Preview with the drafts
Security review of a change, before it merges
Claude reviews a branch's change for security problems with Trail of Bits' method. Every serious finding comes with a test that fails on the change, and plain code checks the review before you trust it.
Our run, 2026-09-28. The change passed all 7 of its own tests. The review named the planted flaw at src/app.js:34 as HIGH: any signed-in customer could download another customer's invoice. Its proof test failed, so the merge was blocked.