Finds the hole.Proves it.Opens the fix PR.
Bishop watches every pull request for security holes and lawsuit risk — proves each one in a sandbox, writes the fix, proves the fix closes it, and opens a pull request. You always merge. Log and live-site monitoring open to the waitlist next.
Free plan for one repo. No credit card.
- security precision
- ~86%security precision
- files we didn't write
- 1,300files we didn't write
Measured on OWASP Juice Shop — real code neither of us wrote, including its flagship login SQL injection.
- const STRIPE_SECRET_KEY = "sk_live_****3f2a";+ const STRIPE_SECRET_KEY = process.env.STRIPE_SECRET_KEY;
Independent benchmark
Run on OWASP Juice Shop — 1,300 files neither of us wrote.
The full breakdown behind the number in the hero: Bishop run on a real app neither of us wrote, every finding hand-adjudicated, reported by category and never blended into one score.
Security detection
~86%
precision · R2 / R3 / R5 / R7
Caught the flagship login SQL injection, plus search SQLi, CSRF, and insecure auth cookies.
6 of 7 flagged were real; the one false positive was a route that already presence-checks its input.
Determinism
100%
identical · 3 fresh runs
The same commit returns the same findings on every run.
Detection is rules and parsers — no rule routes a finding decision to an LLM.
Accessibility labels
38% → 88%
precision · L5
Label detection started at ~38%. Teaching it Angular Material's mat-label took it to ~88%.
We tune for the frameworks real apps use — and we tell you what we don't cover yet.
models.sequelize.query(`SELECT * FROM Users WHERE email = '${req.body.email}' ...`, { model: UserModel })
What we don't catch yet: Angular [innerHTML] template bindings, and a headless-Angular exploit harness — until it exists, an Angular XSS finding is surfaced as an advisory, never an auto-fixed PR.
Every finding carries evidence. Every fix is proven before a human ever looks.
Why it earns the merge
Proven, not guessed
The exploit reproduces, the patch closes it, and a regression test fails without it, before a human ever looks.
Honest escalation
A real hole it cannot safely auto-fix goes to you, never a fix PR that breaks your app to look productive.
Past push protection
It reads git history and high-entropy strings, catches the key push protection missed, and always says rotate.
You always merge
Least-privilege tokens and a write guard mean it opens a PR and stops. It never pushes to your default branch.
From install to merge in three moves
- 01
Connect a repo
Install the GitHub App. It reads your code and git history, nothing else.
- 02
It proves a hole
Deterministic rules find a candidate; an isolated sandbox runs the real exploit to confirm it.
- 03
It opens the fix
A pull request with the exploit before and after, the diff, and a test, or an alert if it cannot prove the fix. You merge.
Proof, not promises
Everything below is real, from the public demo repo — masked exactly as Bishop posted it. Nothing here is a mockup.
Exposed Stripe secret key
server/config.js:2
-export const STRIPE_SECRET_KEY = "sk_live_****yqDv";+export const STRIPE_SECRET_KEY = process.env.STRIPE_SECRET_KEY;
Regression test
✗ before — not ok 1 - server/config.js reads STRIPE_SECRET_KEY from the environment, not a literal
✓ after — the app still boots {"booted":true,"status":200}
Rotate the key. This key already leaked — rotate it in the Stripe dashboard. Moving it to env does not un-leak it.
Exposed Resend API key
server/mailer.js:2
no verified patch after 2 attempt(s): env → the app's own tests fail on the patched code; env-fail-fast → the app's own tests fail on the patched code
Caught the key push protection missed
GitHub blocked the Stripe key on push. The openai project key (sk-proj-****8FW6) slipped through and stayed in history — Bishop read the history and flagged it, with a rotate warning.
Plus the advisories it could not prove into a fix — surfaced honestly, never shipped as a PR. See the demo repo
Static review, meet runtime proof
Claude Code reviews your code. Bishop proves it at runtime. They do different jobs — use both.
- Reads your source and reasons about vulnerabilities like a security researcher.
- Strong on business logic and code review — often stronger there than a runtime tool.
- Describes an exploit scenario and suggests a patch.
- Runs when you invoke it in your terminal.
- Runs the actual exploit against the running app in an isolated sandbox — proves the hole is real, not just plausible.
- Re-runs the exploit after the fix to prove it's closed. No pull request unless it is.
- Escalates when it can't safely auto-fix, instead of shipping a patch that breaks your app.
- Runs on every pull request, automatically. Detection is deterministic — same commit, same findings, no LLM deciding what's a vulnerability.
Static review says “this looks exploitable.” Bishop runs it and says “it is” or “it isn't” — then proves the fix closed it.
Simple plans. You always merge.
Free
Free
One repo, evidenced findings, and verified fix PRs.
- 1 repository
- Evidenced findings with file:line
- Verified fix PRs
- Advisories and escalations
Pro
Most popularPaidpricing at launch
For a small team shipping across a few repos.
- 5 repositories
- Everything in Free
- Slack cards and thread replies
- Reply to revise a fix
Team
Paidpricing at launch
Adds runtime monitoring and policy drift.
- Everything in Pro
- Runtime monitoring (log drain, Sentry)
- Live-site and policy-drift checks
- Priority support
Free for one repo. Paid plans open to the waitlist first — pricing announced at launch.
The honest answers
Does Bishop merge code for me?
No. It opens a pull request with the proof and a human always merges. It never pushes to your default branch and never auto-merges.
How does it know a fix actually works?
It runs the exploit against your code in an isolated sandbox, applies the patch, and re-runs the same exploit. No PR unless the exploit reproduces, then fails after the patch, and your own tests still pass.
What if it cannot prove a fix?
It sends an alert instead of a PR and says why. A real hole it cannot safely auto-fix is escalated to you, not force-fixed.
Is the analysis just an LLM guessing?
No. Detection is deterministic, from rules, parsers, and signatures. The LLM explains findings and writes patches; it never decides whether something is a finding.
What access does it need?
Read code and git history, write pull request comments, and create branches under sentinel/fix-*. It cannot push to your default branch, merge, or touch issues, settings, secrets, or Actions.
A secret leaked. Does the fix un-leak it?
No. Moving a key to an environment variable stops it being in the code, but a committed key is already public in history. Bishop always tells you to rotate it.
Is the lawsuit-risk check legal advice?
No. It flags known risk patterns, such as personal data sent to a third party your privacy policy does not name. It is not legal advice and never says your app is safe.
How do you keep my code and logs protected?
Least-privilege tokens scoped to one repository for one hour, encrypted at rest, logs redacted at ingestion, and untrusted test code runs in an isolated sandbox only.
What does it cost?
A free plan for one repository. Paid plans (Pro and Team) add more repositories, Slack, and runtime monitoring. Pricing is announced at launch, and paid plans open to the waitlist first.
When can I use runtime monitoring?
It is on the way. Join the waitlist and we will email you when it opens.
Put a proof engine
on your repo.
Bishop finds the hole, proves it in a sandbox, and opens the fix PR. Runtime monitoring opens to the waitlist first.
Free plan for one repo. No credit card.
Free for one repo. A human always merges. Nothing is ever pushed to your default branch.