Every public repository, free forever. Private repositories are one flat plan, never per seat.See pricing
[ Console ]
● GitHub AppClaude / Codexyour cloud only

Writing code got fast.
The bottleneck moved
to review.

It reviews every pull request, explains red CI, and turns the issues you assign it into pull requests, inside an ephemeral machine in your own cloud. The merge stays yours.

Your data on your serverYou own the mergeFlat rate · no per-seat
northwind/api · issue #412 → pull request #1204Running
MA
maya-kopened this issue
fix: the same upload creates duplicate rows
bugweb
quellbotbotposted a plan
01reproduce: two uploads with the same body create two rows
02change: derive a content hash and make the insert idempotent
03verify: add a test that uploads the same file twice
MA
maya-kreplied
/build
quellbotbotbuilding…
fix: make the upload idempotent with a content-hash key
+21 −31 test addedpolicy gate ✓
Request changesApproveComment← yours
Triggered· issue #412 matched a trigger slug$0.38
The shape of the problem

The cost moved from
writing to verifying.

Generation is cheap now. Every change still needs a second reader, and that reader has a calendar. So the queue grows, and review becomes the slowest step.

Writing a changeminutes, and falling
Verifying itreviewer hours, and rising

quellbot works that half of the loop. Approving stays a person's job.

In the loop at every stage

One teammate, four jobs

Reviews, red CI, the code you assign, and the questions on the thread. Every one ends at your approval.

01Review

Every pull request, read line by line

Findings against your own conventions, committable suggestions, a real verdict.

Grouped by severity

A busy PR never becomes a wall of text: blockers first, nits last.

Committable suggestions

Where the fix is a concrete edit, it arrives as a suggestion block.

Delta re-reviews

Push new commits and it posts what is fixed, still open, and new. Never a repeat.

qbquellbotRequest changes

Two findings on the retry path; the rest of the diff reads clean. Per-file walkthrough below.

blockeruploadOnce() can be entered twice before the hash key is written, so the duplicate this PR fixes is still reachable under concurrency.
warnThe retry backoff has no jitter; 200 clients will re-collide on the same schedule.
nitThe DST branch added in date.ts has no test east of UTC.
02Triage

Red CI, explained where it broke

The root cause and a concrete fix, posted on the run that failed.

Root cause, not a stack trace

It reads the diff, the log and the migration together.

Deploys count too

A failed deploy is triaged the same way as a failed test.

Advisory only

quellbot never edits a workflow file. That is structural, not a setting.

northwind/api · checks on pull request #11981 failing
build · node 20passed
lintpassed
test · upload.spec.tsexit 1
quellbotcommented on the failed run

Root cause: migration 0043_rename_hash renamed uploads.hash to content_hash, but uploadOnce() still selects the old column. Try updating the query and re-running the suite.

FAIL upload.spec.ts › rejects a duplicate upload error: column "hash" does not exist at uploadOnce (src/uploads/store.ts:41)
advisory only. quellbot never edits your CI
03Build

Assign it an issue, review a pull request

A plan, a build in your own cloud, your tests, a gated pull request.

Plan, then build

Auto-build after planning, or hold until someone replies /build.

A real policy gate

Workflow edits, secrets, oversized diffs and symlinks are blocked before any push.

Accounted per run

Every run reports what it cost, debited atomically at the gateway as it goes.

console.quellbot.dev/app/run/r_8f21c4Complete
machine
fry-1a · destroyed after 58s
lane / model
claude · sonnet-4.5
policy gate
passed · 0 blocked paths
Spend · this month$12.40 / $40.00
this run: $0.38 · debited atomically at the gateway
3 files · +21 −3 · pushed to quellbot/fix-412
04Answer

Mention it on a thread, get the diff back

Mention @quellbot and the answer cites the actual change, file and line.

Cites file and line

Answers point at code, not at a summary of code.

No lingering copy

The machine that read your repository is destroyed when the reply is posted.

Either lane

Claude or Codex: replies run on whichever lane you configured.

northwind/api · pull request #1204 · conversationReplied
DE
dev-ariasked
@quellbot why does the retry path need jitter here? Two hundred clients already back off.
quellbotbotreplied
They back off on the same schedule. retry.ts:28 derives the delay from the attempt count only, so every client that failed in the same second retries in the same second. The content-hash key added in this PR makes the duplicate harmless, but the thundering herd on the gateway stays.
src/uploads/retry.ts:28
− const delay = base * 2 ** attempt
+ const delay = base * 2 ** attempt * (0.5 + Math.random())
the machine that read the diff was destroyed 4 minutes ago
Six invariants, enforced by tests

The security model is the product

Your code, credential and spend stay on your side of the line. Every guarantee is held up by a test.

Our side
never holds your code
01Receives the GitHub webhook
02Holds your credential, encrypted at rest
03Creates and destroys the machine
04Meters spend and enforces caps
05Pushes the branch, opens the PR
Your side
your repo, your machine, ~60s
01Clones the repository
02Runs Claude Code or Codex
03Runs your test suite
04Produces the diff
05Is destroyed when the run ends
01
Your code is never copied to us

Your repository is only ever cloned into a machine in your own Fly account, created for that run and destroyed after it. Nothing of it stays behind.

02
No exfiltration path

Deny-by-default egress plus a per-run machine that is thrown away. A prompt-injected agent has nowhere to send anything.

03
A deterministic policy gate

Workflow edits, secrets, oversized diffs and symlinks are blocked before any push.

04
Budgets enforced by accounting

The per-run bound is a hard gateway debit; a monthly cap holds new work once spend crosses it.

05
The real agents, not a clone

quellbot shells out to the actual Claude Code and Codex CLIs, scoped to your repository.

06
You bring the credential

Subscription or API key. You pay your provider directly; quellbot never marks it up.

The runner

Where the agent actually runs

ephemeral microVM · ~60s life

A throwaway Fly Machine per run, destroyed a minute later. One token to connect, nothing to keep.

Fresh isolation every run
Nothing to maintain
Scales to zero when idle
Two lanes, as peers
ClaudeClaude Code CLI · subscription token or API key
CodexOpenAI Codex CLI · your OpenAI credential
The console

Every run, accounted for

Pipeline, log, policy verdict and exact cost, on one page.

console.quellbot.dev/app
quellbot console

Live activity across every installed repository, spend against the cap, and the runs still moving.

Read the how-to guide

One flat plan. No per-seat pricing, ever.

Public repositories free forever. Private repositories, one flat plan for the whole team.

Sign in

Open the console and choose Continue with GitHub. Signing in creates your account on the spot, no invitation to wait for. No install, no password; GitHub just confirms who you are. The Get started page then walks you through the three connections below, one step at a time.

GitHub only.quellbot never sees a password. It reads your public profile to identify you; you grant repository access separately when you install the App.
console.quellbot.dev
Sign in
Next: Connect GitHub & Claude