What is Hyrax?
Clean code in. Clean PRs out. Hyrax reads the entire codebase, runs a multi-agent audit to surface bugs and security issues, executes the change through 13-step verification, opens the pull request, and closes the Linear ticket. You review and merge every PR. Scan and Resolve run continuously - not triggered by a PR, not waiting for an incident.
How is Hyrax different from a PR review tool?
PR review tools wait for a pull request and post comments. A developer still has to triage every comment, write the change, push it, get another review, and close the ticket. Hyrax starts before the PR exists. It scans the full codebase, surfaces issues that have never appeared in a diff, executes the change autonomously, and closes the loop. Comments are not the output. Closed tickets are.
How is Hyrax different from a static analysis tool?
Static analysis tools surface issues and generate a report. A developer triages every issue and does the work. Hyrax surfaces issues, creates the ticket, executes the change, and closes the ticket. Static analysis is a reporting layer. Hyrax is an execution layer.
What does Discovery do?
Discovery reads the entire codebase and builds a complete application profile: what type of application it is, its architecture, the conventions the team uses, and how-to guides derived from the code itself. This context is committed to the repo via PR as `HYRAX.md` plus a `.hyrax/` directory, so every developer's IDE AI session (Cursor, Copilot, Claude Code) loads full codebase context automatically. Discovery runs once. Every audit and resolve that follows uses it.
How does PR review work?
Every change ships as a pull request with the [Hyrax] prefix. Automated review runs on every opened PR, posts a maintained comment that updates with each commit, uses domain-specific checklists based on the files changed, and can block merge on must-resolve issues. You get up to 100 PR reviews a month for free.
Is Hyrax a security tool?
Security is one of six audit domains. Hyrax's Security agent covers auth patterns, input validation, hardening, privacy, compliance signals, and vulnerability patterns. It is not a dependency scanner (SCA) - it does not scan `package.json` or `go.mod` for vulnerable versions. It is an AI audit-and-execution platform where security is a first-class domain alongside correctness, maintainability, performance, architecture, and operations.
What programming languages does Hyrax support?
Hyrax's audit covers 18+ languages including Python, TypeScript, JavaScript, Go, Rust, Java, Kotlin, Ruby, PHP, Swift, C, and C++. Autonomous upgrade execution targets the languages where execution accuracy is reliable. Language support expands continuously.
How accurate is the audit? What is the false positive rate?
Hyrax's three-step audit is designed to reduce false positives at each stage. Scanner issues are capped at medium severity until LLM-verified - pattern matches alone cannot surface a critical or high alert. The six-agent step requires both severity and confidence fields on every issue. Low-confidence issues are surfaced for human review rather than executed. High false-positive issues accumulate in the review queue, not the execution pipeline.
Can I trust Hyrax to run changes autonomously?
Every change runs through 13 quality stages before the PR opens: isolated worktree, baseline tests, resolve agent, diff size guard (20 files / 2,000 lines max), test regression, build, auto-format, lint, cross-project test, scanner loop (Hyrax scans its own resolve), review loop, post-change audit, and PR opened. If any stage fails, nothing ships. Review and merge rights are retained on every PR. Hyrax cannot self-merge.
What is the 13-step verification in detail?
In order: (1) Isolated worktree - dedicated Git worktree for the change. (2) Baseline tests - existing tests recorded before any change. (3) Resolve agent - convention-matched to the codebase. (4) Diff size guard - rejects changes touching more than 20 files or 2,000 lines. (5) Test regression - every previously passing test must still pass. (6) Build - the repo must build after the change. (7) Auto-format - changed files formatted to config. (8) Lint - linted to config. (9) Cross-project test - validates resolve doesn't break dependent code. (10) Scanner loop - Hyrax scans its own resolve for new issues. (11) Review loop - a second agent reviews the change. (12) Post-change audit - confirms the original issue is resolved. (13) PR opened - opens the pull request. PR opens only if all 13 steps pass.
What happens if a change fails a quality gate?
Nothing is pushed. Hyrax surfaces an escalation signal with the specific gate that failed, the reason, and a suggested next step: retry, reduce scope, or route to a human reviewer. Control returns with a complete explanation of what failed and why.
What if Hyrax's upgrade is technically correct but wrong for our codebase?
