hyrax merge its own changes?
No. Every change opens as a pull request on the configured target branch, Hyrax never writes to a production branch, and an engineer approves and merges each one.
What does the thirteen-stage verification cover?
An isolated worktree, baseline tests, the fix agent, a diff-size guard at 20 files or 2,000 lines, test regression, build, auto-format, lint, a cross-project test, a scanner pass over its own diff, a second agent's review, a post-fix audit, and finally the pull request. If any stage fails, nothing is pushed.
What does Hyrax cost?
The free plan costs nothing and carries a $30 starting credit plus $10 of credits a month. The paid plan is $30 per user per month with $30 of credits per seat. Compute for audits, fixes and reviews is metered in credits on top.
Is customer code used to train models?
The site states that Hyrax does not train on customer code, and the terms rule out intentionally using identifiable code to train third-party foundation models. The technical documentation is more cautious and refers to the model provider's own data terms, since inference runs on Amazon Bedrock.
Where is the code processed?
Entirely in the United States, on Amazon Web Services in the us-east-1 region. The working clone is deleted when a job ends, whether it succeeded, failed or was cancelled.
Does Hyrax replace a dependency or container scanner?
No. Dependency scanning, container scanning and infrastructure-as-code scanning stay outside its scope. Hyrax handles source-code security and quality, and positions itself as the remediation layer for what those tools surface.
How long does setup take?
About two minutes to install the GitHub App, then ten to twenty minutes for Discovery to profile the repository. There is nothing to configure and no rules to write beforehand.
Is there an API?
Yes. A REST API with an OpenAPI 3.1 document, an API explorer and an MCP server, all included on both the free and the paid plan, authenticated with workspace API keys.
Conclusion

Should you pick Hyrax?

Hyrax occupies a narrow and clearly stated position: it is not an assistant that helps write new code, but a layer that governs the code already in the repository. That distinction runs through the whole site, from the four workflows to the comparison pages, and it is the fairest way to judge the product. The central promise is procedural rather than magical, resting on thirteen verification stages, a post-fix audit, a second agent reviewing the diff and a human who merges. Hyrax never merges its own work, and says so repeatedly. The scope is deliberately tight. GitHub is the only source-control platform, Linear the only ticketing integration, and dependency, container and infrastructure scanning are explicitly left to other tools. Read that as honesty about the boundary rather than a gap, but Hyrax slots into an existing toolchain rather than replacing it. Two areas deserve a closer look before committing. The compliance posture is still being built: SOC 2 Type II observation only opened in June 2026, ISO 27001 is not being pursued, and the documentation claims GDPR compliance while the privacy policy restricts the service to users located in the United States and never mentions the regulation. The economics are variable by design too, since a seat costs $30 a month but audits and fixes draw on metered compute credits on top, so the real bill follows repository size and activity. Against that, the free plan is unusually generous: the complete product on real repositories, a starting credit, monthly credits and up to a hundred pull-request reviews a month, with no card. For a team already running coding agents and watching its review backlog grow, that is enough to answer the only question that matters: whether the pull requests Hyrax opens are ones they would have merged anyway.