Norma
Norma checks AI-generated code against a governed rule library and returns the same verdict every time.
It runs in two places. Livecheck evaluates a file or snippet on demand, called from an MCP-capable editor such as Cursor, Claude Code, Windsurf or VS Code. Full Scan audits a whole GitHub or Bitbucket repository, detecting the stack and frameworks without a configuration file, and returns findings ranked by severity with the context needed to fix them.
Rules are evaluated by static analysis, so a result does not move between runs. Rule content comes from SOLID design principles and per-stack conventions, and each rule can be switched off where it does not apply. Coverage spans JavaScript, TypeScript, Python, PHP, Java, Node, React and Supabase.
The MCP server exposes link_repository, get_rulesets, get_rules_for_ruleset, live_check, get_open_issues and register_applied_actions, with OAuth and is on the Official MCP Registry
Learn more
Routebase
Routebase is the single source of truth for your APIs. Design your OpenAPI spec once in a visual editor — no hand-edited YAML — and your documentation portal, mock servers, contract tests, and monitoring all derive from that one spec.
Change the contract, publish, and Routebase catches what drifted before your consumers do: it validates live responses against the spec and flags every divergence with field-level diffs — missing fields, type mismatches, undocumented additions.
Work on specs the way you work on code: branch, review, merge, with breaking-change detection before anything ships. Publish a docs portal on your own custom domain. Spin up realistic mocks so frontend and backend build in parallel. Run contract and security tests against any environment.
Every workspace also ships a built-in MCP server, so your AI agents read and act on the same source of truth, under your team's permissions — no glue code.
Learn more
Cycode
A platform for security, governance, and pipeline integrity for all your development tools & infrastructure. Harden your source control management systems (SCM), find secrets, leaks and prevent code tampering. Scan your CI/CD settings and Infrastructure-as-Code (IaC) for security misconfiguration. Identify drift between production systems IaC configurations and prevent source code tampering. Stop developers from inadvertently exposing proprietary code in public repositories, fingerprint code assets and proactively identify exposure on public sites. Inventory assets, enforce security policies, and easily demonstrate compliance across all your DevOps tools and infrastructure, both in the cloud and on-premises. Scan IaC for security misconfigurations and ensure compliance between defined IaC configurations and production infrastructure. Scan every commit or pull/merge request for hard-coded secrets and prevent them from reaching the master branch across all SCMs and programming languages.
Learn more
Graphite
Streamline Git commands and seamlessly stack pull requests from your terminal. Create and edit stacked PRs visually without leaving your IDE. Stay on top of every PR and review request in one unified inbox. Get immediate, actionable feedback on every pull request with Graphite's codebase-aware AI. Eliminate merge conflicts and keep your main branch green, whether you're a team of 10 or 10,000. Accelerate your team with powerful, real-time developer metrics. A faster, more intuitive Git interface, designed to make stacking effortless. Run gt create again to stack another branch on top of your previous changes without waiting for them to merge into the main. Automatically sync your local stack with remote changes, and clean up stale branches with gt sync. Update changes across your stack with gt modify. Graphite handles all of the recursive rebasing for you. Create or update PRs for every branch in your stack with gt submit.
Learn more