DeepSource

Static analysis and code security platform that reviews every commit and PR, with an AI review agent and Autofix remediation.

$24/user/moLast verified 2026-09-06

Deployment

Cloud · Self-Hosted · Air-Gapped

Languages

18+

Pricing model

Per developer seat, Usage-based credits, Per lines of code, Quote-based / Enterprise

Free tier

Yes

Workflow coverage

Where in the development lifecycle DeepSource operates.

Real-Time IDE FeedbackNo

API schema exposes IDE subscriptions (FREE/PRO/SPONSORED) and IDE device auth; no IDE extension guide documented.

AI Agent Guardrail (MCP)Yes

30-tool MCP server plus JSON-output CLI and a packaged DeepSource Skill for terminal agents.

Local CLI / Pre-CommitPartial

CLI queries results and uploads coverage; analysis runs on DeepSource infrastructure, no local pre-commit scan documented.

PR Inline ReviewYes

Summary comment on every PR plus optional inline comments highlighting exact lines.

Merge Gate BlockingYes

Quality Gates fail checks on category, severity, or metric thresholds; AI Review status can be a required check.

Full Repo ScanYes

Every commit to the default branch is analysed; languages auto-detected on repository activation.

Scheduled / Continuous RescanPartial

Newly published CVEs affecting existing dependencies trigger automatic notifications; no scheduled full rescan.

Runtime / Production MonitoringNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Analysis & detection

Every detection and code-analysis capability tracked for DeepSource.

SASTYes

Bug risk, security, anti-pattern, performance, and typecheck issues across 18 core analyzers.

Taint / Data-Flow AnalysisNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Secrets DetectionYesTeam

Hybrid regex plus 'Narada' AI classifier; PR checks fail on detection. Team or Enterprise plan required.

Secrets ValidationPartialTeam

AI classifier judges each match in context to exclude test values and placeholders; no live credential validation.

SCA (Dependencies)Yesadd-on

Full transitive tree checked against NVD and other advisories, but billed pay-as-you-go per active dependency target on all plans.

Reachability AnalysisYesadd-on

Call-graph tracing to the vulnerable function; REACHABLE/UNREACHABLE/UNKNOWN with call-path visualisation.

Malicious Package DetectionNo

Not offered in vendor documentation reviewed as of 2026-09-05.

License ComplianceYesadd-on

SPDX license identification, category rules and custom overrides across transitive dependencies; rides on SCA billing.

SBOM GenerationNo

Not offered in vendor documentation reviewed as of 2026-09-05.

IaC ScanningYes

Dedicated Dockerfile, Terraform, and Ansible analyzers; community analyzers add CloudFormation and Kubernetes.

Container ScanningPartial

Dockerfile analyzer flags root user, latest tags, missing health checks, exposed ports; no image or layer scanning.

Cloud Posture (CSPM)No

Not offered in vendor documentation reviewed as of 2026-09-05.

DAST / API ScanningNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Code Smells & MaintainabilityYes

Anti-pattern category covers code smells, unused variables, dead code, and unnecessary complexity.

Complexity MetricsYes

Configurable cyclomatic complexity thresholds (low to critical) plus a Complexity Report Card dimension.

Duplication DetectionYes

Duplication is measured and reported inside the Report Card 'Hygiene' dimension.

Dead / Unused CodeYes

Dead code and unused imports raised under the anti-pattern category and the Hygiene dimension.

Test Coverage TrackingYes

Line, branch, condition, and composite coverage tracked; untested lines raised as actionable issues.

Diff / New-Code CoverageYes

New-code metrics NLCV, NBCV, NCCV, NCPCV measure changeset coverage and gate merges on thresholds.

Architecture GovernanceNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Technical Debt QuantificationPartial

Code health score, Code Health Trend, and Issues Prevented reports; no time or cost debt quantification.

Behavioral Delivery AnalyticsNo

Not offered in vendor documentation reviewed as of 2026-09-05.

