The security control plane for AI-assisted development

Your AI ships code.
Prove it.

Every run: cost and grade. Every merged PR: a signed record.

Up in about a minute · free forever for one developer · code stays local

How it works

Declare. Watch. Guard. Prove.

AI writes the code: who checks? RepoOps closes the loop in four steps, from the intent you gave to the record you can verify.

01

Declare

Set the rules your AI must follow. Autonomy zones stop and ask before expensive actions.

loop contractautonomy zones
02

Watch

Every session logged with its cost, across every agent your team runs, not just one. Quality scored on CI, reverts, and churn.

telemetryagent tracesmulti-tool
03

Guard

Gates catch bad changes before merge. Alerts fire when a run drifts below baseline.

incidentsquiet-failure alerts
04

Prove

A tamper evident record of every run: an HMAC signed chain by default, and storable as real git objects (opt in) so it travels with the repo. Trace any incident back to its prompt.

ledgerprod to promptgit-native
Why RepoOps

Check our math

Numbers you can check

These come from the real shipped accountability code run over a committed synthetic fixture, recorded in a checked-in results file. Same fixture in, same numbers out. Reproducible math, not numbers we made up.

repoops bench
75%

Defects attributed

9 of 12 seeded defects traced back to their cause. The merge, the session, the prompt.

100%

Recurrences prevented

12 of 12 recurrence attempts blocked before merge. Each fix becomes a standing rule.

$24.55

Dollars saved

Priced from the fixture run's own token usage, not a projection. Priced 6, unpriced 2, of 12 prevention events, so the honest coverage shows.

Source: docs/benchmarks/accountability-results.json, produced by npm run bench:accountability over the committed accountability-v1 fixture (8 sessions, 12 seeded defects, 20 recurrence attempts, 12 of them true). The fixture is synthetic, so these are reproducible measurements of the code, not measured real-world rates.

See how we prove it

Cost, attributed

Which PR. Which prompt. Which bug.

Others report a monthly bill. RepoOps ties every dollar to the PR it shipped, the prompt that spent it, and the recurrence it prevented. Each saving lands as a pull request, then gets measured after it merges.

Cost per PR

Every merged pull request gets priced, then drills open: the PR, its sessions, the prompts, the dollars. When there is nothing to attribute yet, it says so, it never shows a made-up number.

Savings as PRs

Better defaults, smarter routing, warm caches. Each proposed as a PR, then proven.

ROI guard

Flags savings that hurt quality. A bad trade gets a revert notice.

No caps by default

Spend advice reaches engineers as proposals, so nothing throttles your team out of the box. Hard budget caps and the fleet kill-switch ship, and stay off until an operator arms them.

Invoices you can check

Billing Guard recomputes what each day should have cost from your own telemetry and a versioned rate card, then flags the gap against the provider's bill. Nine detectors, and every flagged day exports an evidence bundle you can attach to a dispute. See Billing Guard

See spend proof

Memory

Memory you can trust

Anyone can generate a wiki. RepoOps proves one: every page cited, its freshness gated, its lessons scored.

Descriptive

verified

A generated wiki where every claim cites its source files, and CI checks those citations against HEAD. Each page carries a verified-fresh badge.

Experiential

only RepoOps

Lessons, errors, decisions, and causal links, learned from what actually happened and enforced back into every agent session.

Proactive

only RepoOps

Connectors can fill your personal brain on a schedule, and session briefings deliver it where you already work.

Lessons write back

The top-ranked fixes land in CLAUDE.md automatically, the rest stay on the Lessons tab. Recurring fixes become proposed prevention rules.

Team brain

Every member's lessons pool into one shared brain, deduped by content, each carrying the repo it came from and how many teammates hit the same thing. A new teammate starts with everything the team already learned, not a blank page.

Brain marketplace

Publish a lesson pack, a loop, or an eval bar to the marketplace, or install a brain template or skill as a staged proposal you review and approve before it lands. Your hardest-won lessons become something the whole community can build on.

publishinstallone command
Example
SessionStart · repo-dashboard
Lesson: re-check the branch between staging and commit (prevented 4x)
Personal: Acme thread "memory rollout" awaits your reply (2d)
Wiki: architecture/brain-and-mcp.md verified fresh · 0 commits behind
See memory and brain

Local-first control

Your code stays. The controls are yours to arm.

No trace store in someone else's cloud. Plenty of tools run locally now; what this local record buys you is the reconciled dollar on the merged PR, authorship signed with your own key, and each defect's lesson blocking its own recurrence.

No cloud trace store

Sessions, costs, and lessons land in local files you own. Your model key lives in your local data directory, not on our servers.

on your machinefiles you own

Opt-in, redacted sync

Cloud sync, team rollup, and raw-fidelity upload are off by default. Turn one on and it ships redacted metadata, never your source.

Controls you arm

Move a detector to enforcing and a dangerous tool call is blocked before it runs. Kill-switch a live run. A local broker can hand your agent a short-lived token instead of the real key. Off until you arm them.

enforcecontainsecret broker

Evidence for your audit

Map your signals to SOC 2, ISO 42001, NIST AI RMF, and EU AI Act controls, and export an audit-ready pack backed by the attestation trail. Evidence for your audit, not a certificate we hold.

compliance export

Enforce locally, govern centrally, at the Claude Code and MCP tool-call boundary. Prompt injection is unsolved at the model layer, so these controls contain blast radius, they do not claim to stop every attack.

See how control works

Pricing

Free where it matters

The full accountability loop is free and local, forever. Paid tiers add hosting, team rollup, and managed identity.

Solo

Free forever
For one dev, all local. Your code never leaves your machine.
  • The full accountability loop, intent to record
  • Caused-by trail + blast radius
  • Lessons and a brain that survives every session
  • Keyless local semantic search + local MCP
  • Bring your own model key
Install

Solo Hosted

$25 / mo
Your data in the cloud, one user.
  • Everything in Solo
  • Hosted dashboard at repoops.ai/team
  • Retained hosted history + backups
  • Brain + telemetry sync for one user
Start

Team

Most popular
$50 / seat / mo
For teams and orgs. Every member's lessons pool into one shared brain.
  • Everything in Solo Hosted
  • Cross-repo + cross-developer cost rollup
  • Incidents attributed to the prompt that caused them
  • Governance rollup + budget alerts
  • Spend Efficiency scorecard + proposers
Get Team

Enterprise

Custom contact sales
For identity-managed orgs. Every repo's agent cost and open risk in one rollup.
  • Everything in Team
  • SSO: Google / SAML / OIDC
  • SCIM provisioning
  • Audit + compliance export
  • Org admin console
Contact sales

Get started

Running in about a minute

Verify your email once, then install. The app itself is free forever, and your first receipts appear on the first run.

1

Install

One command. Approve the sign-in in your browser, and the installer downloads. Free, and local by default.

2

Run your agent

RepoOps records everything automatically. No workflow changes for your team.

3

Check the receipts

Open the dashboard for every run. Priced, graded, and on the record.

Install free