Merge with
confidence.

AI code review that catches bugs, security issues and regressions — right on your Pull Requests. Works with GitHub, GitLab, Bitbucket and Azure DevOps.

Free plan · No credit card

See a real review before you install anything

Paste any public GitHub PR URL and read the full review, usually in a minute or two — no app installed, no repository access, nothing posted to the PR.

acme/web — PR #218: profile header fixes

src/profile/header.tsx

17 const user = await fetchProfile(id);
18+ const label = user.name.toUpperCase();
pulloramajorbugbot

Possible undefined access on user.name

user.name can be undefined when the profile is incomplete, so .toUpperCase() throws.

- const label = user.name.toUpperCase();+ const label = (user.name ?? "").toUpperCase();
or, posted as you
Aalex-dev commented just now

I think user.name can be undefined when the profile is incomplete — worth guarding before the .toUpperCase() call.

Same finding, two voices — a structured bot review, or posted from your own account.

Review policy lives in your repoA committed .ai-review.yml sets the mode, thresholds, categories, ignore paths and your team's own rules.Read the reference →
Works withGitHubGitLabBitbucketAzure DevOps

How it works

From push to reviewed in minutes

01

Connect your git provider

GitHub and GitLab connect with one authorisation; Bitbucket needs your workspace name and Azure DevOps an access token. Then pick the repositories to review.

02

Open a Pull Request

Pullora fetches the diff, builds token-budgeted context from your codebase and runs the review pipeline.

03

Get inline findings

Validated, deduplicated findings land as inline comments with severity, confidence and a suggested fix.

The pipeline

Every finding earns its place

A review isn't one model call — it's a pipeline. Anything the AI can't prove against your diff is discarded before it ever reaches your PR.

PR opened

Webhook or pasted URL

Context built

Diff + full files + your docs

AI review

Multi-pass, adversarial on Deep

Validation

Evidence check · dedupe · confidence

Posted to your PR

Inline findings + summary

Hallucinated or unprovable findings are dropped at validation—not posted to your PR.

Features

A reviewer that actually reads your code

Not a linter with a chat wrapper — a full review pipeline with validation, dedupe and confidence gating.

Try it on any public PR — no installation

Paste any public GitHub PR URL and get a full dry-run review, usually in a minute or two. Nothing is posted; see the quality before you connect anything.

Automatic PR reviews

Every new or updated Pull Request is reviewed the moment it lands — no command to run, no CI step to wire up.

PR-URL reviews

Paste any authorized PR URL into the dashboard for an on-demand review, no webhook required.

Incremental re-reviews

New commits only re-review what changed since the last reviewed SHA — no duplicate comments, no wasted units.

Post comments as yourself

Pro teams can publish reviews from their own account in a natural, conversational voice instead of a formatted bot report — useful when you review on behalf of your team. You stay the author and are accountable for what is posted, so check your project's AI-disclosure rules before turning it on.

Your docs guide the review

Point Pullora at your conventions and architecture docs. Each version is condensed once and cached, so you never pay to re-read them — the distilled rules then apply on every PR.

Prompt-injection hardened

Repository content is untrusted data, never instructions. Findings are schema-validated before publishing.

Multi-model engine

Provider-agnostic AI layer picks the right model for the job — and keeps working when one provider is down.

Per-review control

Override severity, confidence, categories, ignore patterns and context docs for a single run — defaults load from your repo settings.

What you get

What Pullora does — and what it doesn't

No comparison table. Here is the product as it actually is today, so you can decide in two minutes whether it fits.

Try it on any public PR, no install

Paste a GitHub PR URL and read a full review, usually in a minute or two. No app installed, no repository access granted, nothing posted.

Dry-run before anything is posted

Every review can run in preview. You see the findings in the dashboard and choose which ones reach the pull request.

GitHub, GitLab, Bitbucket and Azure DevOps

One review engine behind all four — the same pipeline, findings and controls whichever you use, not a GitHub-first tool with the rest bolted on.

Findings checked against the diff

Every finding must quote your diff verbatim and anchor to a real changed line, then clear a confidence threshold you set. Anything failing either check is discarded rather than posted — and the review log shows exactly how many were dropped and why.

Selectable depth, metered by PR size

Quick, Standard or Deep per review. You see the estimate before running and the exact unit cost afterwards.

Compare the modes →

Policy lives in your repo — and can't weaken security

A committed .ai-review.yml sets the mode, thresholds, categories, ignore paths and your team's own rules. Settings layer in a documented order — system defaults → org rules → .ai-review.yml → dashboard → a one-time instruction — and the last of those can only change the mode and add guidance. It can never raise thresholds, add ignore paths, or switch security checks off.

Read the config reference →

A good fit if

  • You want every pull request reviewed without paying per engineer — units are pooled across the workspace, not billed per seat
  • Your code lives on GitHub, GitLab, Bitbucket or Azure DevOps — all four get the same review engine
  • You want to see the findings, and decide what gets posted, before anything reaches the pull request

Not yet, if

  • You need review inside your IDE or CLI — Pullora reviews pull requests, not keystrokes
  • You want the tool to open branches and push fixes itself
  • Procurement requires SOC 2, SSO/SAML, self-hosting or BYOK

Security

Built like your code matters

Because it does. Pullora treats your source as sensitive data end to end.

Least-privilege GitHub App

Scoped installation tokens per repository — no personal access tokens, no standing broad access.

Encrypted credentials

Provider credentials are encrypted at rest with AES-256-GCM and never written to logs.

No training on your code

AI providers are used under no-training API terms. Your code produces your review, nothing else.

Verified webhooks

Every webhook is signature-verified and idempotent before any work is enqueued.

Read the full security overview →

How pricing works

You pay for review size, not review count

A one-line typo fix and a 4,000-line refactor cost very different amounts to review. Units make that honest instead of averaging it into a flat price.

Every plan includes monthly units

Free gives you 10 units a month, Pro 150, Team 500. Units are spent per review, so a month of small PRs goes much further than the headline number suggests.

Cost scales with the PR

Quick reviews start at 0.5 units, Standard at 1 and Deep at 2 — rising with the size of the diff. We show the estimate before you run a review, and the exact figure after.

Top up any time

Run out mid-month and you can buy a top-up pack without changing plan — from $0.20 per unit in the largest pack. Purchased units never expire: unlike your monthly allowance, they roll over for as long as you need them.

No surprise bills: when your balance runs out, reviews pause rather than charging you automatically.

Pricing

Start free, scale when you do

From solo side projects to engineering orgs. Cancel anytime.

Free

$0/mo

10 review units / mo · 1 repo

Most Popular

Pro

$19/mo

150 review units / mo · unlimited repos · Deep mode

Team

$49/mo

5 seats · 500 pooled review units / mo

See all plans →

FAQ

Frequently asked questions

Connect the Pullora GitHub App to your repositories. When a PR opens or updates, Pullora fetches the diff, builds context from your codebase, runs an AI review, validates every finding against the actual diff, and posts inline comments plus a summary — usually within a couple of minutes.

Catch it before it ships.

Set up Pullora in two minutes. Your next Pull Request gets reviewed automatically.