Local-only Trust Briefs for AI-generated PRs

Review AI-generated pull requests without carrying the whole risk in your head.

ARC gives reviewers a deterministic Trust Brief before merge: whether the agent stayed inside the approved assignment, whether the evidence belongs to this exact commit, and where to slow down first. It runs inside your repo. Source code does not leave.

Security-firstDeterministic receiptsNo source upload
Contract

Freeze what the agent was supposed to do before the diff starts moving under you.

Evidence

Bind commands, logs, contract hash, base commit, and head commit to the PR you are reviewing now.

Verdict

Get Pass, Needs Review, or Blocked with the exact places your review attention should go first.

The reviewer pain

Bad AI PRs do not just waste time. They make every review feel like a security incident waiting to happen.

Deterministic by design

Do not send a probabilistic model to verify another probabilistic model.

ARC runs as a local GitHub Actions workflow and checks the hard facts: assignment drift, stale evidence, missing receipts, protected-path risk, and commit mismatch. The output is a short reviewer-facing Trust Brief, not another AI summary to second-guess.

Source stays in the repositoryReceipts are hashed and commit-boundVerdicts stay narrow: Pass, Needs Review, BlockedInstall only after one useful PR run

Private beta access

Have one AI-generated PR that drained the team or made security review feel uncertain?

Request a Trust Brief for one real pull request. Public PRs can start fastest; private repositories can use local-only setup so source stays inside your repo while ARC checks whether the evidence can be trusted.