no seats You pay for tokens, not per engineer

startups

You do not have a spare reviewer

At five engineers, code review is whoever is least busy at 6pm. Buddy is the second pair of eyes that is always available, never tired, and does not need the context switch — so the human review can be about the design instead of the null check.

$ buddy review

             __
    (\,------'()'--o    working tree
     (_    ___    /~"   6 files, 180 lines
      (_)_)  (_)_)

  src/billing/webhook.ts:44  major  correctness
    Stripe sends this event more than once.
    The handler has no idempotency key, so a
    retried webhook charges twice.

  src/billing/webhook.ts:71  minor  security
    The signature check runs after the body
    is parsed, so malformed payloads reach
    the parser unauthenticated.

  2 findings. run with --fix to apply 1.
💸

Catches the expensive class of bug

Double-charged webhooks, sessions that read as valid when they expired, retries that never terminate. Buddy states the failure a change causes, which is the only kind of review finding worth interrupting a shipping team for.

Reviews before the PR exists

buddy review reads the working tree. The fastest review is the one that happens while you still have the code in your head.

📦

Dependencies stop being a project

Patch updates auto-merge, minor updates come grouped with real changelogs, and the pinned dashboard means you always know how far behind you are.

🎚️

Ships with the gates off

Every gate has an off/warning/error mode. Turn them on when the team is ready, not when a vendor decided the default was error.

🧾

One bot instead of two subscriptions

A hosted reviewer plus a dependency service is two vendors, two security reviews, two invoices. Buddy is one binary in a workflow you already have.

🛠️

Red builds fix themselves

buddy fix-ci regenerates a drifted lock file mechanically, retries a flake once, and reports the failures it will not guess at.

Week one

bun add -g @buddysh/buddy
buddy setup

buddy setup reads the repository, detects your package manager, migrates a Renovate or Dependabot config if it finds one, writes buddy.config.ts and generates the workflows. It asks before it writes anything, and the generated workflows are ordinary YAML you can edit.

Then, before you commit anything else:

buddy review --branch --base main

That is the review of everything on your current branch, in about the time it takes to read this paragraph.

What it costs

Buddy is MIT-licensed. There is no seat count and no plan.

You pay
BuddyNothing
The analyzers, secret scanning, workflow audit, dependency updatesNothing — no model involved
AI review, gates, CI repair, finishing touchesModel tokens, at your provider's rate
CIMinutes you are already buying

Two dials keep the model bill predictable: ai.maxTokensPerRun caps a single run, and a cheaper model on ai.model costs a fraction for the common case. Many teams run haiku on every push and opus only on @buddy full-review.

Keep the humans doing human work

The point is not to remove code review. It is to make sure that by the time a teammate opens the diff, the mechanical objections are already handled and the conversation can be about whether this is the right thing to build.

# a pre-commit hook that costs nothing and blocks the obvious
buddy review --staged --light --fail-on major

AI code review · Local review · Merge gates · Dependency updates