AI Logic Bug DetectionYesadd-on

AI Review agent runs on PRs with issues tagged AI vs STATIC; the bug classes it finds are not enumerated.

PR Summaries & WalkthroughsYes

Report Card carries AI-generated narrative feedback plus a pull-request summary comment.

Custom Rule AuthoringPartial

No custom rule authoring documented; third-party SARIF analyzers plug in via the Community Analyzer framework.

Autofix SuggestionsYes

Autofix button generates fixes for all occurrences of an issue; metered by AI credits, usage-priced on Open Source.

Autofix via Agentic PRsYes

Autofix opens a PR or commits onto an existing PR branch; vulnerability autofix opens PRs with a breakage score.

AI Triage / False-Positive FilteringYesTeam

Narada model filters false-positive secrets (Team+); AI Review has a dedicated false-positive reporting flow.

Monorepo SupportYes

All tiers provide monorepo support alongside unlimited pull request reviews.

AI capabilities

AI Review EngineYes

AI Review agent runs hybrid with static analysis, governed by a team-level AI & Agents policy.

BYO Model / BYOKYesEnterprise

Enterprise Server v5.0.0+ BYOK routes inference through Vertex AI, Bedrock, Azure OpenAI, OpenAI, Google AI, or Anthropic.

MCP ServerYes

mcp.deepsource.com with 30 tools, OAuth and PAT auth; optional admin toggle on Enterprise Server v5.1.0+.

AI Usage GovernanceNo

No AI-generated-code inventory; AI and Agents policy plus autofix toggles govern AI tool use instead.

Chat With ReviewerPartial

AI Review can be invoked by mentioning @deepsourcebot in a PR comment; no conversational thread documented.

Learns From FeedbackYes

Marking an AI Review issue a false positive opens a comment modal that feeds back into AI Review accuracy.

Code Excluded From TrainingYes

Privacy Policy: code not used to train AI models unless customer explicitly opts in via account settings

Models used

Narada (DeepSource's own open-source secrets classification model)

Compliance & governance

Audit LogsYesTeam

Audit logs listed in the Team plan; Enterprise Control Panel adds audit logging for enterprise admins.

SSO / SAMLYesEnterprise

SAML SSO supported on DeepSource Enterprise Server only.

Role-Based Access ControlPartial

GraphQL API exposes access control and WRITE-access checks; Enterprise Control Panel adds global policy controls. No role matrix documented.

Compliance Reporting ExportsYesTeam

Always-current OWASP/CWE-SANS/MISRA C reports shareable via optionally password-protected link; Team or Enterprise required.

Standards mapping

OWASP Top 10CWE/SANS Top 25MISRA C

Integrations

GitHubYes
GitHub Enterprise ServerPartial
GitLabYes
GitLab Self-ManagedPartial
BitbucketYes
Bitbucket Data CenterPartial
Azure DevOpsYes
REST APIPartial
CLIYes
WebhooksYes

CI/CD systems

GitHub Actions (with OIDC auth)GitLab CICircleCITravis CIHeroku CIAzure Pipelines

Issue trackers

Jira Cloud (Enterprise Server only, OAuth 2.0 app, ticket creation from issues)

Chat & notifications

Slack (Enterprise Server, via app manifest)Webhooks (organization accounts only)

Pricing & plans

$24/user/month billed yearly ($30/user/month if billed monthly)

Minimum seats: None documented — billed per user, pro-rated when users are added or removed mid-cycle

Trial: 14 days, no credit card required; up to $50 in bundled AI Review credits for new users

