Onam Security
AI Code Fix

Who actually rewrites the code once the scanner has flagged it?

The scanner says what is wrong. AI Code Fix writes the corrected file and hands it to you on a branch.

AI Code Fix takes the findings from a completed code scan, rewrites each affected source file with a large language model, and commits the result to a separate branch for your team to review, test and merge.

1 pass
per file
Branch
never your main
None
auto-merges
Never
Git token stored
Why this matters

A code scan reports a hardcoded password on line 47 of a configuration file.

The finding is correct, the rule explains the safe pattern, and the ticket still sits for weeks — because someone has to open the file, work out how this codebase reads its configuration, make the change without breaking the import next to it, and push it. Multiply that by every finding in the scan and the backlog is not a knowledge problem. It is a typing problem nobody has time for.

The cost of a backlog

A finding that is known but not fixed is still exposed. Every week it waits is a week an attacker can use it — and an auditor can ask why.

Fixes proposed as code, reviewed by your team
How does it actually work?

The mechanism, not the marketing

  1. 1

    Fixing runs on demand against a completed code scan. You choose which severities to include, and findings your team has already marked as false positives are left out.

  2. 2

    The engine makes a shallow clone of the scanned repository using a Git token passed with that request only. The token is never written to the database or the logs, and is removed from the clone's configuration after the push.

  3. 3

    Findings are grouped by file. For each file, a large language model receives the whole file, every finding in it, and the rule's guidance — what the issue is, how to fix it, and a safe example in the same language where the rule library has one. If a rule has no guidance on record, the scanner's own message is used instead.

  4. 4

    The model is instructed to fix only the listed issues and to keep the rest of the file — indentation, names, imports and style — exactly as it was. It returns the complete corrected file, so several findings in one file are fixed in one coherent pass rather than as separate line edits.

  5. 5

    Corrected files are written back only if they already exist inside the repository, then committed to a new fix branch and pushed. Nothing is merged and nothing is deployed: your normal pull-request review and CI run before any of it reaches your main branch.

What do you actually get?

Specific outputs, measurable outcomes

Corrected files, not advice
the full rewritten file for each affected path
One pass per file
every finding in a file fixed together, with the surrounding code in view
Rule-guided fixes
the rule's recommendation and a language-matched safe example go to the model with each finding
A separate fix branch
your main branch is never written to
Per-finding status
fixed and committed, fix generated, failed or skipped, with the reason
Severity filter
fix the critical and high findings first and leave the rest for later
False positives respected
findings your team dismissed are not touched
Token handling
the Git token is used for one request and never stored or logged
FAQ

Questions we get a lot

Today AI Code Fix is run with you on request: you choose a completed scan and the severities to include, supply a Git token for that run, and the fix branch appears in your repository. It is not yet a button in the console. In the console, every code finding already carries rule guidance and an AI fix prompt you can copy into your own assistant.
Ready to see it live

Ready to see AI Code Fix on your code?

We will run a scan and a fix on a repository you choose, and walk your team through the branch it produces.