Greptile

AI pull request reviewer that indexes the whole repository graph for context and can execute PR code in a sandbox.

$30/seat/moLast verified 2026-09-06

Deployment

Cloud · Self-Hosted · Air-Gapped

Languages

10+

Pricing model

Per contributing developer, Usage-based credits, Quote-based / Enterprise

Free tier

Yes

Workflow coverage

Where in the development lifecycle Greptile operates.

Real-Time IDE FeedbackPartial

MCP server and Claude Code plugin view and resolve comments in IDE; no as-you-type analysis

AI Agent Guardrail (MCP)Yes

MCP server with 11 tools, Claude Code plugin, check-pr and greploop skills, agent-aware CLI

Local CLI / Pre-CommitYes

greptile review runs full-fidelity local branch review in ~60s; exit codes usable in hooks

PR Inline ReviewYes

Inline comments with severity, type and suggested fix on every PR; 1 credit each

Merge Gate BlockingPartial

config.json statusCheck posts a GitHub status check with review result; no fail-state/required-check documented

Full Repo ScanPartial

Indexes entire repo graph and knowledge base as review context; findings remain PR-scoped

Scheduled / Continuous RescanNo

Config reference documents triggerOnUpdates (re-run on PR update) as the only trigger; no cron/schedule option

Runtime / Production MonitoringNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Analysis & detection

Every detection and code-analysis capability tracked for Greptile.

SASTYes

Opengrep rule-based pattern-matching SAST engine plus AI review catch SQLi, SSRF, injection and more

Taint / Data-Flow AnalysisNo

Security Check names pattern-based Opengrep rules and SCA only; no interfile taint/dataflow tracing described

Secrets DetectionYes

Custom rule can disallow hardcoded secrets; CLI withholds secret-looking files unless --include

Secrets ValidationNo

Security Check enumerates its scan types; only static secrets detection is described, no live validation

SCA (Dependencies)Yes

SCA scan type in Security Check reviews dependencies against known vulnerability databases for CVEs

Reachability AnalysisPartial

Repo graph surfaces impacted callers and contracts of changed code; not dependency-vulnerability reachability

Malicious Package DetectionNo

SCA described only as CVE-checking against vulnerability databases; no typosquat/malicious package detection

License ComplianceNo

Security Check page describes SCA as CVE-checking only; no license identification or policy enforcement

SBOM GenerationNo

Security Check page enumerates 3 scan types (SAST, SCA, AI); no SBOM/CycloneDX/SPDX export mentioned

IaC ScanningNo

Security Check's 3 scan types cover code and dependencies only; no Terraform/CloudFormation/K8s misconfig scanning

Container ScanningNo

Security Check's scan types cover code and dependencies only; no container image or base-image CVE scanning

Cloud Posture (CSPM)No

Security Check reviews pull requests only; no live cloud account configuration scanning described

DAST / API ScanningNo

Security Check is static PR-time scanning only; no running-app or API endpoint exercise described

Code Smells & MaintainabilityYes

style and syntax comment types cover naming, formatting, structural consistency, language best practice

Complexity MetricsPartial

Custom rules can cap function length and complexity; no computed complexity metrics reported

Duplication DetectionNo

Analytics dashboard docs list 5 named metrics; no duplication/clone detection metric documented

Dead / Unused CodeNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Test Coverage TrackingNo

Analytics dashboard docs list 5 named metrics (PRs reviewed, merge time, addressed rate, bugs, upvotes); no coverage

Diff / New-Code CoverageNo

Analytics dashboard docs list 5 named metrics; no new-code or diff coverage metric documented

Architecture GovernanceYes

Custom rules enforce architecture patterns (no DB models in controllers, repository pattern); rule-based only

Technical Debt QuantificationNo

Analytics dashboard docs list 5 named metrics; no remediation-effort or cost quantification documented

Behavioral Delivery AnalyticsPartial

Dashboard tracks PRs reviewed, critical bugs, addressed rate, time to merge, upvote ratio

AI Logic Bug DetectionYes

logic comment type for logic errors and algorithmic problems; T-Rex confirms runtime bugs

PR Summaries & WalkthroughsYes

PR summary with 0-5 confidence score, per-file issues, auto-generated sequence diagrams or flowcharts

Custom Rule AuthoringYes

Dashboard rules plus .greptile/ folder (config.json, rules.md, files.json) and legacy greptile.json

Autofix SuggestionsYes

Most inline comments include an applicable code suggestion

Autofix via Agentic PRsNo

Fix with your Agent hands issues to Claude Code, Codex, Conductor, Cursor, Devin; no native fix PRs

AI Triage / False-Positive FilteringYes

Learning suppresses consistently-ignored comment types; security, leaks, null derefs never suppressed

Monorepo SupportYes

Cascading .greptile/ per-directory config lets monorepo packages own strictness, rules and filters

AI capabilities

AI Review EngineYes

Codebase-graph-grounded AI review posting summary, confidence score and inline comments

BYO Model / BYOKYesEnterprise

Any OpenAI-compatible or custom LLM (Anthropic, OpenAI, Azure OpenAI, Bedrock); self-hosted only

MCP ServerYes

Hosted MCP server at api.greptile.com/mcp, API-key authenticated, exposing 11 tools

AI Usage GovernanceNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Chat With ReviewerYes

Reply to comments for follow-ups; CLI offers conversational Chat with Greptile

Learns From FeedbackYes

Learns from PR comments, replies, thumbs reactions and commit-based checks of addressed comments

Code Excluded From TrainingYes

Opt out of anonymized cloud training; self-hosted code never trained on unless configured.

