
Codebase scans are in beta.
Issues that codebase scans find
Codebase scans focus on high-impact issues:- Security vulnerabilities: authentication bypasses, injection points, exposed secrets
- Data integrity risks: race conditions that corrupt state, missing validations, unsafe database operations
- Business logic flaws: billing edge cases that lose money, incorrect permission checks, broken invariants
- Dependency vulnerabilities: known CVEs in your supply chain, unsafe version ranges
How it works
cubic clones your repository into an isolated sandbox and deploys thousands of agents that explore your codebase in parallel. These agents:- Navigate across files to trace data flows
- Follow call chains to verify issues
- Check external documentation (framework docs, security advisories)
- Test multiple hypotheses before confirming findings
- Use your repository’s AI Wiki to understand product context and prioritize investigations
- Maps your repository structure
- Checks for an up-to-date AI Wiki—if one doesn’t exist, cubic generates it automatically
- Deploys thousands of parallel agents informed by the wiki’s understanding of your product
- Investigates suspicious patterns
- Deduplicates findings
- Scores by severity and confidence
Starting a scan
Codebase scans are available by request. Once enabled:- Navigate to your repository’s Codebase scan page
- Click Start scan
- Continue working. You’ll be notified when results arrive
Working with results
Every finding appears in a clean table with three key signals:
- Score: severity × confidence, so you focus on what matters
- Status: track as Open, Resolved, or Dismissed
- Summary: what’s wrong in plain language
- Full explanation with code context
- AI sidebar to explore the finding interactively
- Copy prompt button for a ready-to-paste fix prompt

When to run scans
Think of scans as periodic deep inspection, not continuous monitoring:- Before major releases: catch issues that accumulated during development
- After architecture changes: verify new patterns don’t introduce vulnerabilities
- Post-dependency updates: check for newly exposed attack surface
- Monthly or quarterly: maintain baseline security posture
Custom scans
Need deeper security analysis? Want higher sensitivity for financial code? Require specific compliance checks? Scans are tunable. Reach out and cubic can configure scans for your specific risk profile and requirements.FAQ
Will this slow down our PR reviews?
Will this slow down our PR reviews?
No. PR reviews remain fast and inline. Scans run completely separately in the background.
How accurate are the findings?
How accurate are the findings?
High signal-to-noise ratio. Teams report immediately actionable results, often more precise than
traditional security tools.
What's the actual runtime?
What's the actual runtime?
Small repos: 2-6 hours. Medium: 6-12 hours. Large enterprise codebases: 24-48 hours. You get
progress updates throughout.
Is this replacing our security tools?
Is this replacing our security tools?
It complements them. cubic finds logical flaws and subtle bugs that pattern-matching tools miss.
How does pricing work?
How does pricing work?
Scans are included in your cubic subscription. No per-scan charges. Run as many as you need.