{"license":"CC BY 4.0","attribution":"AI Dispatch — https://aidispatch.news","methodology":"https://aidispatch.news/methodology","generated_at":"2026-08-03T19:48:46.512Z","entity":{"name":"Qodex.ai","slug":"qodex-ai","type":"agent","subtype":"Software Testing","developer":null,"homepage_url":"https://qodex.ai/","summary":null,"url":"https://aidispatch.news/agents/qodex-ai","published_at":"2026-08-01T23:59:48.065884+00:00","updated_at":"2026-08-01T23:59:48.065884+00:00"},"fields":[{"key":"human_oversight","label":"Human oversight","category":"agency","status":"present","value":"A human still decides what merges.","quote":"A human still decides what merges.","source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"initiative","label":"Initiative","category":"agency","status":"present","value":"Qodex agent 34 tests selected","quote":"Qodex agent 34 tests selected","source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"autonomy_level","label":"Autonomy level","category":"agency","status":"no_public_information","value":null,"quote":null,"source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"environment","label":"Operating environment","category":"agency","status":"present","value":"Runs on your real app, not diff guesswork","quote":"Runs on your real app, not diff guesswork","source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"target_sectors","label":"Target sectors","category":"impact","status":"present","value":"Financial services","quote":"Financial services","source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"price_point","label":"Price point","category":"practicality","status":"no_public_information","value":null,"quote":null,"source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"supported_regions","label":"Supported regions","category":"practicality","status":"no_public_information","value":null,"quote":null,"source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"model_swappable","label":"Model swappable","category":"models","status":"no_public_information","value":null,"quote":null,"source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"protocols_supported","label":"Protocols supported","category":"ecosystem","status":"present","value":"OpenAPI spec connected","quote":"OpenAPI spec connected","source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"open_source","label":"Open source","category":"ecosystem","status":"no_public_information","value":null,"quote":null,"source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"safety_policy","label":"Safety policy","category":"safety","status":"no_public_information","value":null,"quote":null,"source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"third_party_evals","label":"Third-party evaluations","category":"safety","status":"present","value":"4.9 / 5 from 60 reviews on G2","quote":"4.9 / 5 from 60 reviews on G2","source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"coverage_limits","label":"Coverage limits","category":"assurance","status":"no_public_information","value":null,"quote":null,"source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"audit_trail_immutable","label":"Tamper-evident log","category":"assurance","status":"no_public_information","value":null,"quote":null,"source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"compliance_certs","label":"Compliance certifications","category":"assurance","status":"no_public_information","value":null,"quote":null,"source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"settlement_mechanism","label":"Settlement mechanism","category":"assurance","status":"no_public_information","value":null,"quote":null,"source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"goal_complexity","label":"Goal complexity","category":"agency","status":"present","value":"Continuous testing that runs your scenarios against every PR and deploy, and shows you exactly what broke.","quote":"Continuous testing that runs your scenarios against every PR and deploy, and shows you exactly what broke.","source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"user_base","label":"User base","category":"impact","status":"present","value":"4.9 / 5 from 60 reviews on G2","quote":"4.9 / 5 from 60 reviews on G2","source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"documented_incidents","label":"Documented incidents","category":"impact","status":"present","value":"Scenario “Admin cannot access tenant billing across orgs” failed: GET /v1/orgs/{orgB}/billing returned 200 instead of 403.","quote":"Scenario “Admin cannot access tenant billing across orgs” failed: GET /v1/orgs/{orgB}/billing returned 200 instead of 403.","source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"deployment_options","label":"Deployment options","category":"practicality","status":"present","value":"Install the GitHub app","quote":"Install the GitHub app","source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"base_models","label":"Base models","category":"models","status":"no_public_information","value":null,"quote":null,"source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"fine_tuning","label":"Fine-tuning","category":"models","status":"no_public_information","value":null,"quote":null,"source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"multi_agent","label":"Multi-agent","category":"ecosystem","status":"no_public_information","value":null,"quote":null,"source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"safety_evaluations","label":"Safety evaluations","category":"safety","status":"present","value":"CVSS 8.6 OWASP API1:2023","quote":"CVSS 8.6 OWASP API1:2023","source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"model_card","label":"Model or system card","category":"safety","status":"no_public_information","value":null,"quote":null,"source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"insurance_available","label":"Insurance available","category":"assurance","status":"no_public_information","value":null,"quote":null,"source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"liability_cap","label":"Liability cap","category":"assurance","status":"no_public_information","value":null,"quote":null,"source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"runtime_governance","label":"Runtime governance","category":"assurance","status":"present","value":"Merge gate 1 blocking finding","quote":"Merge gate 1 blocking finding","source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"outcome_based_pricing","label":"Outcome-based pricing","category":"assurance","status":"no_public_information","value":null,"quote":null,"source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"sla_terms","label":"SLA terms","category":"assurance","status":"no_public_information","value":null,"quote":null,"source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"action_space","label":"Action