Models used

Anthropic Claude 3.7 Sonnet (recommended default)OpenAI Embeddings (recommended default)

Compliance & governance

Audit LogsYesEnterprise

Audit logging referenced as an enterprise feature; no scope, retention or export detail

SSO / SAMLYesEnterprise

SAML SSO via bundled BoxyHQ Jackson service, documented for self-hosted deployments

Role-Based Access ControlYes

Organization Admin/Member roles; per-team Admin/Member roles in multi-team workspaces

Compliance Reporting ExportsNo

Trust Center and Enterprise page list security controls and certifications; no audit-ready framework export feature

Certifications

SOC 2 Type IIHIPAAGDPR

Integrations

GitHubYes
GitHub Enterprise ServerYes
GitLabYes
GitLab Self-ManagedYes
BitbucketNo
Bitbucket Data CenterNo
Azure DevOpsNo
REST APIYes
CLIYes
WebhooksYes

IDEs

CursorVS CodeClaude Code (CLI)Codex (CLI)WindsurfClaude Desktop

Issue trackers

Jira (read-only, one authorized Atlassian site)Linear (read-only, scopable to teams)Notion (named as a context source, no setup docs in source)Datadog (named as a context source, no setup docs in source)

Chat & notifications

Slack (shared support channel with Greptile engineering; not described as a notification integration)

Pricing & plans

$30/seat/month (no annual discount published; custom pricing available for annual/multi-year contracts)

Minimum seats: None documented for Pro (billed per seat, no stated floor); Starter is capped at 1 active developer

Trial: 14-day free trial with no payment method or credit card required (cloud sign-up and CLI onboarding); no free trials for self-hosted, but 100% refund within the first 30 days

StarterFreeIndividual developers
  • 50 credits per month
  • Unlimited repositories
  • Codebase-aware PR review
  • Free tier extended in full to open-source and public repos
  • Only 1 active developer
  • 50 credits per month (1 credit per standard review, 3 per T-Rex review)
  • No self-hosting, SSO or custom compliance controls
Pro$30/seat/monthTeams
  • 50 credits included per seat
  • Full codebase-aware review with confidence scores and diagrams
  • Custom rules, learning system, analytics dashboard
  • MCP server, CLI, coding-agent handoff
  • Flex usage for overage at $1/credit
  • Credits are charged to the PR author, not pooled across the team
  • Overage billed at $1/credit unless flex usage is capped
  • T-Rex reviews cost 3 credits each
  • No self-hosting or SSO/SAML
EnterpriseCustom pricingOrganizations at scale, data-sovereignty and air-gapped requirements
  • Self-hosting via Docker Compose or Kubernetes, including air-gapped
  • SSO/SAML
  • Custom deployment and compliance controls
  • Bring-your-own-LLM and custom code host integrations
  • Custom credit allocation
  • Quote-only
  • No free trial for self-hosted
  • Refunds: 100% within 30 days, pro-rated in months 2-4 for upfront annual payments only
  • Self-hosted CLI reviews need deployments from 2026-05-14 or later

Who it's for

Starter covers 1 active developer; self-hosted sizing guidance is Docker Compose up to 100 developers and Kubernetes for 100+ developers

Notable strengths

  • Whole-repository graph plus self-updating knowledge base as review context, not diff-only
  • T-Rex sandbox execution writes and runs tests and browser flows, attaching logs, screenshots and videos
  • Cascading per-directory .greptile/ configuration with explicit merge and precedence semantics
  • Learning system with a hard never-suppress floor for security, memory leaks and null dereferences
  • SOC 2 Type II, HIPAA and GDPR claimed alongside air-gapped Docker Compose and Kubernetes self-hosting

Notable limitations

  • Native review integration covers GitHub and GitLab only; Bitbucket and Azure DevOps appear solely as MCP lookup values
  • No SCA, SBOM, license, container, IaC or dedicated secrets scanning documented
  • Credit metering per PR author: 1 credit per review, 3 per T-Rex review, $1/credit overage
  • T-Rex runtime validation and auto-approve are beta; no free trial for self-hosted deployments
  • Self-hosted ships no monitoring stack, and CLI reviews require deployments from 2026-05-14 or later

Similar tools

Other PR Review tools in the directory.

FAQ

When should you choose Greptile?

Greptile best fits Indie developers, Startups, Mid-market teams, Enterprise, Regulated industries, Starter covers 1 active developer; self-hosted sizing guidance is Docker Compose up to 100 developers and Kubernetes for 100+ developers. Whole-repository graph plus self-updating knowledge base as review context, not diff-only

What languages does Greptile support?

Greptile supports 10+ languages and frameworks, including Python, JavaScript, TypeScript, Go, Java, Ruby, Elixir, Rust, PHP, C++.

What does Greptile integrate with?

Greptile integrates with GitHub, GitHub Enterprise Server, GitLab, GitLab Self-Managed for source control, and IDEs including Cursor, VS Code, Claude Code (CLI), Codex (CLI), Windsurf, and 1 more.

What tools are similar to Greptile?

Similar PR Review tools tracked here include CodeAnt AI, CodeRabbit, Cursor (Bugbot), Qodo.

What are Greptile's plans and pricing?

Greptile offers a free tier, with paid plans starting around $30/seat/mo; enterprise pricing is quote-only.