Kodus
AI PR Review · AGPL-3.0
Open-source AI code review built to run where the organization controls: self-hosted or cloud, models under your keys, org-wide Kody Rules.
Filtered view · Verified 2026-08-11
For teams in regulated industries, or with a security review that says source code does not leave the network, deployment is the first filter — not features. 8 of 27 tools here document full self-hosting; 10 more will sell it to you on an enterprise contract.
Watch the second half of the question too: self-hosting the reviewer does not move the model inside your boundary. Check the model-control row on each profile.
No enterprise contract required to run it yourself.
| # | Tool | Coverage | Self-hosting | Licence | Free tier | From |
|---|---|---|---|---|---|---|
| =1 | Kodus AI PR Review | 6.5/9 Coverage score 6.5 out of 9 | Self-hostable | Open source | Limited free tier | $10/dev/mo |
| =1 | Entelligence AI AI PR Review | 6.5/9 Coverage score 6.5 out of 9 | Self-hostable | Proprietary | Unknown | See pricing |
| =3 | Semgrep Security | 4.5/9 Coverage score 4.5 out of 9 | Self-hostable | Open source | Limited free tier | $30/contributor/mo |
| =3 | Tabnine AI PR Review | 4.5/9 Coverage score 4.5 out of 9 | Self-hostable | Proprietary | No free tier | $39/user/mo |
| 5 | SonarQube Code Quality | 4/9 Coverage score 4 out of 9 | Self-hostable | Open source | Limited free tier | $34/mo |
| 6 | Qodana Static Analysis | 3.5/9 Coverage score 3.5 out of 9 | Self-hostable | Proprietary | Limited free tier | $5/contributor/mo |
| 7 | OpenReview AI PR Review | 3/9 Coverage score 3 out of 9 | Self-hostable | Proprietary | Free tier | Free (self-run) |
| 8 | PR-Agent AI PR Review | 2.5/9 Coverage score 2.5 out of 9 | Self-hostable | Open source | Free tier | Free (MIT) |
AI PR Review · AGPL-3.0
Open-source AI code review built to run where the organization controls: self-hosted or cloud, models under your keys, org-wide Kody Rules.
AI PR Review · Proprietary
Reviews PRs on GitHub, GitLab, and Bitbucket with codebase and team context, plus CLI pre-PR review and engineering metrics.
Security · LGPL-2.1
Open-source static analysis engine with a commercial AppSec Platform adding cross-file analysis and an AI assistant for triage.
AI PR Review · Proprietary
Enterprise AI dev platform whose Code Review Agent checks PRs against plain-language team rules on GitHub, GitLab, and Bitbucket.
Code Quality · LGPL-3.0
Deterministic static analysis platform (Server and Cloud) with PR decoration and LLM-generated AI CodeFix suggestions.
Static Analysis · Proprietary
JetBrains' static analysis for CI, running IDE inspections in pipelines with quality gates, baselines, and cloud reports.
AI PR Review · Proprietary
Vercel Labs' self-hosted GitHub review bot: mention @openreview for Claude-powered inline suggestions; dormant beta since March 2026.
AI PR Review · MIT
Community-maintained, MIT-licensed PR reviewer with /review, /describe, and /improve commands, self-hosted with your own model keys.
Available, but priced and gated — expect a sales cycle and, in some cases, a seat minimum.
Private Mode (data-plane pod in your AWS EKS) on Pro and Enterprise; full VPC deployment is an Enterprise capability.
6.5/9On-prem/VPC deployment on Enterprise; also connects to self-hosted SCMs (GHES, GitLab self-managed, Bitbucket DC).
6.5/9Self-hosted deployment on custom-priced Enterprise; docs cite availability for orgs with 500+ seats, connecting to your own LLM provider.
6/9Self-hosted deployment on custom-priced Enterprise tier, alongside SOC 2 Type II and SSO/SAML.
4.5/9Enterprise offers single-tenant SaaS, on-prem, and air-gapped deployment at custom pricing.
3.5/9SaaS platform; Snyk Broker connects private SCMs and an enterprise Local Code Engine runs analysis in your network (with feature limits).
3/9SaaS-first; Pro adds on-premises/local scanning and Enterprise offers on-premises deployment options.
2.5/9Enterprise adds self-hosted and air-gapped deployment plus BYOK (Anthropic, OpenAI, or Gemini keys).
1.5/98 of the 27 tools in this directory document self-hosting on a standard plan: Kodus, Entelligence AI, Semgrep, Tabnine, SonarQube, Qodana, OpenReview, PR-Agent. A further 10 offer it only on a custom enterprise contract.
No, and conflating them is the most common mistake in this evaluation. A proprietary tool can ship a self-hosted deployment you cannot read the source of, and an open-source tool can still route your code through a vendor API. Check the licence row and the deployment row separately.
Only if the model runs somewhere you control too. Self-hosting the reviewer moves the orchestration into your network, but the model call still goes wherever the tool points it. Look for BYOK plus support for a local or private endpoint if the requirement is that code never leaves your boundary.
Usually your own infrastructure plus your own model spend, which is why the total bill can be lower or much higher than a seat price depending on review volume. Tools that meter model usage separately are marked in the pricing column of each profile.
Open source matters to you too?
Different filter, different list — self-hostable and readable are not the same thing.