cubic
cubic is an AI code review platform for GitHub that flags hard-to-find bugs in pull requests, scans entire codebases overnight, writes PR summaries and applies one-click fixes through background agents. A permanent free tier is available.
What is cubic?
cubic is an AI code review platform built around GitHub. Once its GitHub App is installed on a repository or an entire organisation, every new pull request is reviewed automatically: the tool posts inline comments on logic errors, style inconsistencies, security vulnerabilities and accumulating technical debt, and it resolves its own threads once the feedback has been addressed. Reviews are incremental, so pushing new commits triggers a pass on the change alone rather than a repetition of remarks already handled. Above two hundred files in a single pull request, cubic reviews the two hundred it ranks highest.
The platform works on three surfaces. On GitHub it behaves like a reviewer. In the editor it plugs into Cursor, Claude Code, VS Code, Codex or Gemini CLI. Locally, a CLI installed with a single shell command runs a faster, deliberately shallower pass on uncommitted work before anything is pushed. A desktop application is also published for macOS, Windows and Linux.
Beyond reviewing, cubic acts. Background agents turn a flagged issue into a commit on the pull request branch or into a separate fix pull request, generated by Claude Code inside an isolated sandbox; nothing is ever pushed straight to a protected branch. Codebase scans send thousands of agents through the whole repository at night to surface bugs and vulnerabilities, then triage the findings, notify owners, open tickets and propose fixes. Ultrareview spends a longer pass on the most capable models when a migration or a refactor is risky.
The tool is meant to converge on a team's habits. It identifies senior engineers and learns from their pull request comment history, custom agents encode standards in plain English, and context is pulled from Linear, Jira, Notion, Confluence and Asana. An AI wiki indexes the repository and answers architecture questions in natural language through an MCP server, while analytics track AI coding usage and delivery effectiveness through a documented API.
cubic is language-agnostic, covering JavaScript, TypeScript, Python, Go, Ruby, PHP, Java, C#, C and C++, Rust, Kotlin and Swift. It is published by MRGE, Inc. and counts n8n, Cal.com, Better Auth, Resend and Granola among its named customers.
What it does
- Review every GitHub pull request automatically and comment inline on bugs, security issues and technical debt
- Fix a flagged issue in one click through a background agent running in an isolated sandbox
- Scan the whole codebase overnight with thousands of agents, then triage findings and open fix pull requests
- Generate pull request descriptions that explain what changed and what it affects
- Enforce team coding standards written as custom agents in plain English
- Build and maintain a searchable AI wiki of the repository, queryable in natural language
- Review uncommitted work locally from the CLI or from the IDE before anything is pushed
When to use cubic / When not to
A quick filter to help you decide if cubic is the right fit.
When to use cubic
- Engineering teams shipping a high volume of pull requests on GitHub
- Maintainers of open source projects, since public repositories are reviewed free of charge
- Teams working on large, long-lived codebases where bugs hide between files rather than inside one
- Security-minded teams that want nightly vulnerability scans on top of pull request review
- Small teams without a senior reviewer always on hand, since cubic learns from senior comment history
When not to use cubic
- Teams hosting their code on GitLab or Bitbucket, neither of which cubic supports
- Organisations that cannot let source code transit through third-party AI providers such as OpenAI or Anthropic
- Buyers who require SOC 2 Type 2 or ISO 27001, since only SOC 2 Type 1 is claimed
- Anyone working outside a code repository: cubic does nothing else
- Users under 18, who are excluded by the terms of service
How to use cubic
A typical end-to-end flow, from setup to results.
