AI Dispatch
agent · Software Testing

Qodex.ai

Indexed12 or more fields evidenced; not yet scored by a human against the rubric

26 fields evidenced · 29 with no public information. Every value below links to the document it came from and the date we checked it.

These scores are automated. They measure how many fields this entry answers with a citation — not what those answers say. No one has scored this entry against the rubric yet.

Runtime governance
2/3 auto

Are scope, spend, and authority enforced while the agent runs?

Scored from 2 evidenced field(s): runtime_governance, permission_scopes. Automated score; capped at 2 pending review.

Audit trail
2/3 auto

Is there a tamper-evident record of what it actually did?

Scored from 2 evidenced field(s): audit_trail, explainability. Automated score; capped at 2 pending review.

Compliance
1/3 auto

Are compliance obligations attached per engagement?

Scored from 1 evidenced field(s): regulatory_alignment. Automated score; capped at 2 pending review.

Outcome settlement
unscored

Does payment depend on a verified result?

Insurance & indemnity
unscored

Can the deployment be insured, and is the customer indemnified?

Assurance

Insurance available
no public information
qodex.ai · checked Aug 1, 2026 · source did not state this
Insurance carriers
no public information
qodex.ai · checked Aug 1, 2026 · source did not state this
Coverage limits
no public information
qodex.ai · checked Aug 1, 2026 · source did not state this
Indemnification
no public information
qodex.ai · checked Aug 1, 2026 · source did not state this
Liability cap
no public information
qodex.ai · checked Aug 1, 2026 · source did not state this
Audit trail
Qodex posts the result inline: the failing request, the response, and a screenshot.
Qodex posts the result inline: the failing request, the response, and a screenshot.
qodex.ai · checked Aug 1, 2026
Tamper-evident log
no public information
qodex.ai · checked Aug 1, 2026 · source did not state this
Explainability
Qodex bot reviewed and requested changes commented just now Changes requested checkout-api/billing.ts line 84 - const billing = await db.billing.find(orgId) + const billing = await db.billing.find({ orgId, callerOrgId }) Tenant isolation is broken here. An Org A admin can read another org’s billing. Scope the query to the caller’s org.
Qodex bot reviewed and requested changes commented just now Changes requested checkout-api/billing.ts line 84 - const billing = await db.billing.find(orgId) + const billing = await db.billing.find({ orgId, callerOrgId }) Tenant isolation is broken here. An Org A admin can read another org’s billing. Scope the query to the caller’s org.
qodex.ai · checked Aug 1, 2026
Runtime governance
Merge gate 1 blocking finding
Merge gate 1 blocking finding
qodex.ai · checked Aug 1, 2026
Permission scopes
Scope the query to the caller’s org.
Scope the query to the caller’s org.
qodex.ai · checked Aug 1, 2026
Compliance certifications
no public information
qodex.ai · checked Aug 1, 2026 · source did not state this
Regulatory alignment
OWASP API1:2023
OWASP API1:2023
qodex.ai · checked Aug 1, 2026
Outcome-based pricing
no public information
qodex.ai · checked Aug 1, 2026 · source did not state this
Settlement mechanism
no public information
qodex.ai · checked Aug 1, 2026 · source did not state this
Dispute process
no public information
qodex.ai · checked Aug 1, 2026 · source did not state this
SLA terms
no public information
qodex.ai · checked Aug 1, 2026 · source did not state this
Evaluation coverage
1 of 41 scenarios failed
1 of 41 scenarios failed
qodex.ai · checked Aug 1, 2026

Agency

Autonomy level
no public information
qodex.ai · checked Aug 1, 2026 · source did not state this
Human oversight
A human still decides what merges.
A human still decides what merges.
qodex.ai · checked Aug 1, 2026
Goal complexity
Continuous testing that runs your scenarios against every PR and deploy, and shows you exactly what broke.
Continuous testing that runs your scenarios against every PR and deploy, and shows you exactly what broke.
qodex.ai · checked Aug 1, 2026
Action space
Qodex bot reviewed and requested changes
Qodex bot reviewed and requested changes
qodex.ai · checked Aug 1, 2026
Operating environment
Runs on your real app, not diff guesswork
Runs on your real app, not diff guesswork
qodex.ai · checked Aug 1, 2026
Initiative
Qodex agent 34 tests selected
Qodex agent 34 tests selected
qodex.ai · checked Aug 1, 2026

