Baz
Also known as: Baz, Baz Technologies, Baz Technologies, Inc., baz.ai, baz.co, baz-scm, Baz Planner, Spec Reviewer, Awesome Reviewers
Engineering review platform whose agents govern AI-written code end to end: an AI code reviewer, a Spec Reviewer that runs your app in a sandbox and drives a browser to check the built experience against Figma and Jira, and Planner, whose plans a person approves before code is written.
Baz, based in Boston, is an agentic coding platform whose AI agents operate directly on a team's codebase to review, govern, and secure the code that developers and AI copilots produce.
Founded by a team of former Palo Alto Networks engineers who helped build its cloud application security business, and led by chief executive Guy Eisenkot, who earlier co founded Bridgecrew before its acquisition by Palo Alto Networks, it raised a seed round that it extended to seventeen million dollars in June 2026, co led by Battery Ventures and Boldstart Ventures.
Its premise is that in a world where AI generates code faster than any team can review it, reviewing after the fact is no longer a viable primary defense.
Baz began with an AI Code Review agent that runs on every pull request, deeply understanding the codebase, detecting breaking changes across endpoints and behavior, and enforcing standards across product, design, architecture, security, and reliability, and Baz reports that it ranks first on the precision weighted Code Review Bench. Its Spec Review agent goes further, pulling requirements from Figma over MCP and Jira over REST and using secure browser automation to validate that the delivered experience matches intent, reducing bugs and time to merge.
Its newest release, Baz Planner, moves review upstream: it produces an implementation plan that goes through an approval workflow, with versioning and comments, before any code is written. Throughout, Baz keeps a developer in the loop for every significant decision, accumulates learnings from a team automatically and updates its own instructions, and is built to be observable, explainable, predictable, and reproducible.
Baz reflects its founders' security background, framing itself as AI code governance that gives engineering and security leaders control over a codebase increasingly authored by systems they cannot fully audit, and acting as a super harness that coordinates coding agents rather than replacing them.
Its reviewers run on OpenAI's GPT-5-Codex with Anthropic Sonnet 4.5 reflections, chosen by Baz rather than the customer, and Private Mode keeps source code in the customer's own VPC, with VPC and self-hosted deployment available under an Enterprise contract.
For a team shipping with AI copilots that wants deep, learning code review, spec validation, and pre code governance integrated into GitHub and the IDE, Baz is a strong fit; a team wanting a lightweight linting bot will find it a governance layer rather than a checkbox.
Vendor details
Canonical URL
https://baz.ai
Category
Coding agent
Subcategory
Agentic AI code review and governance
Funding status
Independent, based in Boston, founded by a team of former Palo Alto Networks engineers who helped build its cloud application security business, and led by chief executive Guy Eisenkot, who earlier co founded Bridgecrew before its acquisition by Palo Alto Networks. Baz Technologies raised an eight million dollar seed co led by Battery Ventures and Boldstart Ventures, then extended it by nine million dollars to seventeen million dollars total in June 2026, with participation from AFG Partners and Disruptive VC. Its AI Code Review tool ranks first on the precision weighted Code Review Bench, and it is available on the GitHub and AWS marketplaces.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Source platforms: GitHub, GitLab (GA since September 2025, two-way comment and merge sync via personal access token) and Azure DevOps with project-scoped onboarding. Ticketing: Jira, Linear, Azure DevOps, Monday, Shortcut and YouTrack, with acceptance criteria seeding the spec and optional write scopes to post conclusions back. Design: Figma over MCP. Engineering knowledge: Notion and Fibery. Baz publishes dedicated solution pages for working alongside Claude Code, OpenAI Codex, Cursor and Devin, positioning as a super harness that coordinates coding agents rather than replacing them. Surfaces include the pull request, a PR Inbox, an interactive CLI review loop, an MCP server for IDE agents, and a slash command that starts a Planner session from inside another coding agent. Distributed through the GitHub and AWS marketplaces.
In practice
Your AI copilots generate diffs faster than anyone can review, and risky changes slip into production. Baz reviews every pull request with agents that understand your codebase, flag breaking changes, and enforce your standards, ranking first on a code review benchmark.
Code compiles and passes tests but silently drifts from the Figma design and Jira acceptance criteria. Baz's Spec Review agent pulls the requirements and uses browser automation to verify the delivered experience matches intent before merge.
You want to stop reviewing AI code after the fact and catch problems earlier. Baz Planner reviews the plan against your architecture before code is written, blocks unsafe paths with a risk matrix, and cuts downstream reverts and hotfixes.