Open Source$0Open-source and public-repo projects
  • PR reviews for public repos, stated as unlimited but capped at up to 1,000 monthly
  • Static analysis for 18 languages
  • Basic issue detection
  • Code formatters, PR diffing, and Quality Gates
  • Monorepo support
  • AI Review charged at $8/10K LOC (Standard) or $15/10K LOC (Advanced) with no included credit
  • OSS dependency scanning is pay-as-you-go
  • No secrets detection
  • No compliance reporting (OWASP, CWE/SANS, MISRA C)
  • No advanced security features
Team$24/user/month billed yearly (monthly billing also available)Private-repo engineering teams
  • Unlimited repositories and PR reviews
  • All Open Source features
  • $100 annual AI Review credit per user
  • Secrets detection with the hybrid AI engine
  • Compliance reporting (OWASP Top 10, CWE/SANS Top 25, MISRA C)
  • API access, audit logs, priority support, advanced security features
  • AI Review overage billed at $8/10K LOC (Standard) or $15/10K LOC (Advanced)
  • OSS dependency scanning still pay-as-you-go per active target
  • No self-hosted deployment, SAML SSO, SCIM, Enterprise Control Panel, or BYOK
  • GitHub Enterprise Server, GitLab self-managed, and Bitbucket Data Center are documented only for Enterprise Server
EnterpriseCustom pricingOrganisations with compliance or security requirements needing operation inside their firewall
  • All Team features
  • Self-hosted DeepSource Enterprise Server, including air-gapped install
  • SAML SSO and SCIM provisioning (Okta documented)
  • Enterprise Control Panel with cross-team user management, license monitoring, global policy, audit logging
  • Bring-Your-Own-Key AI routing
  • Dedicated account manager and priority SLA support
  • No published price
  • Self-hosting requires Kubernetes plus a customer-managed PostgreSQL and backup strategy
  • AI Review and SCA usage costs still apply

Who it's for

Notable strengths

  • Reachability analysis with call-path visualisation plus a tunable Dynamic Risk Score combining CVSS, EPSS, and reachability
  • Autofix covers both code issues and dependency upgrades, opening PRs with an AI-assessed breakage score
  • 30-tool MCP server and JSON-output CLI give AI agents structured access to issues, metrics, and vulnerabilities
  • Coverage tracking across line, branch, condition, and composite metrics including new-code variants, with merge gating
  • Zero-config activation (no YAML, no CI change, no agents) and stacked-PR-aware issue diffing with documented edge cases

Notable limitations

  • Secrets detection, compliance reporting, audit logs, and advanced security features require Team or Enterprise
  • OSS dependency scanning is billed pay-as-you-go per active dependency target on every plan, including Team
  • AI Review is usage-priced per 10K LOC beyond included credits, so cost scales with code volume
  • No third-party certifications (SOC 2, ISO 27001) named anywhere in the documentation
  • Self-managed VCS providers (GitHub Enterprise Server, GitLab self-managed, Bitbucket Data Center) are documented only for Enterprise Server

Similar tools

Other Quality Platform tools in the directory.

FAQ

When should you choose DeepSource?

DeepSource best fits Indie developers, Startups, Mid-market teams, Enterprise, Regulated industries. Reachability analysis with call-path visualisation plus a tunable Dynamic Risk Score combining CVSS, EPSS, and reachability

What languages does DeepSource support?

DeepSource supports 18+ languages and frameworks, including Go, Rust, Java, Scala, C#, JavaScript, TypeScript, PHP, Python, Ruby, and 9 more.

What does DeepSource integrate with?

DeepSource integrates with GitHub, GitHub Enterprise Server (partial), GitLab, GitLab Self-Managed (partial), Bitbucket, Bitbucket Data Center (partial), Azure DevOps for source control, CI systems including GitHub Actions (with OIDC auth), GitLab CI, CircleCI, Travis CI, Heroku CI, and 1 more.

What tools are similar to DeepSource?

Similar Quality Platform tools tracked here include Codacy, CodeScene, Qlty, SonarQube.

What are DeepSource's plans and pricing?

DeepSource offers a free tier, with paid plans starting around $24/user/mo; enterprise pricing is quote-only.