A code scan reports a hardcoded password on line 47 of a configuration file.
The finding is correct, the rule explains the safe pattern, and the ticket still sits for weeks — because someone has to open the file, work out how this codebase reads its configuration, make the change without breaking the import next to it, and push it. Multiply that by every finding in the scan and the backlog is not a knowledge problem. It is a typing problem nobody has time for.
The cost of a backlog
A finding that is known but not fixed is still exposed. Every week it waits is a week an attacker can use it — and an auditor can ask why.
The mechanism, not the marketing
- 1
Fixing runs on demand against a completed code scan. You choose which severities to include, and findings your team has already marked as false positives are left out.
- 2
The engine makes a shallow clone of the scanned repository using a Git token passed with that request only. The token is never written to the database or the logs, and is removed from the clone's configuration after the push.
- 3
Findings are grouped by file. For each file, a large language model receives the whole file, every finding in it, and the rule's guidance — what the issue is, how to fix it, and a safe example in the same language where the rule library has one. If a rule has no guidance on record, the scanner's own message is used instead.
- 4
The model is instructed to fix only the listed issues and to keep the rest of the file — indentation, names, imports and style — exactly as it was. It returns the complete corrected file, so several findings in one file are fixed in one coherent pass rather than as separate line edits.
- 5
Corrected files are written back only if they already exist inside the repository, then committed to a new fix branch and pushed. Nothing is merged and nothing is deployed: your normal pull-request review and CI run before any of it reaches your main branch.
Specific outputs, measurable outcomes
Questions we get a lot
Ready to see AI Code Fix on your code?
We will run a scan and a fix on a repository you choose, and walk your team through the branch it produces.