Sources & related URLs
Related / legacy domains
Research sources
Agentic Index coverage score
13.0 / 14 capabilities · 93%
| Integrations & Tool Calling | Full |
|---|---|
|
Integrations cover GitHub, GitLab and Azure DevOps for source control; Jira, Linear, Monday, Shortcut, Azure DevOps Boards, YouTrack and Fibery for tickets; Figma for design; Notion and Google Docs for knowledge; Datadog and Sentry for the SRE agent; Slack for chat; and preview environments and a sandbox for running the app. Sourcebaz.ai/docs/basics/integrationsread 2026-09-29 |
|
| Workflow Orchestration | Full |
|
Multiple agents divide the work on a change: SDLC agents (Fixer, Merger, SRE, Skill Maintainer) run independently in sandboxed environments alongside a set of individually scoped review agents, Merger decides after CI passes whether a pull request is safe to merge, and Planner produces an implementation plan that goes through approval before code is written. Sourcebaz.ai/docs/agents/baz-agents and baz.ai/changelog 2026-07-01read 2026-09-29 |
|
| Knowledge Grounding & RAG | Full |
|
Reviewers ground on the organization's repositories, with API endpoints for file search, text grep and cross repository architecture search, and on product intent pulled from ticketing, Figma, Notion and Google Docs integrations, which the Requirements Validator checks code against. Sourcebaz.ai/docs/account/api-keys, docs/basics/integrations and docs/agents/baz-agents; baz.ai/docs/basics/integrationsread 2026-09-29 |
|
| Human Oversight & Guardrails | Full |
|
Plans generated by Planner go through a dedicated approval workflow before implementation starts, and since September 2026 reviewers review plans together and track revisions, so a person approves before the agent's plan is built; Merger escalates changes it does not judge safe to merge. Sourcebaz.ai/changelog 2026-07-01 and 2026-09-24read 2026-09-29 |
|
| Security, Identity & Governance | Full |
|
SOC 2 certification is stated on the security, privacy and compliance page, Enterprise adds SSO, centralized controls and VPC deployment, and API keys are limited to a whitelist of endpoints under the creator's permissions. Sourcebaz.ai/docs/account/security-privacy-and-compliance, baz.ai/pricing and docs/account/api-keysread 2026-09-29 |
|
| Observability & Auditability | Full |
|
Session Logs let a team inspect how each run was triggered, where it executed, its status, the major stages it completed, its outcome and its cost, and the API records MCP session events, giving a per run record of what an agent did. Sourcebaz.ai/changelog 2026-06-01 and docs/account/api-keysread 2026-09-29 |
|
| Memory & State Persistence | Partial |
|
Reviewer Memory stores a memory in a reviewer's own memory bank when similar feedback is given more than once, updates that reviewer's prompt automatically and shows the memories on its Reviewer Card and drawer, with every prompt change versioned for rollback. No lifetime, expiry or purge path for these memories is stated, and the version rollback is change control over the prompt rather than a way to purge memories. Sourcebaz.ai/changelog 2025-07-02read 2026-09-29 |
|
| Deployment & Data Residency | Full |
|
Private Mode, on Pro and Enterprise, keeps source code stored only in the customer's own VPC through a file system service pod on AWS EKS, with analysis on Baz infrastructure reading it transiently; Enterprise lists VPC deployment and self hosted deployment under an Enterprise contract, and private application review can run the sandbox inside the customer's Kubernetes as a limited preview, which is a named customer environment. Sourcebaz.ai/docs/account/private-mode, baz.ai/pricing and baz.ai/changelog 2026-07-29read 2026-09-29 |
|
| Prebuilt Agents, Templates & Packs | Full |
|
Named built in agents each do their own job: Fixer, Merger, SRE and Skill Maintainer as SDLC agents, and review agents including Requirements Validator, Guidelines Enforcer, Logic Checker, Breaking Changes Detector, Type Validator, security reviewers and an API Design Reviewer, each of which stands on its own; customized agents can be built on top. Sourcebaz.ai/docs/agents/baz-agentsread 2026-09-29 |
|
| Triggers & Channel Coverage | Full |
|
Reviews run automatically when pull requests open across GitHub, GitLab and Azure DevOps, Merger runs after CI passes, and Skills Maintainer can scan on a schedule every three days, weekly or every two weeks, so work reaches the agents without a person starting it; comment commands, the CLI and the MCP server add on demand runs. Sourcebaz.ai/changelog 2026-08-10 and docs/agents/baz-agentsread 2026-09-29 |
|
| Model Flexibility & Routing | Partial |
|
Baz discloses that its agentic reviewers run on OpenAI's GPT-5-Codex with Anthropic Sonnet 4.5 reflections, so it routes across more than one provider, but it keeps the choice itself: no customer model selection, bring your own key or local model option is documented. Sourcebaz.ai/changelog 2025-10-16read 2026-09-29 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
