# Hyrax

> Hyrax is a codebase architect for AI-native engineering teams that maps repositories, runs six-agent audits, and ships verified fixes as GitHub pull requests.

Hyrax positions itself as a "Codebase Architect" for AI-native engineering teams, sitting above AI coding assistants by governing the existing codebase rather than helping write new code. It connects to GitHub, maps the full repository into a shared context bundle (HYRAX.md + .hyrax/discovery), runs six specialized agents across security, correctness, maintainability, performance, architecture, and operations, and turns the highest-leverage findings into verified pull requests that engineers review and merge. The product launched as a Top 5 Product of the Day on Product Hunt.

## What It Is

Hyrax is an autonomous code governance platform that operates continuously on connected repositories — not triggered by pull requests, not waiting for incidents. It fills the gap between detection tools (static scanners, AI code review) and actual remediation: instead of generating a queue of comments for developers to triage, Hyrax executes the fix, runs it through a 13-step verification pipeline, and opens a merge-ready pull request. An engineer approves and merges every PR; Hyrax cannot self-merge.

## How the Four-Workflow Pipeline Works

Hyrax organizes its work into four sequential stages:

- **Scan** — Discovery clones the repo into isolated compute, runs deterministic scanners plus six reasoning agent groups across every file, and commits a HYRAX.md context bundle to the repository. Every finding is ranked P0–P3 with file and line reference.
- **Fix** — Approved findings are executed in an isolated Git worktree. The fix agent matches the repo's own conventions (naming patterns, test structure, error handling styles), then the 13-step verification gate runs: isolated worktree, baseline tests, fix agent, diff size guard (max 20 files / 2,000 lines), test regression, build, auto-format, lint, cross-project test, scanner loop, review loop, post-fix audit, and PR open. If any required step fails, nothing ships.
- **Improve** — Suggestions and advisories that fall outside the must-fix queue carry stable HYRAX-N references and sit alongside findings without clogging the execution pipeline.
- **Govern** — Automated review runs on every push, posts a maintained comment that updates with each commit, and can block merge on must-fix findings. Accepted fixes become deterministic scanner patterns, sharpening the next audit.

## Architecture and Context Model

The codebase map lives inside the repository itself as HYRAX.md and a .hyrax/discovery directory, so both human contributors and AI tools (Cursor, Copilot, Claude Code, Codex, Devin) read the same context automatically. Discovery runs once per repo and costs approximately $5–10 in compute; subsequent audits and fixes are pay-per-use. All AI inference runs on Anthropic's Claude models via AWS Bedrock in Hyrax's own account — no separate AI API key is required, and Hyrax states it does not train on customer code.

## Where It Fits in the Stack

Hyrax is designed to complement, not replace, existing tooling:

- **vs. static scanners (Snyk, SonarQube)** — those tools surface findings; Hyrax closes them. Many teams run both: detection and compliance reporting in the scanner, remediation in Hyrax.
- **vs. AI code review (CodeRabbit, Copilot Code Review)** — those tools judge changes someone else made; Hyrax proposes and verifies its own changes before a PR exists.
- **vs. AI coding assistants (Cursor, Copilot)** — assistants accelerate new code creation; Hyrax governs the accumulating codebase. The FAQ explicitly positions them as complementary.

Linear integration is supported at launch with full ticket lifecycle closure (finding opens ticket, fix merges, ticket closes). Jira is on the roadmap. GitHub is the only supported source control platform at launch.

## Compliance and Security Posture

Hyrax produces a PR-based audit trail for every fix — finding type, severity, code diff, test suite results, approver identity, and merge timestamp. The FAQ states this evidence addresses PCI-DSS 4.0 (Req 6.2, 6.4, 6.5), SOC 2 Type II (CC8.1, CC6.1, CC7.2), HIPAA Technical Safeguards, and SOX IT General Controls. The security agent covers auth patterns, input validation, hardening, privacy, compliance signals, and vulnerability patterns, but is not a dependency/SCA scanner. Code is processed in isolated environments and never used for model training.

## Language and Integration Support

The audit covers 18+ languages including Python, TypeScript, JavaScript, Go, Rust, Java, Kotlin, Ruby, PHP, Swift, C, and C++. Autonomous fix execution targets languages where execution accuracy is reliable, with support expanding continuously. Setup takes approximately two minutes for GitHub App installation plus 10–20 minutes for the initial Discovery run — no configuration, rule authoring, or pre-tuning required before first value.

## Features
- Codebase mapping via HYRAX.md and .hyrax/discovery context bundle
- Six-agent audit across security, correctness, maintainability, performance, architecture, and operations
- 13-step verification pipeline before any PR is opened
- Autonomous fix execution in isolated Git worktrees
- Verified fixes shipped as GitHub pull requests
- Automated PR review on every push with merge blocking
- Linear integration with full ticket lifecycle closure
- Findings ranked P0–P3 with file and line references
- Convention-matched fixes derived from codebase patterns
- Diff size guard (max 20 files / 2,000 lines per fix)
- Shared codebase context for AI tools (Cursor, Copilot, Claude Code)
- AWS Bedrock inference — no customer API key required
- No self-merge — engineer approves every PR
- Compliance audit trail for PCI-DSS, SOC 2, HIPAA, SOX
- 18+ language support including Python, TypeScript, Go, Rust, Java
- Up to 100 PR reviews per month on free plan
- Opt-in overage with budget caps on paid plans

## Integrations
GitHub, Linear, Cursor, GitHub Copilot, Claude Code, Codex, Devin, AWS Bedrock, Snyk (complementary), SonarQube (complementary), CodeRabbit (complementary)

## Platforms
WEB, API

## Pricing
Freemium — Free tier available with paid upgrades

## Links
- Website: https://hyrax.dev
- Documentation: https://docs.gethyrax.app/
- EveryDev.ai: https://www.everydev.ai/tools/hyrax
