Quality Platform
DeepSource
Static analysis and code security platform that reviews every commit and PR, with an AI review agent and Autofix remediation.
Deployment
Cloud · Self-Hosted · Air-Gapped
Languages
18+
Pricing model
Per developer seat, Usage-based credits, Per lines of code, Quote-based / Enterprise
Free tier
Yes
Workflow coverage
Where in the development lifecycle DeepSource operates.
API schema exposes IDE subscriptions (FREE/PRO/SPONSORED) and IDE device auth; no IDE extension guide documented.
30-tool MCP server plus JSON-output CLI and a packaged DeepSource Skill for terminal agents.
CLI queries results and uploads coverage; analysis runs on DeepSource infrastructure, no local pre-commit scan documented.
Summary comment on every PR plus optional inline comments highlighting exact lines.
Quality Gates fail checks on category, severity, or metric thresholds; AI Review status can be a required check.
Every commit to the default branch is analysed; languages auto-detected on repository activation.
Newly published CVEs affecting existing dependencies trigger automatic notifications; no scheduled full rescan.
Not offered in vendor documentation reviewed as of 2026-09-05.
Analysis & detection
Every detection and code-analysis capability tracked for DeepSource.
Bug risk, security, anti-pattern, performance, and typecheck issues across 18 core analyzers.
Not offered in vendor documentation reviewed as of 2026-09-05.
Hybrid regex plus 'Narada' AI classifier; PR checks fail on detection. Team or Enterprise plan required.
AI classifier judges each match in context to exclude test values and placeholders; no live credential validation.
Full transitive tree checked against NVD and other advisories, but billed pay-as-you-go per active dependency target on all plans.
Call-graph tracing to the vulnerable function; REACHABLE/UNREACHABLE/UNKNOWN with call-path visualisation.
Not offered in vendor documentation reviewed as of 2026-09-05.
SPDX license identification, category rules and custom overrides across transitive dependencies; rides on SCA billing.
Not offered in vendor documentation reviewed as of 2026-09-05.
Dedicated Dockerfile, Terraform, and Ansible analyzers; community analyzers add CloudFormation and Kubernetes.
Dockerfile analyzer flags root user, latest tags, missing health checks, exposed ports; no image or layer scanning.
Not offered in vendor documentation reviewed as of 2026-09-05.
Not offered in vendor documentation reviewed as of 2026-09-05.
Anti-pattern category covers code smells, unused variables, dead code, and unnecessary complexity.
Configurable cyclomatic complexity thresholds (low to critical) plus a Complexity Report Card dimension.
Duplication is measured and reported inside the Report Card 'Hygiene' dimension.
Dead code and unused imports raised under the anti-pattern category and the Hygiene dimension.
Line, branch, condition, and composite coverage tracked; untested lines raised as actionable issues.
New-code metrics NLCV, NBCV, NCCV, NCPCV measure changeset coverage and gate merges on thresholds.
Not offered in vendor documentation reviewed as of 2026-09-05.
Code health score, Code Health Trend, and Issues Prevented reports; no time or cost debt quantification.
Not offered in vendor documentation reviewed as of 2026-09-05.
AI Review agent runs on PRs with issues tagged AI vs STATIC; the bug classes it finds are not enumerated.
Report Card carries AI-generated narrative feedback plus a pull-request summary comment.
No custom rule authoring documented; third-party SARIF analyzers plug in via the Community Analyzer framework.
Autofix button generates fixes for all occurrences of an issue; metered by AI credits, usage-priced on Open Source.
Autofix opens a PR or commits onto an existing PR branch; vulnerability autofix opens PRs with a breakage score.
Narada model filters false-positive secrets (Team+); AI Review has a dedicated false-positive reporting flow.
All tiers provide monorepo support alongside unlimited pull request reviews.
AI capabilities
AI Review agent runs hybrid with static analysis, governed by a team-level AI & Agents policy.
Enterprise Server v5.0.0+ BYOK routes inference through Vertex AI, Bedrock, Azure OpenAI, OpenAI, Google AI, or Anthropic.
mcp.deepsource.com with 30 tools, OAuth and PAT auth; optional admin toggle on Enterprise Server v5.1.0+.
No AI-generated-code inventory; AI and Agents policy plus autofix toggles govern AI tool use instead.
AI Review can be invoked by mentioning @deepsourcebot in a PR comment; no conversational thread documented.
Marking an AI Review issue a false positive opens a comment modal that feeds back into AI Review accuracy.
Privacy Policy: code not used to train AI models unless customer explicitly opts in via account settings
Models used
Compliance & governance
Audit logs listed in the Team plan; Enterprise Control Panel adds audit logging for enterprise admins.
SAML SSO supported on DeepSource Enterprise Server only.
GraphQL API exposes access control and WRITE-access checks; Enterprise Control Panel adds global policy controls. No role matrix documented.
Always-current OWASP/CWE-SANS/MISRA C reports shareable via optionally password-protected link; Team or Enterprise required.
Standards mapping
Integrations
CI/CD systems
Issue trackers
Chat & notifications
Pricing & plans
$24/user/month billed yearly ($30/user/month if billed monthly)
Minimum seats: None documented — billed per user, pro-rated when users are added or removed mid-cycle
Trial: 14 days, no credit card required; up to $50 in bundled AI Review credits for new users
- PR reviews for public repos, stated as unlimited but capped at up to 1,000 monthly
- Static analysis for 18 languages
- Basic issue detection
- Code formatters, PR diffing, and Quality Gates
- Monorepo support
- AI Review charged at $8/10K LOC (Standard) or $15/10K LOC (Advanced) with no included credit
- OSS dependency scanning is pay-as-you-go
- No secrets detection
- No compliance reporting (OWASP, CWE/SANS, MISRA C)
- No advanced security features
- Unlimited repositories and PR reviews
- All Open Source features
- $100 annual AI Review credit per user
- Secrets detection with the hybrid AI engine
- Compliance reporting (OWASP Top 10, CWE/SANS Top 25, MISRA C)
- API access, audit logs, priority support, advanced security features
- AI Review overage billed at $8/10K LOC (Standard) or $15/10K LOC (Advanced)
- OSS dependency scanning still pay-as-you-go per active target
- No self-hosted deployment, SAML SSO, SCIM, Enterprise Control Panel, or BYOK
- GitHub Enterprise Server, GitLab self-managed, and Bitbucket Data Center are documented only for Enterprise Server
- All Team features
- Self-hosted DeepSource Enterprise Server, including air-gapped install
- SAML SSO and SCIM provisioning (Okta documented)
- Enterprise Control Panel with cross-team user management, license monitoring, global policy, audit logging
- Bring-Your-Own-Key AI routing
- Dedicated account manager and priority SLA support
- No published price
- Self-hosting requires Kubernetes plus a customer-managed PostgreSQL and backup strategy
- AI Review and SCA usage costs still apply
Who it's for
Notable strengths
- Reachability analysis with call-path visualisation plus a tunable Dynamic Risk Score combining CVSS, EPSS, and reachability
- Autofix covers both code issues and dependency upgrades, opening PRs with an AI-assessed breakage score
- 30-tool MCP server and JSON-output CLI give AI agents structured access to issues, metrics, and vulnerabilities
- Coverage tracking across line, branch, condition, and composite metrics including new-code variants, with merge gating
- Zero-config activation (no YAML, no CI change, no agents) and stacked-PR-aware issue diffing with documented edge cases
Notable limitations
- Secrets detection, compliance reporting, audit logs, and advanced security features require Team or Enterprise
- OSS dependency scanning is billed pay-as-you-go per active dependency target on every plan, including Team
- AI Review is usage-priced per 10K LOC beyond included credits, so cost scales with code volume
- No third-party certifications (SOC 2, ISO 27001) named anywhere in the documentation
- Self-managed VCS providers (GitHub Enterprise Server, GitLab self-managed, Bitbucket Data Center) are documented only for Enterprise Server
Similar tools
Other Quality Platform tools in the directory.
FAQ
When should you choose DeepSource?
DeepSource best fits Indie developers, Startups, Mid-market teams, Enterprise, Regulated industries. Reachability analysis with call-path visualisation plus a tunable Dynamic Risk Score combining CVSS, EPSS, and reachability
What languages does DeepSource support?
DeepSource supports 18+ languages and frameworks, including Go, Rust, Java, Scala, C#, JavaScript, TypeScript, PHP, Python, Ruby, and 9 more.
What does DeepSource integrate with?
DeepSource integrates with GitHub, GitHub Enterprise Server (partial), GitLab, GitLab Self-Managed (partial), Bitbucket, Bitbucket Data Center (partial), Azure DevOps for source control, CI systems including GitHub Actions (with OIDC auth), GitLab CI, CircleCI, Travis CI, Heroku CI, and 1 more.
What tools are similar to DeepSource?
Similar Quality Platform tools tracked here include Codacy, CodeScene, Qlty, SonarQube.
What are DeepSource's plans and pricing?
DeepSource offers a free tier, with paid plans starting around $24/user/mo; enterprise pricing is quote-only.
Opens deepsource.com in a new tab. Review Radar is not affiliated with DeepSource.