Qodex.ai
26 fields evidenced · 29 with no public information. Every value below links to the document it came from and the date we checked it.
Trust gap
How this is scoredThese scores are automated. They measure how many fields this entry answers with a citation — not what those answers say. No one has scored this entry against the rubric yet.
Are scope, spend, and authority enforced while the agent runs?
Scored from 2 evidenced field(s): runtime_governance, permission_scopes. Automated score; capped at 2 pending review.
Is there a tamper-evident record of what it actually did?
Scored from 2 evidenced field(s): audit_trail, explainability. Automated score; capped at 2 pending review.
Are compliance obligations attached per engagement?
Scored from 1 evidenced field(s): regulatory_alignment. Automated score; capped at 2 pending review.
Does payment depend on a verified result?
Can the deployment be insured, and is the customer indemnified?
Assurance
- Insurance available
- no public informationqodex.ai · checked Aug 1, 2026 · source did not state this
- Insurance carriers
- no public informationqodex.ai · checked Aug 1, 2026 · source did not state this
- Coverage limits
- no public informationqodex.ai · checked Aug 1, 2026 · source did not state this
- Indemnification
- no public informationqodex.ai · checked Aug 1, 2026 · source did not state this
- Liability cap
- no public informationqodex.ai · checked Aug 1, 2026 · source did not state this
- Audit trail
- Qodex posts the result inline: the failing request, the response, and a screenshot.
“Qodex posts the result inline: the failing request, the response, and a screenshot.”
qodex.ai · checked Aug 1, 2026 - Tamper-evident log
- no public informationqodex.ai · checked Aug 1, 2026 · source did not state this
- Explainability
- Qodex bot reviewed and requested changes commented just now Changes requested checkout-api/billing.ts line 84 - const billing = await db.billing.find(orgId) + const billing = await db.billing.find({ orgId, callerOrgId }) Tenant isolation is broken here. An Org A admin can read another org’s billing. Scope the query to the caller’s org.
“Qodex bot reviewed and requested changes commented just now Changes requested checkout-api/billing.ts line 84 - const billing = await db.billing.find(orgId) + const billing = await db.billing.find({ orgId, callerOrgId }) Tenant isolation is broken here. An Org A admin can read another org’s billing. Scope the query to the caller’s org.”
qodex.ai · checked Aug 1, 2026 - Runtime governance
- Merge gate 1 blocking finding
“Merge gate 1 blocking finding”
qodex.ai · checked Aug 1, 2026 - Permission scopes
- Scope the query to the caller’s org.
“Scope the query to the caller’s org.”
qodex.ai · checked Aug 1, 2026 - Compliance certifications
- no public informationqodex.ai · checked Aug 1, 2026 · source did not state this
- Regulatory alignment
- OWASP API1:2023
“OWASP API1:2023”
qodex.ai · checked Aug 1, 2026 - Outcome-based pricing
- no public informationqodex.ai · checked Aug 1, 2026 · source did not state this
- Settlement mechanism
- no public informationqodex.ai · checked Aug 1, 2026 · source did not state this
- Dispute process
- no public informationqodex.ai · checked Aug 1, 2026 · source did not state this
- SLA terms
- no public informationqodex.ai · checked Aug 1, 2026 · source did not state this
- Evaluation coverage
- 1 of 41 scenarios failed
“1 of 41 scenarios failed”
qodex.ai · checked Aug 1, 2026
Agency
- Autonomy level
- no public informationqodex.ai · checked Aug 1, 2026 · source did not state this
- Human oversight
- A human still decides what merges.
“A human still decides what merges.”
qodex.ai · checked Aug 1, 2026 - Goal complexity
- Continuous testing that runs your scenarios against every PR and deploy, and shows you exactly what broke.