- Sign up on the cubic site and start the seven-day trial; no credit card is requested
- Install the cubic GitHub App on the repositories, or the whole organisation, you want covered
- Open a pull request: the review starts on its own, with no further configuration
- For a pull request opened before installation, comment @cubic-dev-ai review this PR
- Read the inline comments, reply to them, and request an Ultrareview when a change is risky
- Click Fix with cubic, or tag @cubic, to let a background agent write and push the correction
- Write custom agents in plain English to encode the standards your team actually enforces
- Tune the behaviour through a cubic.yaml file committed to the repository
- Connect Linear, Jira, Notion, Confluence or Asana for context, and Slack or email for notifications
- Install the CLI or connect cubic to your IDE to review changes before you push them
Pros & Cons
Pros
- A permanent free tier of twenty AI reviews a month, and unlimited free use on public repositories
- Seven-day trial with no credit card, and an installation the vendor describes as two clicks
- Fixes are applied rather than merely suggested: background agents commit them for review
- Third-party benchmark placings and named customers such as n8n, Cal.com, Better Auth and Resend can be checked
- Learns from the pull request comment history of your senior engineers, which is meant to cut false positives
- Documented security posture: TLS 1.2 or above in transit, AES-256 at rest, a review sandbox with no network egress, published GitHub scopes and SOC 2 Type 1
- Fifty per cent discount for nonprofits and schools, twenty per cent for annual commitment, cancellation at any time
Cons
- GitHub only: GitLab and Bitbucket are explicitly unsupported
- The homepage promise that cubic never trains AI on your code sits awkwardly beside clause 7.1 of the terms, which grants cubic a licence to train and fine-tune on your content
- The publisher discloses no postal address, no legal notice page and no contact page, only an email
- SOC 2 Type 1 only, and no hosting country or region is named anywhere
- A data processing agreement is reserved for the Enterprise plan
- No self-service way to opt out of training; the nearest option is switching AI features off entirely, on request
- Per-developer seat billing, with overage charged at twenty dollars per ten thousand extra reviewed lines
Pricing & Plans
cubic offers a permanent free plan: the Starter tier costs nothing and includes twenty AI reviews per month with full access to the platform, and public repositories are reviewed free of charge with no application to file. The cheapest paid tier is Team, at USD 30 per developer per month when billed annually in advance, or USD 40 per developer per month on a monthly commitment. Pro follows at USD 79 per developer per month billed annually, or USD 99 monthly, and Enterprise is quoted on request. A seven-day free trial requires no credit card.
- twenty pull request reviews a month
- up to five custom agents
- automatic PR descriptions
- custom context
- connections to Jira
- Linear
- Asana and Notion
- and unlimited AI wikis
- everything in the free plan plus AI code reviews
- 40
- 000 reviewed lines per developer
- up to five custom agents
- background agent fixes
- the cubic CLI
- Ultrareview
- weekly wiki updates and simple analytics
- everything in Team plus premium support
- 80
- 000 reviewed lines per developer
- faster pull request and CLI reviews
- up to ten custom agents
- coding agent fixes
- Confluence integration
- nightly scans on three repositories
- everything in Pro plus additional custom agents and codebase scans
- premium support
- a custom MSA and DPA
- custom payment terms
- SSO and SAML with GitHub OAuth
- GitHub Enterprise support
- exportable compliance audits and the option to bring your own API keys
Data, GDPR & hosting
A consolidated view of how cubic handles your data.
GDPR overview
cubic never claims GDPR compliance in so many words, but its privacy policy carries a dedicated European Union section. It sets out the legal bases relied upon, namely consent, performance of a contract, legal obligation, public interest and legitimate interest, and enumerates the rights available to data subjects: withdrawal of consent, objection, access, rectification, restriction, erasure, portability and the right to lodge a complaint. Requests go to contact@cubic.dev and are answered free of charge within one month. Beyond that the implementation is thin. No data protection officer is named, no Article 27 representative is designated, no transfer mechanism such as standard contractual clauses is mentioned, and no hosting country is disclosed. A data processing agreement exists only in the Enterprise plan, negotiated case by case.
Who owns the data?
Under the terms of service you keep every right in the content you submit and in the code the service generates from your prompts. cubic nonetheless grants itself a worldwide, royalty-free licence to use, process, copy, analyse and create derivative works from your content, pull request data, review results, prompts and metadata, in order to operate and to train, fine-tune and improve its own products. It may exercise those rights through its affiliates, service providers, subprocessors and assignees. It states that it does not sell customer code and does not let third-party AI providers train their own models on it. A separate written agreement, such as an enterprise contract, can override all of this.
Reuse rights
You may reuse whatever the service produces without asking permission: the terms state that you retain all right, title and interest in the code generated from your prompts, as well as in the content you submit. Nothing requires attribution or a licence back for that reuse. Three limits apply. The service and its AI outputs are supplied as is, with no warranty that any particular result will be obtained, so verification remains your responsibility. cubic's own intellectual property, meaning its brand, interface and software, is excluded, and reverse engineering, redistribution of service material and circumvention of security controls are all prohibited. Finally, liability is capped at the greater of twelve months of fees paid or one hundred US dollars.
