Introduction

What ScanDrix is, how Drixy reviews pull requests, and where to go next.

ScanDrix is an autonomous AI code review and AST security scanning platform. It connects to your Git provider, reads every pull request, and returns inline review comments — vulnerabilities, rule violations, and one-click patch suggestions — typically in under 60 seconds.

How it works

ScanDrix combines deterministic Abstract Syntax Tree analysis with multi-model AI reasoning. Diffs are parsed into ASTs, tainted flows and architectural boundaries are resolved, and review rules are evaluated against real code structure — not regex guesses over isolated files.

  1. Webhook arrives. Your Git provider notifies ScanDrix that a pull request was opened or updated.
  2. Diff is analyzed. The diff is expanded with surrounding context and parsed. Secrets are redacted before any model call.
  3. Rules are evaluated. Active Drixy rules (organization, repository, or library) run against the AST with severity-based filtering.
  4. Review is posted. Inline comments, patch suggestions, and a summary appear directly on the pull request.

Reviews are processed in ephemeral, isolated environments with zero data retention. ScanDrix never trains on customer source code.

What you get

  • Inline comments with severity, rule ID, and a concrete fix.
  • One-click patch suggestions as applyable diffs on the PR.
  • Custom Drixy rules — global, per-repository, or from a shared library, with Dry Run previews before enforcement.
  • CLI and team API keys for local runs, pre-commit hooks, and custom CI.
  • Supported providers: GitHub, GitLab, Bitbucket, Azure Repos, and Forgejo.

Where to go next