Discovery maps conventions before any resolve runs - naming patterns, test structure, API patterns, error handling styles. Changes are required to match the codebase's conventions, not produce generic solutions. If a PR is rejected, that feedback informs the change policy. Repeated rejections of a change class route that class to human review.
Which issues does Hyrax execute autonomously vs. surface for review?
High-severity, high-confidence issues execute autonomously. Low-confidence issues, large-scope issues (above the diff size guard threshold), and issues in configured review-only categories are surfaced as actionable work items rather than executed. The thresholds are configurable via the change policy. The security team or engineering lead owns the policy configuration.
Does Hyrax execute changes on production branches?
No. Hyrax opens PRs against the configured target branch - typically `main` or a staging branch. It never pushes directly to production branches and never self-merges. Every change requires a human to approve and merge the PR.
How much does it cost to run Hyrax?
Hyrax provides all AI compute - no separate AI account or API key needed. Token costs are passed through at cost and appear on the Hyrax invoice. Discovery: ~$5-10, runs once. Full audit: ~$1-35 depending on codebase size; most mid-sized repos land between $3-8. Resolve: ~$1-10 per resolve. Hyrax charges a platform subscription fee for access on top of compute.
What is the free tier?
Full access to Hyrax features, a $30 starter credit, $10/month ongoing credit, and up to 100 PR reviews a month for free. Credits cover audits, changes, and other Hyrax workflows. No commitment and no card required.
What are the plans?
Two plans. Free: full access to Hyrax, a $30 starter credit, $10/month ongoing credit, and up to 100 PR reviews a month for free, no card required. Paid: $30 per user per month, where each paid user gets $30/month of credits. Credits meter usage across audits, changes, and reviews; there are no feature walls.
How do paid seats work?
Paid seats are $30 per user per month, and each paid user gets $30/month of credits. You only pay for developers who want deeper access - the workspace still gets up to 100 PR reviews a month for free.
What AI models does Hyrax use?
Hyrax uses Anthropic's Claude models via Amazon Bedrock. The multi-agent audit runs parallel agent groups. Model selection is managed by Hyrax - configuration is not required.
How does pricing scale with multiple repos?
Compute cost scales with the number of repos connected and their activity - specifically with issue volume and upgrade execution frequency. The platform subscription covers org-level access. Discovery is a one-time cost per repo; subsequent audits and resolves are pay-per-use on compute.
How do I get started?
Install the GitHub App on the repo. Hyrax runs Discovery immediately - reads the codebase, builds the application profile, generates `HYRAX.md` and the `.hyrax/` directory, and opens the first PR. No configuration required before first value.
What source control platforms does Hyrax support?
GitHub at launch.
Does Hyrax integrate with Linear?
Linear is supported at launch with full ticket lifecycle closure - issue opens ticket, resolve merges, ticket closes automatically. Jira is on the roadmap. Ticket lifecycle closure ensures issues don't live in a scanner dashboard disconnected from the project management workflow.
Does Hyrax replace existing SAST scanners?
No. Hyrax's Scan phase runs its own SAST-grade scanning - but it's designed to complement existing scanners, not replace them. SCA (dependency scanning), container scanning, and IaC scanning are separate capabilities owned by specialized tools. Hyrax handles source code security and quality; existing SCA and container tools continue to own their surfaces. If using Snyk or SonarQube, Hyrax is the remediation layer for what they surface.
How does Hyrax affect CI/CD pipelines?
Hyrax runs as a GitHub App alongside the existing pipeline - it doesn't modify CI/CD steps. It opens PRs; the pipeline runs on those PRs exactly as it does on human-authored ones. Continuous scanning and execution happen asynchronously, not in the critical path of builds.
We don't have a SAST scanner yet. Can Hyrax be the first security tool?
Yes. Hyrax runs its own scanning from the first audit. A separate SAST tool is not required first. Install the GitHub App, connect the repo, and Hyrax begins scanning immediately.
How long does setup take?
GitHub App installation takes two minutes. Discovery runs automatically and completes in 10-20 minutes depending on codebase size. The first audit can start immediately after Discovery. No configuration, no rule authoring, no pre-tuning phase before first value.
Does code leave infrastructure?
