Free
For an occasional reviewNo card. No expiry.
- One hosted AI review per UTC day
- All three specialist review profiles
- Web and MCP share the same daily allowance
- Local privacy check and prompt export
- Downloadable review and file manifest
A workbench for security researchers
Bring the code. Choose a specialist review. Leave with observations, counterarguments, and the evidence your next step needs.
The example needs no account or API key. Your first hosted review each day is free.
2 if response.status_code >= 400:
3 return {"error": response.text}
Evidence of the response contents and the affected caller. The supplied files don’t establish either.
Return a stable public error and verify the change locally.
Upload, paste code, or import an authorized GitHub file. Pick the review that fits.
Inspect what leaves the tab. Use your own API key or take the request to your AI client.
Download the review, next steps and exact file manifest. Continue from a clear record.
Your next review
Only this file is read, at an exact commit. GitHub requests go directly from your browser. Use a fine-grained token with read-only Contents access to the selected repository.
Scope, version, and prior art have not been established.
Privacy checks run in your browser. Preview the exact request before you send it.
Choose where the review runs. Your checked request is ready to preview.
Your key and files pass through our server to the selected provider. We do not save them. Provider usage is billed by that provider.
Sign in with a passkey to use your free daily AI review.
It will reference the supplied files, flag uncertain claims, and suggest fixes.
Choose your pace
Keep your choice of model.
All profiles and AI connections on both plans.
No card. No expiry.
Every week. Renews automatically until cancelled.
Checking subscription availability…
Your AI provider bills its usage separately. US$10/week, renewing weekly until cancelled. Cancel online; keep access through your paid period. File limits and fair use apply. Any applicable tax is shown at checkout.
What the workbench adds
Check for secrets, preview the full request, and send only the selected files. The manifest records their hashes.
Keep scope, version, local proof, and prior art alongside the code. Missing evidence and same-root overlap stay explicit.
Every review asks for the strongest counterargument, code references, defensive fixes, and unresolved questions.
Download the review, supplied evidence notes, and exact file manifest together. Carry the context into your next review.
Spend less time rebuilding context. Keep the files, evidence, counterarguments, and next steps together.
Public research record
Research by Tradi3. Published competition results and findings are linked below.
August 2026 Immunefi competition. Two accepted High findings.
Published leaderboard ↗August 2026 Immunefi competition. One Critical and one High finding.
Published leaderboard ↗Publicly confirmed findings from the StableSwap Hooks competition on Cantina.
Published results ↗Also published: Metric findings on Sherlock · Full audit portfolio
ENS: competition complete. Results coming next. Current programme status ↗
Published researcher results · Updated 2 October 2026.
Turn scattered notes into a clear report. The guide and template are free.
Good to know
Yes, through prompt export: check your files, download the prompt, and paste it into your chat app. A chat subscription is separate from API billing. Hosted reviews require an OpenAI or OpenRouter API key.
Account and passkey records, hashed session and AI connection tokens, review activity, and billing references. We do not store uploaded code, prompts, API keys, or review results. The provider you choose has its own data and retention policies.
Code references, evidence gaps, counterarguments, suggested fixes, and a downloadable review packet. Add your scope, version, and proof to give your model the context it needs.
Each review accepts up to 20 text files: 120 KB per file and 240 KB combined, with a two-minute provider timeout. Operator removes the daily review cap and runs one review at a time. It is for individual use; automated bulk use and account sharing are excluded.
Yes. The command-line kit remains free. The subscription pays for repeated reviews through the hosted website. You can use the kit with your own API endpoint or local model.