API keys call the Baz REST API (v2, under /api/v2/ with an x-api-key header) and the Baz MCP server for scripts, CI and unattended agents, with twelve documented endpoints covering reviewer configuration, review discussions, repository search, plan creation and versioning, plan comments and linking pull requests to plans. Sourcebaz.ai/docs/account/api-keysread 2026-09-29 |
|
| Testing, Debugging & Optimization | Full |
|
Prompt Playground lets a team test a review agent's behavior on real change requests before rollout and tune its tone, scope and strictness without pushing untested agents to production, and Evaluations report reviewer performance with usage metrics and comment tracking. Sourcebaz.ai/changelog 2025-05-22 and 2025-07-29read 2026-09-29 |
|
| Browser & Computer Use | Full |
|
Spec Reviewer clones the repository, restores dependencies, runs the setup and start commands, waits for the application to become healthy and opens it in a browser to check the built experience against the specification. Sourcebaz.ai/changelog 2026-07-29read 2026-09-29 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
Baz Planner adds shared review of implementation plans published from coding agents, with comments on passages or the entire plan that survive revisions. Teams can compare plan versions, assign reviewers by repository access, review on mobile and follow plan links from pull request comments.
Bears on: Human approval / guardrails
View sourceBaz added the SAST-inside feature to its Advanced Security agent. This update runs specialized static analysis checks over modified code to nominate potential vulnerability hypotheses. The agent then investigates each signal against the broader repository context, including data flow and reachability, to determine if it is exploitable before creating a review finding.
Bears on: Security / enterprise
View sourcePricing
From $30 per active developer per month (Pro), plus Engineering Work Credits for advanced agents
Per active developer per month for access and standard review, plus Engineering Work Credits at $0.01 each for advanced agent sessions.
What is public
Pro is $30 per active developer per month with standard AI code review included, Engineering Work Credits cost $0.01 each for advanced agents, and Enterprise is priced on contact. A 14 day free trial comes with both plans.
Billing mechanics
Seats cover access and standard AI code review; Fixer, Advanced Security, Spec Reviewer and AI SRE sessions draw Engineering Work Credits at $0.01 per credit, with published typical ranges per session and a suggested budget of $20 to $50 per active developer per month.
Cost watchouts
Engineering Work Credits for advanced agents are billed on top of the per developer seat price.
Variable cost rationale
Seats are fixed per active developer, while advanced agent work is metered in credits per session, so part of the cost follows usage.
Additional watchouts
The seat price covers standard review only; advanced agent sessions are billed in credits on top, so heavy use of Fixer or Spec Reviewer raises the monthly cost.
Overage / add-ons
Advanced agent sessions consume Engineering Work Credits at $0.01 per credit, with typical sessions from $1 to $4.30 for Fixer, $1.75 to $2.20 for Advanced Security, $1 to $2.50 for Spec Reviewer and $1.50 to $3 for AI SRE.
Sales call required
Mixed (some tiers require a call)
Free / trial
Fourteen day free trial with full platform access on Pro and Enterprise; no permanent free plan.
Lowest paid plan
Pro at $30 per active developer per month, with Engineering Work Credits billed on top.
Key ambiguities
Enterprise pricing is not published, and credit spend depends on how often advanced agents run.
Related vendors
- Cognition — Maker of Devin, an autonomous AI software engineer
- 10Web — Agentic website platform whose specialized AI agents build, host,…
- AgentUI — Managed AI app builder for operations teams that generates and hosts…
- Aider — Open source, model agnostic terminal coding agent that edits your…
- Anthropic Claude Code — Anthropic's agentic coding system across terminal, desktop, IDE, web…
- AppFactor — Agentic platform that runs persistent agents across an enterprise…
Alternatives to Baz
The closest documented capability profiles to Baz among coding agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Cognition13.0 / 14Fuller documented coverage on Model Flexibility & Routing
- Warp13.0 / 14Fuller documented coverage on Model Flexibility & Routing
- Zencoder13.0 / 14Fuller documented coverage on Model Flexibility & Routing
- Anthropic Claude Code12.5 / 14Fuller documented coverage on Memory & State Persistence
- Cursor12.5 / 14Fuller documented coverage on Model Flexibility & Routing
- Factory12.5 / 14Fuller documented coverage on Model Flexibility & Routing
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded