Deployment
What is Cloud / SaaS?
The vendor hosts and operates the tool; your code is analysed on their infrastructure.
SaaS is the default for good reason: nothing to run, updates arrive continuously, and you are not staffing the operation of a scanner. For most teams it is the right answer.
It requires sending source code to a third party, which is the whole conversation in regulated environments. Where it survives review, it is usually because of data-residency guarantees and a training-exclusion commitment rather than the security posture alone.
Top 20 Cloud / SaaS tools
Every tool in the directory documented as supporting Cloud / SaaS, with what its own documentation says.
Support is not the same as parity, since some implementations are narrower in scope, gated to a higher plan tier, or maintained only for existing customers. The note under each tool is what its own documentation describes.
- 1
Codacy Cloud multi-region (EU, US) on AWS and Google Cloud with 99.9% SLA.
- 2AikidoCode Security Platform
Default hosted model; auto-scaling, continuous updates, 99.9% uptime SLA claimed
- 3
Codex cloud runs tasks in isolated OpenAI-managed containers; ChatGPT web, desktop and mobile surfaces.
- 4Checkmarx OneCode Security Platform
Multi-tenant SaaS across 10-11 named regions; a separately versioned Single-Tenant offering is also documented.
- 5Claude CodeAgent Coding Tool
Anthropic-hosted Code Review, ultrareview sandbox and cloud sessions in isolated managed VMs.
- 6CodeAnt AIPR Review
CodeAnt.ai cloud platform is described as the primary offering
- 7CodeRabbitPR Review
Primary delivery model; CodeRabbit Cloud with GitHub, GitLab, Azure DevOps, Bitbucket apps
- 8
CodeScene Cloud at codescene.io with US and EU data centres and automatic scaling
- 9CorgeaCode Security Platform
Default hosted app (corgea.app), multi-tenant by default
- 10Cursor (Bugbot)PR Review
Cloud-only on SOC 2 Type II compliant AWS infrastructure; Cloud Agents run in isolated cloud VMs.
- 11DeepSourceQuality Platform
app.deepsource.com, connect GitHub, GitLab, Bitbucket, or Azure DevOps at sign-up.
- 12
Delivered as a Google Cloud service via the Gemini for Google Cloud API, isolated from other project APIs.
- 13GitHub Advanced SecurityCode Security PlatformAdd-on: Secret Protection / Code Security on GitHub Team or Enterprise Cloud
GitHub.com and GitHub Enterprise Cloud host all GHAS features
- 14GreptilePR Review
Hosted by Greptile on AWS and Azure; runs in minutes with zero infrastructure management
- 15
Qlty Cloud on AWS, installed as a GitHub App creating a Workspace; analysis on ephemeral Fargate containers
- 16QodoPR Review
Multi-tenant cloud SaaS available on Free, Team and some Enterprise plans
- 17SemgrepCode Security Platform
AppSec Platform is a proprietary SaaS with single-tenant architecture.
- 18SnykCode Security Platform
Multi-tenant hosted SaaS is the default deployment model.
- 19SonarQubeQuality Platform
SonarQube Cloud, fully managed, EU at sonarcloud.io and US at sonarqube.us.
- 20
Veracode Platform SaaS with region-specific domains and API endpoints
What to look for
- Data residency options if you have jurisdictional requirements
- Uptime SLA, and whether an outage blocks your merges
- What is retained after analysis, and for how long
- Certifications backing the vendor's own security claims
Related terms
FAQ
What is Cloud / SaaS?
The vendor hosts and operates the tool; your code is analysed on their infrastructure.
How many tools support Cloud / SaaS?
20 of the 20 tools tracked in this directory support Cloud / SaaS, including Codacy, Aikido, ChatGPT / Codex, Checkmarx One, Claude Code. Support is not the same as parity, since some implementations are narrower in scope, gated to a higher plan tier, or maintained only for existing customers. The note under each tool is what its own documentation describes.
What should you look for in Cloud / SaaS?
Data residency options if you have jurisdictional requirements. Uptime SLA, and whether an outage blocks your merges. What is retained after analysis, and for how long. Certifications backing the vendor's own security claims.