“Continuous testing that runs your scenarios against every PR and deploy, and shows you exactly what broke.”
qodex.ai · checked Aug 1, 2026 - Action space
- Qodex bot reviewed and requested changes
“Qodex bot reviewed and requested changes”
qodex.ai · checked Aug 1, 2026 - Operating environment
- Runs on your real app, not diff guesswork
“Runs on your real app, not diff guesswork”
qodex.ai · checked Aug 1, 2026 - Initiative
- Qodex agent 34 tests selected
“Qodex agent 34 tests selected”
qodex.ai · checked Aug 1, 2026
Safety
- Safety evaluations
- CVSS 8.6 OWASP API1:2023
“CVSS 8.6 OWASP API1:2023”
qodex.ai · checked Aug 1, 2026 - Red teaming
- OWASP security probes on every PR
“OWASP security probes on every PR”
qodex.ai · checked Aug 1, 2026 - Safety policy
- no public informationqodex.ai · checked Aug 1, 2026 · source did not state this
- Usage restrictions
- no public informationqodex.ai · checked Aug 1, 2026 · source did not state this
- Model or system card
- no public informationqodex.ai · checked Aug 1, 2026 · source did not state this
- Incident reporting
- Qodex bot flagged a vulnerability commented just now
“Qodex bot flagged a vulnerability commented just now”
qodex.ai · checked Aug 1, 2026 - Third-party evaluations
- 4.9 / 5 from 60 reviews on G2
“4.9 / 5 from 60 reviews on G2”
qodex.ai · checked Aug 1, 2026 - Data handling
- no public informationqodex.ai · checked Aug 1, 2026 · source did not state this
Practicality
- Pricing model
- no public informationqodex.ai · checked Aug 1, 2026 · source did not state this
- Price point
- no public informationqodex.ai · checked Aug 1, 2026 · source did not state this
- Availability
- Start free trial
“Start free trial”
qodex.ai · checked Aug 1, 2026 - Deployment options
- Install the GitHub app
“Install the GitHub app”
qodex.ai · checked Aug 1, 2026 - Integrations
- no public informationqodex.ai · checked Aug 1, 2026 · source did not state this
- Supported regions
- no public informationqodex.ai · checked Aug 1, 2026 · source did not state this
- Support model
- no public informationqodex.ai · checked Aug 1, 2026 · source did not state this
Foundation models
- Base models
- no public informationqodex.ai · checked Aug 1, 2026 · source did not state this
- Model provider
- no public informationqodex.ai · checked Aug 1, 2026 · source did not state this
- Model swappable
- no public informationqodex.ai · checked Aug 1, 2026 · source did not state this
- Open weights
- no public informationqodex.ai · checked Aug 1, 2026 · source did not state this
- Fine-tuning
- no public informationqodex.ai · checked Aug 1, 2026 · source did not state this
- Context window
- no public informationqodex.ai · checked Aug 1, 2026 · source did not state this
Ecosystem
- Protocols supported
- OpenAPI spec connected
“OpenAPI spec connected”
qodex.ai · checked Aug 1, 2026 - Tool use
- Qodex bot ran the test suite
“Qodex bot ran the test suite”
qodex.ai · checked Aug 1, 2026 - Multi-agent
- no public informationqodex.ai · checked Aug 1, 2026 · source did not state this
- API access
- Real API, UI, and security tests on every pull request.
“Real API, UI, and security tests on every pull request.”
qodex.ai · checked Aug 1, 2026 - Open source
- no public informationqodex.ai · checked Aug 1, 2026 · source did not state this
- Marketplace presence
- Install the GitHub app
“Install the GitHub app”
qodex.ai · checked Aug 1, 2026
Impact
- User base
- 4.9 / 5 from 60 reviews on G2
“4.9 / 5 from 60 reviews on G2”
qodex.ai · checked Aug 1, 2026 - Deployment scale
- Teams already trust Qodex with their testing.
“Teams already trust Qodex with their testing.”
qodex.ai · checked Aug 1, 2026 - Target sectors
- Financial services
“Financial services”
qodex.ai · checked Aug 1, 2026 - High-risk domains
- Critical Broken object-level authorization (BOLA) GET /v1/orgs/{orgB}/billing returns 200 for an Org A admin (expected 403). Cross-tenant billing is exposed.
“Critical Broken object-level authorization (BOLA) GET /v1/orgs/{orgB}/billing returns 200 for an Org A admin (expected 403). Cross-tenant billing is exposed.”
qodex.ai · checked Aug 1, 2026 - Documented incidents
- Scenario “Admin cannot access tenant billing across orgs” failed: GET /v1/orgs/{orgB}/billing returned 200 instead of 403.
“Scenario “Admin cannot access tenant billing across orgs” failed: GET /v1/orgs/{orgB}/billing returned 200 instead of 403.”
qodex.ai · checked Aug 1, 2026