CheckrailGet a key

Terms of Service

Checkrail Tecnologia Ltda.

Last updated: 27 February 2026 · Version 1.0

1. These terms, and who they apply to

These terms cover your use of Checkrail, an API that reviews the pull requests a coding-agent pipeline sends it, comments on them and returns its findings as structured data, billed per review. They are a contract between Checkrail Tecnologia Ltda., of Rua Marechal Deodoro 630, Sala 1204, Centro, 80010-010 Curitiba, Brazil (“Checkrail”, “we”) and the company that signs up (“Customer”, “you”).

The service is for businesses only, not consumers. By signing up you confirm that you are acting for your business and that you have the authority to commit your company.

The person who accepts these terms accepts them for the company, not for themselves. If you don’t have that authority, please don’t go ahead.

If documents disagree. This order applies: (1) a signed order form or agreement between us, (2) the data processing agreement, (3) these terms, (4) our Privacy Policy, (5) anything else on our website.

2. What the service is

Checkrail is an HTTP API and a code-host app for GitHub, GitLab or Bitbucket. Your pipeline calls the review endpoint with a repository, a pull request and, where it has one, the Linear or Jira issue or the prompt the coding agent was given. The service fetches the diff and the changed files through the app, excludes generated files, runs fixed checks for secrets, removed tests, CI and dependency changes and code-owner boundaries, and has a code model read each change against the task and the code that calls it. Findings scored 0.80 or above are posted as review comments on the pull request; every finding, posted and held, is returned with a routing verdict by webhook and on request. You are billed per completed review.

3. What the service is not

These limits are deliberate, and they are part of what you are buying. They are not defects.

Not an approver. The service comments. It does not approve a pull request, submit a blocking review, merge, push a commit or change a branch protection rule, and a pull request it has reviewed still needs the approval your code host requires.

Not a reviewer of every pull request. Nothing is reviewed until your software calls the endpoint. The service does not pick up hand-written pull requests on its own and provides no IDE or command-line reviewer.

Not a self-hosted product. The service runs on cloud infrastructure in Frankfurt. There is no version installed inside your network, and a repository whose code may not leave your network should not be connected.

Not a test or build runner. The service reads code. It does not execute it, run your test suite or your CI, or say that a change works.

4. What you need to do, and why it matters

What you get from the service depends a lot on things only you control. Please read this section carefully, because sections 9 and 10 build on it.

Permission to connect. You confirm that you may send the repositories the app is installed on, and the tickets named in your calls, to a processor registered in Brazil that holds them in Germany, including under any customer contract or security policy that covers your source code.

Keys and caps. A key is issued to a work email at your company. You keep it secret, close a key that has leaked, and set its monthly spend cap; every review called with a key is billed to the account that holds it, up to that cap.

Passing the task. Your pipeline passes the issue key or the prompt the agent was given. A call without one is reviewed for defects only and marked task_unknown, and no finding about scope can be made on it.

Keeping code owners current. The ownership check reads your CODEOWNERS file as it stands at the default branch. A stale file routes pull requests to the wrong person, and the service does not correct it.

Acting on verdicts. Your software decides what happens on send_back, ready_for_human and human_first, including whether findings are handed back to a coding agent automatically. A change an agent makes on one of our findings is your change.

Resolving comments. Your reviewers resolve or dismiss our comments. Your account's reranker learns only from comments that were resolved or dismissed; a comment left untouched teaches it nothing.

5. Getting started, and what is free

The first 300 reviews on each account are free, without a time limit and without a payment card. Reviews refused for size or failed on our side never count. When the 300 are used, reviews continue and a payment method is asked for before the first monthly invoice; if none is added by the invoice date, new calls are refused until one is, and findings already returned stay available for their retention period.

6. Fees

Price. $0.30 per completed review. A review is one call on one pull request at one head commit, whatever the number of files it changes, up to 4,000 changed lines after generated files are excluded. Reviews above 5,000 in one calendar month are billed at $0.22 each. Prices are in US dollars and exclude tax. Brazilian service taxes are added to invoices for customers in Brazil; reviews billed to customers outside Brazil are an export of services and carry none.

What is not billed. The first 300 reviews on the account; diffs refused above 4,000 changed lines; reviews that fail for a reason on our side; a second call on the same head commit; building and updating repository indexes; held and discarded findings; webhook deliveries and fetching results. There is no seat, no monthly fee and no minimum.

Spend caps. Each key carries a monthly spend cap you set. When a key reaches it, new calls are refused with a reason until the next calendar month or until you raise the cap; nothing is queued into the next month and nothing is billed above the cap.

Billing. Usage is billed monthly in arrears by card. Accounts whose monthly usage exceeds $1,000 may ask for invoices on 30-day terms. Each invoice lists every review by repository, pull request number, head commit and changed lines.

Price hold and closing. The per-review price in force when an account opens is held for 24 months. You can close any key or the whole account at any time; the final invoice covers reviews completed up to that moment.

