# Cq · Code Review — element 7 of 58

> A second pair of tireless eyes. Turns AI-speed code into trustworthy code.

- **Group:** 2 · Build
- **Necessity:** Optional
- **Price band:** $ · under $30/mo
- **Maturity:** Emerging
- **Edition:** v2026.Q3 · verified 2026-09-13

## Leading tools (v2026.Q3)

- **CodeRabbit** — the category leader
- **Copilot code review** — one in five reviews
- **Graphite** — stacked review flow
- **Greptile** — full-codebase context
- **Bugbot** — cursor-native bug hunter

## Our take

AI code carries a 2.7x vulnerability rate. Review is the tax you pay for velocity — automate the tax.

## Combines with

Ca, Ev


## The top 5 — deep dossier (verified 2026-09-13)

CodeRabbit, for most teams — the category it effectively created still belongs to it: $40M ARR by April 2026 (up 700% YoY), 15,000+ customers, and the most-installed AI app on both GitHub and GitLab. The context that makes this element non-optional: AI now writes roughly half of committed code and its security pass rate has stalled at 56% (Veracode, Jul 2026). Copilot code review wins when you already pay for Copilot — 60M reviews and 1 in 5 of all GitHub reviews is distribution nobody matches; Graphite when the review process itself (stacks, merge queue) is the bottleneck; Greptile when you want the deepest full-codebase context with the least noise; Bugbot when your team lives in Cursor and wants a pure bug-hunter on the diff.

1. **CodeRabbit** (CodeRabbit Inc.) — Free tier (PR summaries, IDE/CLI reviews) · Pro $24/user/mo · Pro Plus $48 · Enterprise custom (self-host). Best for: Teams shipping AI-speed code who want line-by-line PR review with linters, security checks, and chat — installed in minutes on GitHub/GitLab/Azure/Bitbucket. Why: The standalone-category leader by every measure: ~$40M ARR in April 2026, up 700% from ~$5M a year earlier (Sacra est.); 15,000+ customers, 6M repositories, 75M defects found; most-installed AI app on GitHub and GitLab. The $60M Series B (Sep 2025, $550M valuation) was pitched explicitly on vibe-coding cleanup demand — the same 2.7x-vulnerability wave this element exists to tax. Watch: Comment volume is the perennial complaint — tuning is required before it feels like a colleague rather than a lint firehose. ARR figures are Sacra estimates, not audited. Bundled reviewers (Copilot, Bugbot, Claude Code Review) are commoditizing baseline review from above. [https://www.coderabbit.ai](https://www.coderabbit.ai)
2. **Copilot code review** (Microsoft / GitHub) — Included in all paid Copilot plans (Pro $10/mo → Enterprise $39/user) · consumes AI credits per review · not on Copilot Free. Best for: Teams already paying for Copilot who want a reliable first-pass review on every PR with zero new vendors, contracts, or apps. Why: Distribution nobody can answer: 60M reviews since the April 2025 launch, 10x usage growth, and more than 1 in 5 of all code reviews on GitHub by March 2026, with 12,000+ orgs auto-reviewing every PR. Quality is climbing — 71% of reviews surface actionable feedback, and agent skills + MCP context went GA July 29, 2026. Watch: Depth trails the specialists in most independent roundups — it reviews the diff well but reads the codebase less deeply than Greptile or CodeRabbit. GitHub-only. The 2026 shift to AI-credit billing makes per-review cost opaque, and reviews are blocked when credit budgets run out. [https://github.com/features/copilot](https://github.com/features/copilot)
3. **Graphite** (Graphite → Cursor/Anysphere (Dec 2025; → SpaceX pending)) — Hobby free · Starter $20/user/mo · Team $40 (unlimited AI reviews, merge queue) · Enterprise custom. Best for: Teams who want to fix the review process, not just add a bot — stacked PRs, merge queue, and the Diamond AI reviewer in one flow. Why: The only top-5 pick that re-architects review itself: stacked PRs plus merge queue plus AI review (Diamond, launched with the $52M Accel-led Series B in March 2025 — Anthropic's Anthology Fund participated). Used by hundreds of thousands of engineers, and now the code-review arm of the Cursor empire after the December 19, 2025 acquisition — the strongest possible signal that review and generation are converging. Watch: Ownership churn squared: acquired by Cursor, which is itself being acquired by SpaceX ($60B, close expected Q3 2026). Stacked-PR workflow has a real adoption cost for teams happy with plain PRs, and unlimited AI review requires the $40 Team tier. [https://graphite.com](https://graphite.com)
4. **Greptile** (Greptile (YC W24)) — Free 50 credits/mo · Pro $30/seat incl. 50 reviews, $1/extra review · Enterprise custom (self-host, SSO). Best for: Complex codebases and monorepos — it indexes the whole repository graph so reviews catch cross-file breakage a diff-reader can't see. Why: The context-depth play: full-codebase indexing rather than diff-only review, a v3 rewrite the company says catches 3x more critical bugs than v2, and a learning system that absorbs your engineers' review comments. Benchmark led the $25M Series A (Sep 23, 2025); customers include Brex, Substack, and PostHog, with 500M+ lines reviewed and 180k+ bugs prevented at announcement. Watch: Per-credit pricing stacks up fast on high-throughput repos ($1/review beyond the included 50). Headline bug-catch numbers are self-published, not independently benchmarked. Smallest vendor in the top 5 — procurement-sensitive orgs will notice. [https://www.greptile.com](https://www.greptile.com)
5. **Bugbot** (Cursor/Anysphere (→ SpaceX pending)) — Usage-based $1.00–1.50/review since Jun 8, 2026 (was $40/seat/mo) · individuals draw from Cursor plan usage. Best for: Cursor-native teams who want a pure bug-hunter on every PR — logic errors and edge cases, not style commentary — with one-click fixes back in the editor. Why: Rides the largest AI-coding install base on earth (Cursor: 1M+ paying users, $3B ARR by May 2026) and stays deliberately narrow: hard bugs only, with a claimed 80% resolution rate on flagged issues and a high-effort mode that finds 35% more bugs at the same precision (May 2026). The June 2026 move to $1–1.50 per review made it the cheapest credible entry point in the category. Watch: Not a full reviewer — no summaries, style, or architectural feedback; you still need review process elsewhere. Pricing model changed twice inside a year, and the SpaceX acquisition adds the same ownership uncertainty as Graphite. GitHub-focused. [https://cursor.com/bugbot](https://cursor.com/bugbot)