Code goes to the AI provider (Claude via AWS Bedrock) for analysis. Hyrax receives structured issue data from LLM calls, not raw code content. No codebase content is stored by Hyrax beyond what is needed to execute the current workflow.
Does Hyrax produce audit evidence for compliance assessments?
Yes. Every change Hyrax executes produces a PR with a complete audit trail: issue type, severity, code diff, test suite results, approver identity, and merge timestamp. This evidence satisfies change management documentation requirements for PCI-DSS (Req 6.5), SOC 2 Type II (CC8.1), HIPAA Technical Safeguards, and SOX IT General Controls without additional tooling or manual assembly.
Can Hyrax help with PCI-DSS 4.0 compliance?
PCI-DSS 4.0 Req 6.2 requires secure coding practices including automated scanning for in-scope payment systems. Req 6.4 requires critical vulnerabilities to be remediated within one month of discovery. Req 6.5 requires change and tamper-detection mechanisms. Hyrax addresses all three: continuous SAST-grade scanning, autonomous upgrade execution that doesn't wait for sprint allocation, and a PR-based audit trail for every change.
Can Hyrax help with SOC 2 Type II?
SOC 2 Trust Services Criteria CC8.1 requires change management controls including authorization and testing before deployment. Every Hyrax upgrade is a PR - it cannot self-merge. The developer or lead who merges is the approving party. The issue, upgrade, test results, and merge event are all logged. CC6.1 (logical access controls) and CC7.2 (system monitoring) are addressed by Hyrax's continuous scanning and PR-based change controls.
What is Hyrax's own security posture?
Code is processed in isolated environments and never used for training. All AI inference runs on AWS Bedrock.
Can we configure what data Hyrax can access within repos?
Hyrax operates on the repos connected via the GitHub App. Which repos are connected can be limited. The change policy controls which issues execute autonomously versus surface for human review. Fine-grained file-level access restrictions are on the roadmap.
We already use Snyk. Why add Hyrax?
Snyk is a detection platform - best-in-class SCA with a database that leads NVD by 47 days, plus SAST, container, and IaC scanning. Snyk surfaces issues. Hyrax closes them. If the Snyk SAST queue is growing faster than the team resolves it, Hyrax addresses that directly. Many teams run both: Snyk for detection and compliance reporting, Hyrax for source code remediation.
We already use SonarQube. Why add Hyrax?
SonarQube is a mature detection platform with 40+ language coverage, Quality Gates, and enterprise compliance dashboards. Its Remediation Agent is available on one configuration: SonarQube Cloud Enterprise, GitHub only. Hyrax works regardless of SonarQube edition and runs continuously - not only when a PR introduces 2+ fixable issues. The pattern: SonarQube for detection and compliance reporting, Hyrax for remediation.
We already use GitHub Copilot Code Review. Why add Hyrax?
Copilot Code Review reviews PRs and leaves inline comments - developers apply them manually. A 2025 peer-reviewed study surfaced fewer than 20 total security comments across 7 vulnerability datasets. Copilot Autofix covers CodeQL alerts only, capped at 20 per PR. Hyrax runs continuously, catches issues before PRs open, and executes changes without a manual trigger.
We already use CodeRabbit. Why add Hyrax?
CodeRabbit manages incoming changes: it triages PRs, explains large diffs, reviews code, and its Security product monitors shipped code. Every issue still lands on your team as a judgment call. Hyrax doesn't add to that queue; it closes issues with verified upgrade PRs across six categories. They don't conflict - CodeRabbit judges the changes others propose, Hyrax proposes its own.
Can Hyrax work alongside existing tools?
Hyrax is designed to complement, not replace. Snyk for SCA, SonarQube for enterprise compliance dashboards, CodeRabbit for PR triage and review - all of these run in parallel with Hyrax. Hyrax's job is to close the issues those tools surface and to continuously reduce the source code debt that accumulates between sprint cycles.
How is Hyrax different from AI coding assistants like Cursor or GitHub Copilot?
AI coding assistants help developers write new code faster. Hyrax operates on existing code - scanning what's already there, issue what's wrong, and resolving it autonomously. The two are complementary: assistants accelerate new code creation; Hyrax oversees the accumulating codebase. They don't overlap in function.