PullFlow
PullFlow is a code-review platform that syncs pull-request conversations, identities and review activity across GitHub, Slack and VS Code, putting human reviewers and AI agents in one thread. The vendor claims teams merge quality PRs 4X faster.
What is PullFlow?
PullFlow is a code-review platform published by Pullflow Inc. (Sunnyvale, California) for teams where humans and AI agents review pull requests side by side. Its founding idea is deliberately modest: rather than replace GitHub or Slack, it synchronises user identities and review activity between them, and into the editor, so nobody has to switch context to keep a pull request moving.
In daily use, a GitHub pull request spawns a Slack thread. Messages written on either side appear on the other, edits included, with Markdown and attachments carried across. Reviewers can act on the pull request without leaving Slack or their IDE: request a review, assign, add a label, approve, close or reopen, either as an explicit command (@Pullflow request review from @User) or in plain English, since 'this looks good to me' is enough to approve. A task dashboard, available in the Slack Home tab and from the VS Code status bar, splits pending work into Mine and Waiting for me and sorts it by age. CI/CD results from GitHub Actions, external pipelines and GitHub Apps are consolidated into one Slack message that evolves as jobs run, with four notification modes set through /pullflow config.
The AI layer has two halves. The @Pullflow agent, described in the documentation as GPT-powered, sits in every pull-request thread for one-to-one or group conversation and quick pull-request actions. Alongside it, third-party review agents such as CodeRabbit, Greptile and GitHub Copilot are connected from an Agents Dashboard, where their output can be hidden, shown or summarised per channel type, summaries being flagged 'Summarized by PullFlow'.
The scope is intentionally narrow. PullFlow states it does not access source code, only pull-request metadata and comments, and holds a SOC 2 Type II report available on request. The IDE extension covers VS Code, Cursor and Antigravity, ships on the Visual Studio Marketplace and is open source on GitHub. Merge statistics track review lead time, review cycles and response time. The vendor claims 4X faster reviews, and one customer reports wait time falling from 14 hours to under four. Tom Preston-Werner, co-founder of GitHub, is an investor.
What it does
- Synchronises pull-request conversations, user identities and review activity across GitHub, Slack and VS Code
- Opens a Slack thread for each pull request, with two-way message sync that also carries edits, Markdown and attachments
- Acts on a pull request without leaving Slack or the IDE: request review, assign, add a label, approve, close, reopen
- Understands natural-language instructions in the thread, so a simple '@Pullflow lgtm' approves a pull request
- Consolidates CI/CD activity from GitHub Actions, external pipelines and GitHub Apps into a single Slack message that updates as jobs run
- Centralises third-party AI review agents and controls their notifications channel by channel: hide, show or summarise
- Tracks merge statistics (review lead time, review cycles, response time) and sends reminders on reviews still pending
When to use PullFlow / When not to
A quick filter to help you decide if PullFlow is the right fit.
When to use PullFlow
- Engineering teams already standardised on GitHub and Slack, since PullFlow does not replace either one but connects the two.
- Distributed, asynchronous teams: one customer testimonial describes a team spread across five continents keeping reviews moving without meetings.
- Open-source projects and small teams, covered by a free-forever plan with unlimited public repositories and up to five users on private repositories.
- Teams running several AI review agents (CodeRabbit, Greptile, GitHub Copilot) that want a single dashboard to connect them and control their notifications channel by channel.
- Larger organisations needing SSO (OpenID Connect, SAML 2.0, SCIM), audit and access control or on-premise deployment, all available on the Enterprise plan.
When not to use PullFlow
- Teams hosting code anywhere other than GitHub: no GitLab, Bitbucket or Azure DevOps support is mentioned on any page of the site.
- Teams that do not use Slack: sign-up itself runs through 'Sign up with Slack' and the Slack bot is the pivot of the whole product.
- Developers who need a public API to build on: the site publishes no API documentation and the docs tree contains no API section.
- Users of IDEs outside the VS Code family: the extension covers VS Code, Cursor and Antigravity only, with no JetBrains support mentioned.
- Solo developers working outside a collaborative review loop, and anyone expecting a mobile companion: the product is built around the pull-request thread and there is no iOS or Android app.
How to use PullFlow
A typical end-to-end flow, from setup to results.
- Go to app.pullflow.com and sign in with your Slack account.
- Authorise GitHub access when the prompt appears.
- Line up an admin of the GitHub organisation: those rights are required to configure repository connections, whereas Slack admin rights are not.
- Choose or create the Slack channel that will receive pull-request updates.
- Invite the bot into that channel with the command /invite @Pullflow.
- Link the GitHub repositories you want connected; for a monorepo, several channels can be attached to a single repository.
- Open a test pull request, check that the Slack thread is created, then post a message on both sides to confirm two-way synchronisation.
- Work from Slack with commands such as @Pullflow request review from @John, @Pullflow assign to @User, @Pullflow add label hold-merge, @Pullflow approve, @Pullflow close or @Pullflow reopen, or simply write in plain English.