space","category":"agency","status":"present","value":"Qodex bot reviewed and requested changes","quote":"Qodex bot reviewed and requested changes","source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"deployment_scale","label":"Deployment scale","category":"impact","status":"present","value":"Teams already trust Qodex with their testing.","quote":"Teams already trust Qodex with their testing.","source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"pricing_model","label":"Pricing model","category":"practicality","status":"no_public_information","value":null,"quote":null,"source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"integrations","label":"Integrations","category":"practicality","status":"no_public_information","value":null,"quote":null,"source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"model_provider","label":"Model provider","category":"models","status":"no_public_information","value":null,"quote":null,"source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"context_window","label":"Context window","category":"models","status":"no_public_information","value":null,"quote":null,"source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"api_access","label":"API access","category":"ecosystem","status":"present","value":"Real API, UI, and security tests on every pull request.","quote":"Real API, UI, and security tests on every pull request.","source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"red_teaming","label":"Red teaming","category":"safety","status":"present","value":"OWASP security probes on every PR","quote":"OWASP security probes on every PR","source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"incident_reporting","label":"Incident reporting","category":"safety","status":"present","value":"Qodex bot flagged a vulnerability commented just now","quote":"Qodex bot flagged a vulnerability commented just now","source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"insurance_carriers","label":"Insurance carriers","category":"assurance","status":"no_public_information","value":null,"quote":null,"source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"audit_trail","label":"Audit trail","category":"assurance","status":"present","value":"Qodex posts the result inline: the failing request, the response, and a screenshot.","quote":"Qodex posts the result inline: the failing request, the response, and a screenshot.","source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"permission_scopes","label":"Permission scopes","category":"assurance","status":"present","value":"Scope the query to the caller’s org.","quote":"Scope the query to the caller’s org.","source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"eval_coverage","label":"Evaluation coverage","category":"assurance","status":"present","value":"1 of 41 scenarios failed","quote":"1 of 41 scenarios failed","source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"high_risk_domains","label":"High-risk domains","category":"impact","status":"present","value":"Critical Broken object-level authorization (BOLA) GET /v1/orgs/{orgB}/billing returns 200 for an Org A admin (expected 403). Cross-tenant billing is exposed.","quote":"Critical Broken object-level authorization (BOLA) GET /v1/orgs/{orgB}/billing returns 200 for an Org A admin (expected 403). Cross-tenant billing is exposed.","source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"availability","label":"Availability","category":"practicality","status":"present","value":"Start free trial","quote":"Start free trial","source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"support_model","label":"Support model","category":"practicality","status":"no_public_information","value":null,"quote":null,"source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"open_weights","label":"Open weights","category":"models","status":"no_public_information","value":null,"quote":null,"source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"tool_use","label":"Tool use","category":"ecosystem","status":"present","value":"Qodex bot ran the test suite","quote":"Qodex bot ran the test suite","source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"marketplace_presence","label":"Marketplace presence","category":"ecosystem","status":"present","value":"Install the GitHub app","quote":"Install the GitHub app","source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"usage_restrictions","label":"Usage restrictions","category":"safety","status":"no_public_information","value":null,"quote":null,"source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"data_handling","label":"Data handling","category":"safety","status":"no_public_information","value":null,"quote":null,"source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"indemnification","label":"Indemnification","category":"assurance","status":"no_public_information","value":null,"quote":null,"source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"explainability","label":"Explainability","category":"assurance","status":"present","value":"Qodex bot reviewed and requested changes commented just now Changes requested checkout-api/billing.ts line 84 - const billing = await db.billing.find(orgId) + const billing = await db.billing.find({ orgId, callerOrgId }) Tenant isolation is broken here. An Org A admin can read another org’s billing. Scope the query to the caller’s org.","quote":"Qodex bot reviewed and requested changes commented just now Changes requested checkout-api/billing.ts line 84 - const billing = await db.billing.find(orgId) + const billing = await db.billing.find({ orgId, callerOrgId }) Tenant isolation is broken here. An Org A admin can read another org’s billing. Scope the query to the caller’s org.","source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"regulatory_alignment","label":"Regulatory alignment","category":"assurance","status":"present","value":"OWASP API1:2023","quote":"OWASP API1:2023","source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"},{"key":"dispute_process","label":"Dispute process","category":"assurance","status":"no_public_information","value":null,"quote":null,"source_url":"https://qodex.ai/","retrieved_at":"2026-08-01T23:58:34.916869+00:00"}],"trust_gap_scores":[{"dimension":"audit_trail","score":2,"rationale":"Scored from 2 evidenced field(s): audit_trail, explainability. Automated score; capped at 2 pending review.","rubric_version":"v1-auto"},{"dimension":"compliance","score":1,"rationale":"Scored from 1 evidenced field(s): regulatory_alignment. Automated score; capped at 2 pending review.","rubric_version":"v1-auto"},{"dimension":"runtime_governance","score":2,"rationale":"Scored from 2 evidenced field(s): runtime_governance, permission_scopes. Automated score; capped at 2 pending review.","rubric_version":"v1-auto"}]}