Agent-written code moves faster than human compliance review.
Stop risky PRs before they merge.
CompliPatch watches GitHub webhooks, scans changed code, scores compliance risk, and writes the exact PR comment your team can act on.
AI can ship code at midnight. Compliance still needs evidence before merge.
3 changed files scanned from webhook delivery.
patient-export.ts:2patient-export.ts:11patient-export.ts:13Do not merge. Critical evidence requires remediation.
The review gap is no longer style. It is proof.
Sensitive evidence gets buried inside ordinary diffs.
Merge decisions need proof, not another vague warning.
A PR opens from Codex, Claude, an IDE, or GitHub.
Secrets, PHI logs, auth gaps, SQL, cookies, and CORS are checked.
Deterministic findings become an AI-assisted merge signal.
One GitHub-style comment gives evidence, impact, and fix guidance.
Webhook in. Evidence out. Merge decision clear.
Stable scanner rules catch the six risks this demo must not miss.
Optional AI turns findings into reviewer-ready context and priority.
Preview locally, then post or update the PR comment when credentials are enabled.