- Open the dashboard from the Slack app's Home tab, or press Cmd+T on Mac and Ctrl+Shift+T on Windows, then type '@Pullflow'.
- Install the extension for VS Code, Cursor or Antigravity, open the quick-pick view from the status bar (default shortcut Cmd+Shift+, on Mac), and tune CI/CD notifications with /pullflow config, globally or per channel.
Pros & Cons
Pros
- Removes the context switching between GitHub, Slack and the IDE: one pull-request conversation, three surfaces, edits carried across
- Cuts notification noise, according to a customer testimonial stating that PullFlow 'has dramatically reduced our notification noise' and that reviewers are now notified only on pull requests requiring their attention
- Genuinely generous free plan: unlimited public repositories, unlimited private repositories, five users on private repositories, and free forever for open source
- Low paid entry point at USD 5 per user per month, with 30% off on annual billing and a free trial that does not require a credit card
- Careful security posture for a company of this size: SOC 2 Type II with independent audit, no source-code access requested, and a permission scope that stays restricted and revocable
- Explicit commitment in the privacy policy's AI Policy not to train AI models on customer data or share it with third parties for that purpose
- Third-party review agents driven from a single dashboard, and an IDE extension whose source code is open on GitHub
Cons
- Hard dependency on both GitHub and Slack: no other code forge and no other messaging platform is mentioned anywhere on the site
- No public API and no API documentation, the full documentation tree containing no API section
- IDE coverage limited to the VS Code family (VS Code, Cursor, Antigravity), with no JetBrains support and no mobile application at all
- Setup requires an admin of the GitHub organisation, so a single developer cannot roll the tool out alone
- The free plan caps private-repository usage at five users
- SSO, advanced audit, on-premise deployment, guest users and custom agents are reserved for the Enterprise plan, whose price is not published
- No support email address is published, the free plan relies on community support only, and the support.pullflow.com subdomain cited in the documentation does not resolve
Pricing & Plans
PullFlow operates on a freemium basis. A Free plan is available at no cost and is presented by the vendor as free forever, covering open-source projects and up to five users on private repositories. The lowest paid entry point is the Team plan at USD 5.00 per user per month, which is the rate displayed by default on the pricing page and corresponds to annual billing, presented as 30% below the monthly rate. A free trial is offered without a credit card. The Enterprise plan is quoted on request and no public price is published for it.
- unlimited public repositories
- unlimited public users
- unlimited private repositories
- up to 5 users on private repositories
- community support.
- everything in Free plus unlimited paid users
- unlimited repositories
- the standard feature set
- Basic Audit and email support.
- everything in Team plus private-cloud and on-premise deployment
- audit and access control
- SSO through OpenID Connect
- SAML 2.0 and SCIM
- custom agents
- guest users outside Slack
- and email plus chat support.
- GitHub
- Slack and VS Code synchronisation
- GitHub Actions
- draft pull-request handling
- CI/CD and check runs
- external CI/CD
- cross-platform Markdown and attachments
- pull-request overview
Data, GDPR & hosting
A consolidated view of how PullFlow handles your data.
GDPR overview
The privacy policy, effective 5 September 2021 and last updated 22 January 2024, carries a dedicated section titled 'Additional Disclosures for General Data Protection Regulation (GDPR) Compliance (EU)'. PullFlow declares itself a Data Controller for the personal information users provide, and names four legal bases: consent, performance of a contract or transaction, legitimate interests and legal obligation. Parental consent is required below the age of 16. Transfers outside the EEA rely on standard contractual clauses approved by the European Commission, binding corporate rules or other legally accepted means. Rights listed include access, rectification, restriction, objection, portability in CSV or machine-readable format, erasure, non-discrimination, breach notification and complaint to a supervisory authority, all exercised through privacy@pullflow.com. Two gaps: no Article 27 EU representative is designated and no DPO is named. Separate sections address the Australian Privacy Act and California (CCPA, Shine the Light; Do Not Track signals are not honoured).
Who owns the data?
Under the Terms of Use dated 12 July 2021, users keep their intellectual-property ownership over the content they submit. PullFlow states it will never claim ownership, but requires a non-exclusive, royalty-free, transferable, sub-licensable, worldwide licence to use it. That licence ends when the user deletes the content or the account, except where commercial or sponsored use is already under way. Operationally the scope stays narrow: PullFlow says it neither has nor needs source-code access, requesting only pull-request metadata and comments, while Slack access is limited to channels where the bot is invited and to threads attached to a pull request. Customers choose the authorised repositories and can revoke access from GitHub at any time.
Reuse rights
The privacy policy, effective 5 September 2021 and last updated 22 January 2024, separates information users provide voluntarily from information collected automatically. The automatic set covers log data (IP address, browser type and version, pages visited, date and duration, technical error details) and device data (device type, operating system); volunteered data may include name, email address, social profiles, telephone number and postal address. PullFlow reserves the right to combine the two and to enrich them with data from trusted third-party sources. Stated purposes are delivery of core functionality, personalisation, communication, advertising and marketing, access to the site and related applications, legal obligations and disputes, security and fraud prevention, and technical evaluation and improvement. Disclosure is possible to service providers, related entities, authorities, partners, and to an acquirer in the event of a sale. One point is stated explicitly in the AI Policy: PullFlow does not use customer data to train AI models, nor share it with third parties for that purpose.