Safety

Safety evaluations
CVSS 8.6 OWASP API1:2023
CVSS 8.6 OWASP API1:2023
qodex.ai · checked Aug 1, 2026
Red teaming
OWASP security probes on every PR
OWASP security probes on every PR
qodex.ai · checked Aug 1, 2026
Safety policy
no public information
qodex.ai · checked Aug 1, 2026 · source did not state this
Usage restrictions
no public information
qodex.ai · checked Aug 1, 2026 · source did not state this
Model or system card
no public information
qodex.ai · checked Aug 1, 2026 · source did not state this
Incident reporting
Qodex bot flagged a vulnerability commented just now
Qodex bot flagged a vulnerability commented just now
qodex.ai · checked Aug 1, 2026
Third-party evaluations
4.9 / 5 from 60 reviews on G2
4.9 / 5 from 60 reviews on G2
qodex.ai · checked Aug 1, 2026
Data handling
no public information
qodex.ai · checked Aug 1, 2026 · source did not state this

Practicality

Pricing model
no public information
qodex.ai · checked Aug 1, 2026 · source did not state this
Price point
no public information
qodex.ai · checked Aug 1, 2026 · source did not state this
Availability
Start free trial
Start free trial
qodex.ai · checked Aug 1, 2026
Deployment options
Install the GitHub app
Install the GitHub app
qodex.ai · checked Aug 1, 2026
Integrations
no public information
qodex.ai · checked Aug 1, 2026 · source did not state this
Supported regions
no public information
qodex.ai · checked Aug 1, 2026 · source did not state this
Support model
no public information
qodex.ai · checked Aug 1, 2026 · source did not state this

Foundation models

Base models
no public information
qodex.ai · checked Aug 1, 2026 · source did not state this
Model provider
no public information
qodex.ai · checked Aug 1, 2026 · source did not state this
Model swappable
no public information
qodex.ai · checked Aug 1, 2026 · source did not state this
Open weights
no public information
qodex.ai · checked Aug 1, 2026 · source did not state this
Fine-tuning
no public information
qodex.ai · checked Aug 1, 2026 · source did not state this
Context window
no public information
qodex.ai · checked Aug 1, 2026 · source did not state this

Ecosystem

Protocols supported
OpenAPI spec connected
OpenAPI spec connected
qodex.ai · checked Aug 1, 2026
Tool use
Qodex bot ran the test suite
Qodex bot ran the test suite
qodex.ai · checked Aug 1, 2026
Multi-agent
no public information
qodex.ai · checked Aug 1, 2026 · source did not state this
API access
Real API, UI, and security tests on every pull request.
Real API, UI, and security tests on every pull request.
qodex.ai · checked Aug 1, 2026
Open source
no public information
qodex.ai · checked Aug 1, 2026 · source did not state this
Marketplace presence
Install the GitHub app
Install the GitHub app
qodex.ai · checked Aug 1, 2026

Impact

User base
4.9 / 5 from 60 reviews on G2
4.9 / 5 from 60 reviews on G2
qodex.ai · checked Aug 1, 2026
Deployment scale
Teams already trust Qodex with their testing.
Teams already trust Qodex with their testing.
qodex.ai · checked Aug 1, 2026
Target sectors
Financial services
Financial services
qodex.ai · checked Aug 1, 2026
High-risk domains
Critical Broken object-level authorization (BOLA) GET /v1/orgs/{orgB}/billing returns 200 for an Org A admin (expected 403). Cross-tenant billing is exposed.
Critical Broken object-level authorization (BOLA) GET /v1/orgs/{orgB}/billing returns 200 for an Org A admin (expected 403). Cross-tenant billing is exposed.
qodex.ai · checked Aug 1, 2026
Documented incidents
Scenario “Admin cannot access tenant billing across orgs” failed: GET /v1/orgs/{orgB}/billing returned 200 instead of 403.
Scenario “Admin cannot access tenant billing across orgs” failed: GET /v1/orgs/{orgB}/billing returned 200 instead of 403.
qodex.ai · checked Aug 1, 2026