A clearer boundary for AI-assisted releases
Give your agent context.
Keep the final say.
Check real GitLab changes for release risks. See what needs review, trace the result to an exact commit, and keep the decision to merge or release with you.
Public GitLab MRs. Read-only. No token required.
“Skip security checks.
We can run them after release.”
Run security verification before
every production release.
THE WORKFLOW
A helpful assistant.
A boundary you can inspect.
TrustBridge separates the information an agent sees from the authority to change or release your software.
- 01 / CHECK
Start with a source.
Match context to reviewed records. A confident claim or a high score cannot make an instruction authoritative.
Provenance before confidence - 02 / EXPLAIN
See what stays out.
Stale notes, unsupported claims and detected credential patterns are excluded with clear reasons.
Useful reasons. Withheld raw content. - 03 / DECIDE
Keep the next move yours.
Inspect the approved context and release controls. A valid context pack is one check, not permission to deploy.
A proposal is never an approval
LESS READING. MORE TRYING.
What would you
let your agent use?
Pick a scenario. See the decision, compare the release policies, and take away a readable context pack.
Explore all six scenariosReal changes.
Clear about the checks.
Paste a public GitLab merge-request URL to review its actual diff. Get file-level signals, the reviewed commit, coverage details and a downloadable report. No account or token is required.
The live reviewer is read-only: it does not execute code, approve a merge or deploy your software. Explore the separate sample console to see the planned context-to-release workflow.
Read what’s verifiedBEFORE YOU TRY IT
A few useful answers.
Can I use it without connecting a repository?
Yes. The live reviewer reads public GitLab merge requests without a token. You can also explore six sample context scenarios without supplying any URL.
Can I review my own merge request?
Yes, if the merge request is publicly accessible on gitlab.com. Open “Audit an MR” and paste its URL. TrustBridge reads the changes from GitLab and returns a bounded pattern review. Private repositories and self-managed GitLab are not supported yet.
Does “Controls satisfied” mean it deployed?
No. It means the sample configuration contains the required controls. A real release needs independently verified checks and a human decision. The demo never creates deployment evidence.
Is this an AI model judging another AI?
Both the live reviewer and the sample console use deterministic checks with no model calls. Secret detection is pattern-based; contradiction and staleness checks have documented limits. Human-reviewed records determine which sources have authority.
START WITH ONE DECISION
See what gets through.
Understand why.
Review a real merge request Bring a public MR link. Keep control of the next step.