Data retention & training
Hosting summary
PullFlow's privacy policy states that the personal information collected is stored and/or processed in the United States, or wherever the company, its partners, affiliates and third-party providers maintain facilities. Amazon Web Services is named as the hosting provider; the other declared third parties are PostHog for analytics, SendGrid for email and OpenAI for the GPT capability behind the agent. No European or other regional hosting option is offered or mentioned, so the United States is the only hosting jurisdiction on record. Transfers out of the EEA are covered contractually, through standard contractual clauses approved by the European Commission, binding corporate rules or other legally accepted mechanisms. On the security side, PullFlow claims SOC 2 Type II certification covering security, availability and confidentiality controls, with the report available on request. One caveat on infrastructure: the site resolves to 76.76.21.21, an anycast CDN node geolocated in the United States, which indicates a point of presence rather than the location of an origin server.
Things to keep in mind
Risks and trade-offs to weigh before adopting PullFlow.
- The Terms of Use and the Acceptable Use Policy are both dated 12 July 2021 and have not been revised since, while the product has evolved considerably in the meantime.
- No DPA is published or mentioned anywhere on the site, and no Article 27 EU representative is designated, despite a detailed GDPR section in the privacy policy that is effective 5 September 2021 and updated 22 January 2024.
- Data is hosted in the United States only, with no European residency option, and OpenAI figures among the declared third-party providers for the agent's GPT capability, adding one more processor in the chain.
- Support is thin on paper: no support email address is published (privacy@pullflow.com is the site's only address), the free plan gets community support only, and the support.pullflow.com subdomain cited in the official documentation does not resolve.
- Installation requires an admin of the GitHub organisation, which can block adoption by an individual developer and creates a single point of dependency inside the team.
- The performance figures put forward (4X faster reviews, 100% fewer incidents, 75% less review time) are vendor claims and customer testimonials, not independent measurements, and the Enterprise price is not public, so budgeting at scale requires a sales conversation.
- The per-channel option to summarise AI agents' notifications, flagged 'Summarized by PullFlow', keeps threads readable but means a reviewer can end up approving on a condensed version rather than on an agent's full findings; the convenience of approving from Slack in one word deserves the same caution.
Setup & Integrations
Technical difficulty
Low for the end user, subject to one organisational condition. Setup is three documented steps with no server work on the Free and Team plans: sign in at app.pullflow.com with Slack, authorise GitHub, pick or create the Slack channel, invite the bot with /invite @Pullflow, then link repositories and open a test pull request. The blocker is permissions: admin rights on the GitHub organisation are required to connect repositories, while Slack admin rights are not. Non-admin members can join an existing configuration. The IDE extension installs from the Visual Studio Marketplace. On-premise and private-cloud deployment is Enterprise-only.
Deployment
Integrations
Behind PullFlow
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
How does PullFlow connect to our existing GitHub and Slack accounts?
Can we choose which GitHub repositories PullFlow can access?
Does PullFlow have access to our source code?
Does PullFlow read all of our Slack messages?
Can any member of a Slack workspace sign up on their own?
Is PullFlow SOC 2 compliant?
Is there a free plan, and what does the paid plan cost?
Which IDEs does PullFlow support?
Is our data used to train AI models, and where is it hosted?
Does PullFlow offer a public API?
Should you pick PullFlow?
PullFlow is unapologetically a niche tool: it replaces neither GitHub nor Slack, it wires them together. That framing decides who should look at it. If your team already lives in both, the value lands immediately, because the pull request stops being a tab someone forgets to open and becomes a conversation happening where the team already is. If either tool is missing, there is nothing here, since no other forge and no other messaging platform is supported.
Its current positioning is on orchestrating AI review agents rather than writing reviews itself: one place to connect CodeRabbit, Greptile or Copilot and decide how loudly each one speaks. The company backs that stance with its own research on 40.3 million pull requests, and with a security posture more careful than most tools of this size: SOC 2 Type II, no source-code access, and an explicit commitment not to train models on customer data.
Commercially it is generous. The free tier is genuinely usable for an open-source project or a five-person team, and USD 5 per user per month is low for developer tooling. Enterprise pricing, however, is not published, and SSO, advanced audit and on-premise deployment all sit behind it.
The reservations are administrative rather than technical. The Terms of Use and Acceptable Use Policy still carry a July 2021 date while the product has moved on considerably. The privacy policy is fresher, effective September 2021 and updated January 2024, but no DPA is published and no Article 27 EU representative is designated, which will matter to European buyers. Data is hosted in the United States only. Support publishes no email address, and the support subdomain cited in the documentation does not resolve. Worth trialling on the free plan, with legal review if you procure from the EU.
- Choosing a selection results in a full page refresh.
- Opens in a new window.