### How to choose
- If Coding agents are writing most of your code and PRs pile up faster than humans can read them → CodeRabbit — the fastest install-to-value in the category, then spend a week tuning its noise down. Review is the tax on AI velocity; this automates the tax.
- If You already pay for Copilot and procurement hates new vendors → Turn on Copilot code review org-wide — a 71%-actionable first pass for AI credits you already budget, with the honest caveat that it reads the diff, not your architecture.
- If Review latency is the bottleneck — big PRs rotting for days → Graphite — stacked PRs plus merge queue attacks the process, and Diamond handles the first pass. Accept the Cursor→SpaceX ownership uncertainty.
- If You run a monorepo or a gnarly legacy codebase where diff-only review misses cross-file breakage → Greptile — full-codebase indexing is the whole product; budget ~$1/review beyond the included 50.
- If You expect AI review to catch security holes → Don't — AI code stalls at a 56% security pass rate (Veracode, Jul 2026) and general reviewers are not SAST. Pair any pick with a real scanner (Snyk/Semgrep class) and, if on Claude, the free claude-code-security-review action.

### The field (23 more)

Qodo (Qodo Merge), Claude Code Review, PR-Agent, claude-code-security-review, Gemini Code Assist on GitHub (sunsetting), Ellipsis, Sourcery, Bito AI Code Review Agent, Baz, cubic, Macroscope, Entelligence, CodeAnt AI, Panto AI, Korbit AI (fading), DeepSource, Codacy, SonarQube AI Code Assurance, CodeScene, Sweep (fading), What The Diff (fading), Codeball (dead), PullRequest (acquired)

Full dossier data: https://elems.ai/e/cq.json

---
Source: [elems.ai](https://elems.ai/e/cq.html) — the periodic table of the AI-led startup. Data: https://elems.ai/elements.json (CC BY 4.0, cite elems.ai).