Data retention & training
Hosting summary
No hosting country or region is disclosed. The privacy policy states only that data is processed at the owner's operating offices and wherever the parties involved in the processing are located, and that a transfer abroad may occur depending on where the user is; no transfer mechanism such as standard contractual clauses is named. What is documented is the pipeline rather than the geography. Reviews run in an isolated container with no network egress, only the code snippets needed for the requested analysis leave it, and the named AI subprocessors are OpenAI and Anthropic. Data is encrypted in transit with TLS 1.2 or above and at rest with AES-256, including database records and object storage. The publisher is a Delaware corporation and the terms are governed by Californian law, which points to the United States without confirming where anything is actually stored. The domain resolves to a United States anycast node, which is a content delivery address and says nothing about storage.
Things to keep in mind
Risks and trade-offs to weigh before adopting cubic.
- The vendor's own documents disagree: marketing promises that cubic never stores your code or trains AI on it, while clause 7.1 of the terms grants a licence to train and fine-tune on your content, prompts and metadata
- Source code is sent to third-party AI providers by design, even though those providers are contractually barred from training on it
- The GitHub App holds write access to code, pull requests, workflows and Actions, a broad blast radius that branch protection rules only partly contain
- Background agents push AI-generated code: a plausible but wrong fix can slip through if the pull request is approved without human reading
- Auto-approval hands the approval decision to a model on changes it judges clean, which can quietly remove human review from part of the flow
- Habituation erodes vigilance: a team that trusts the AI reviewer may stop reading carefully, including on large pull requests where only the top two hundred files are examined
- On termination cubic has no obligation to keep or return anything, liability is capped at one hundred US dollars or twelve months of fees, and disputes go to individual arbitration under Californian law
Setup & Integrations
Technical difficulty
Very low. Three steps: create an account, install the cubic GitHub App on the repositories or the organisation you choose, then open a pull request, at which point reviews start with no further configuration. The only prerequisite is the right to install a GitHub App on the target repository, which usually means an organisation administrator. Everything else is optional: a cubic.yaml file, custom agents written in plain English, connections to Linear, Jira, Notion, Confluence or Asana, a CLI installed with a single shell command, or the IDE integration. Seat assignment is reserved to administrators.
Deployment
Integrations
Supported languages
Behind cubic
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
Which code hosting platforms does cubic support?
Which programming languages does cubic review?
Is there a free plan, and what does it include?
How much does the first paid tier cost?
What counts as a reviewed line?
Is my code used to train AI models?
What permissions does the cubic GitHub App request, and can it push to main?
What security certifications does cubic hold?
Are there discounts or special offers?
Is there a mobile app or an API?
Should you pick cubic?
cubic is a narrow tool that does its one job unusually well. It reviews pull requests on GitHub, and it has extended that base into continuous scanning of the whole repository, one-click fixes by background agents, an AI wiki and delivery analytics. For a company that went through Y Combinator in 2025, the product surface is already broad, and the customer names it displays are checkable and credible within the developer tooling world. Two things make it easy to try: the Starter tier is permanently free, and public repositories are reviewed at no cost automatically, so an open source maintainer can judge the quality of the reviews before any conversation about money.
The reservations are real and they are mostly about disclosure rather than engineering. The most serious is a contradiction inside the vendor's own documents: the homepage states that cubic never stores your code or trains AI on it, while clause 7.1 of the terms grants cubic a broad licence to train and fine-tune on your content, prompts and metadata. Only the commitment binding third-party model providers is unambiguous. Around that sit smaller gaps: no postal address and no legal notice page, SOC 2 Type 1 rather than Type 2, no hosting country named, a data processing agreement reserved for Enterprise, and no self-service way to exclude your data from training.
The practical verdict is straightforward. If your code lives on GitHub and your team is comfortable with source code passing through OpenAI and Anthropic, cubic is worth a trial that costs nothing. If your legal or security review is strict, ask the vendor to reconcile clause 7.1 with its marketing in writing before signing anything.
- Choosing a selection results in a full page refresh.
- Opens in a new window.