What Monterva does
An automated code-health and security review for repositories written with heavy AI assistance, explained for founders rather than security engineers.
Monterva connects to a GitHub repository, reviews it with a set of established open-source analysis tools, and gives you a report you can act on: what it found, where, how confident the tooling is about each thing, what to do next — and, just as importantly, what it did not look at.
Who it is for
Founders and small teams shipping code written quickly, often with an AI assistant, without a senior security engineer on hand to read it afterwards. The report is written to be understood by the person who has to decide what to fix, not by a specialist.
What it is not
This is not a penetration test, and it is not an audit in the certification sense. Nothing here proves the absence of a problem. Monterva reports potential issues with a stated confidence and a recommended remediation, and it tells you which parts of your repository it was unable to analyse.
That last part is deliberate. A tool that quietly skips half your code and reports "nothing found" has told you something worse than nothing, because you will believe it.
How a review works
- You install the GitHub App and choose which repositories it may read.
- You start a review of one repository at a branch.
- Monterva downloads a snapshot of that commit, unpacks it inside an isolated sandbox with no network access, and runs its analysis tools over it.
- The snapshot is destroyed. What is kept is the findings, short evidence excerpts, and a record of what was and was not covered.
- You get a report, and can re-run the review after fixing things to see what changed.
Your code is never executed. Dependencies are never installed, and your own linter configuration is never loaded. That is the single most important design decision in the product, and Security and your code explains why.