7. Delivery, availability and support

Reviews. A review is complete when every hunk has been read. How long that takes depends on the size of the diff and on how many reviews are in flight; each key runs up to 30 reviews at once, and later calls wait in order, with their queue position in the response. There is no per-developer or per-hour limit.

Comments and webhooks. Findings at 0.80 or above are posted to the pull request through the app. The full result is delivered to your webhook, signed and retried up to five times over 24 hours, and can be fetched on request whether or not the webhook was received.

API versions. The response schema is dated. A key is pinned to the version current when it was issued and you move it forward; each version is served for at least 12 months after the next is published.

Support. Support is by email, answered as soon as we can without a committed time. A review that failed on our side is re-run without charge.

Support. Support is by email at [email protected]. We aim to reply within one business day. That is a target, not a guarantee.

8. Reviews, verdicts and export

Findings are not rewritten. A review's findings and verdict are stored as delivered. When a reviewer resolves, dismisses or answers a comment, that outcome is stored beside the finding with the username and the time; we never change what a review said after it was delivered.

The usage record. Every review keeps a record of its changed lines, its findings posted, held and discarded, and whether it was billed, so any invoice line can be traced to a pull request and a head commit.

Export. Findings, verdicts and labeled pairs can be fetched as JSON through the API at any time within their retention periods, and for 30 days after an account is closed.

9. What we promise, and what we don’t

We promise to provide the service with reasonable skill and care, and that we have the right to provide it.

We do not promise that a review finds every defect, every change outside the task or every security problem in a pull request, or that every finding it posts is right. Findings carry a confidence, findings below 0.80 are not posted, and a posted finding can still be wrong; the approval your code host requires, given by a person at your company, remains what decides whether a change is merged.

Beyond that we give no other warranty. As far as the law allows, we exclude all implied warranties, including merchantability, fitness for a particular purpose and non-infringement.

10. Liability

10.1 Neither of us limits liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for anything else the law says can’t be limited.

10.2 Losses neither of us covers. Neither of us is liable for lost profit, revenue, expected savings, business, goodwill or reputation, or for any indirect or consequential loss, however it arises.

10.3 Specific exclusions. We are not liable for a defect, vulnerability or outage in code that the service reviewed and your team merged, including where the service posted no finding about it; for a change a coding agent made on a finding handed back to it; for a pull request routed to the wrong reviewer by an out-of-date CODEOWNERS file; for delay while reviews wait in a key's queue or after a spend cap is reached; or for a breach of a contract or policy on where your source code may be held that you accepted by connecting a repository.

10.4 Cap. Our total liability under these terms in any 12-month period is limited to the fees you paid us in that period, or $500 if you paid none.

10.5 You accept that the limits in sections 9 and 10 are a fair way to share risk, given the price and your part under section 4, and that we could not offer the service at this price without them.

11. Confidentiality and data

Each of us keeps the other's confidential information confidential and uses it only to perform these terms. Your source code, diffs, tickets, findings, repository indexes and labeled pairs are your confidential information. We use them only to review your pull requests and to train your account's reranker, and we do not use them to train the shared code model unless your account owner has opted in as described in our Privacy Policy.

How we handle personal data is set out in our Privacy Policy and in the data processing agreement between us, which forms part of these terms. If the DPA and these terms disagree about personal data, the DPA wins.

12. Who owns what

You own your source code, your tickets, and the findings, verdicts and suggested patches returned to your account; a suggested patch you apply is your code. We own the service, the models, the fixed checks and the response schema.

Labeled pairs belong to your account and are never shared with another customer. They train your account's reranker. They are used to fine-tune the shared code model only if your account owner opts in; the opt-in is off by default, covers the finding, the hunk it points at and the reviewer's verdict, and can be withdrawn for future training at any time.

You may not use our name or logo in public, and we may not use yours, without written permission first.

13. How long this lasts, and how it ends

13.1 The contract starts when you sign up and runs until one of us ends it.

13.2 You can end it. Cancel at any time. It takes effect at the end of the current billing month, unless section 6 sets a minimum term.

13.3 We can end it. We can end it with 30 days’ notice. We can end it immediately if you seriously break these terms and don’t fix it within 14 days of being told, if you become insolvent, or if your use exposes us to legal risk.

13.4 What happens then. We stop delivering and stop billing. You keep everything already delivered to you, and your right to use it continues. We delete or return our working copies as the DPA says. Sections 9, 10, 11 and 12 continue to apply.

14. Changes to these terms

We may update these terms. A change that matters takes effect 30 days after we email you about it. If you don’t accept it, you can end the contract before then. Using the service after that date means you accept the change.

15. Contact

Checkrail Tecnologia Ltda., Rua Marechal Deodoro 630, Sala 1204, Centro, 80010-010 Curitiba, Brazil
[email protected]

← Back

Your request has been received.

Expect a message from Checkrail. It goes to the address you gave.