Features/Understand and fix

Code Scan

Find what’s wrong before your users do.

Connect GitHub, pick a branch, and get a report on bugs, security vulnerabilities and code smells in minutes. Then ask Quanta to explain any of it.

3
kinds of issue: bugs, vulnerabilities, smells
5
severity levels, Blocker to Info
Live
progress while it scans

AI writes your code faster than anyone can review it. Somewhere in there is an exposed key, and nobody has looked.

Code Scan reads every line.

01

Connect, pick a branch, scan.

Install the Rectify GitHub App with read-only access, choose a repository and a branch, and scan the whole repo. Progress shows live, from queued to fetched, analysed and processed.

Code Scan: connect GitHub to scan for vulnerabilities, bugs and maintainability
02

A report you can act on.

Summary tiles for bugs, vulnerabilities and code smells, with quality ratings, duplication and lines of code stored for every scan. Browse issues by severity, from Blocker to Info, by type or by search. Open any issue to see the rule, the root cause, how to fix it and the code around it.

CriticalHardcoded secret in billing.tsVulnerability
RuleSecrets must not be hardcodedFilelib/billing.ts:42

40export async function charge(cart) {

41 const total = sum(cart.items)

42 const stripe = new Stripe("sk_live_51NcX…")

43 return stripe.charges.create({ amount: total })

Root cause

A live Stripe key is committed to the repository, so anyone with read access can use it.

How to fix

Move it to an environment variable such as STRIPE_SECRET_KEY, then rotate the key.

03

Ask Quanta about it.

Quanta shows the top issues, starts a new scan and builds a PDF report you can share with the team. AI assistants connected over MCP, like Cursor and Claude Code, can start scans and read the results too.

A quality gate with counts of bugs, vulnerabilities and code smells

Ask Quanta

Don’t click through it. Just ask.

Ask in plain English and Quanta does the work. Anything that changes your data waits for a person to approve it.

QuantaOn shift

What’s the worst thing in my code right now?

One critical vulnerability: an API key exposed in lib/billing.ts, line 42. Then two major bugs in the sign-in flow. Want the details?

Ask Quanta to do anything

Everything in it

The details, all of them.

GitHub AppRead-only access, set up in about a minute
Any branchScan the whole repository
Live progressQueued, fetch, analyse, process
Summary tilesBugs, vulnerabilities and code smells
Quality ratingsPlus duplication and lines of code
SeverityBlocker, Critical, Major, Minor, Info
Issue detailRule, root cause, fix and source
Search and filterBy severity, type or text
PDF reportsGenerated by Quanta
Over MCPStart scans from your editor

Give your SaaS its first hire.

Free for 14 days. Set up in about two minutes.