← Back to TrustBridge

GETTING STARTED

Your first merge-request review.

Paste a public GitLab merge-request URL to inspect its real changes. No account or token is required. The separate sample console explains the context-policy workflow.

Review a real MR

Review a real public MR

Open Audit an MR, paste a URL from gitlab.com, and choose Check merge request. The server reads the actual diff and rechecks the MR head before returning your result. If it changed during the audit, you must retry.

Inspect file-level signals and the exact head commit. Coverage is partial if GitLab omitted or truncated changes. Download the JSON report or Markdown review brief for your own review. The service does not approve or modify anything.

Supported signals include changes to release-sensitive files, credential patterns in added lines, optional CI checks and some certificate-verification bypass patterns. These are review prompts, not proof that a change is unsafe or safe. Private repositories and self-managed instances are not supported.

Explore the sample context workflow

  1. 01

    Choose “An outdated release instruction.”

    A stale note suggests skipping security verification. The current approved policy says to run it before release. The console shows which one is admitted and why the other is excluded.

  2. 02

    Compare Original and Repaired policy.

    The original sample policy omits the security scan, so the release is blocked. Select Repaired policy to restore it. “Controls satisfied” means the sample policy passes; delivery stays “Not triggered.”

  3. 03

    Inspect your context pack.

    Expand the context pack below the checks. It contains approved policy text and safe exclusion codes. Copy it or download it as Markdown; it’s example output, not deployment authorization.

  4. 04

    Try a different failure.

    Choose a fabricated source, a credential marker, conflicting notes or an unsupported claim. The clean scenario shows an authorized record passing all checks.

KNOW WHAT YOU’RE LOOKING AT

Sample decisions. Real boundaries.

Context selection

Which sample records may appear in the approved context pack.

Release policy

Whether the sample configuration contains the mandatory checks and human approval requirement.

Delivery

Whether an actual release occurred. This demo never changes it to “deployed.”

The hosted demo replays outputs generated by the Python audit engine from fixed synthetic fixtures. It does not process your own data. All twelve scenario/policy combinations are included, so the demo needs no running Python service or paid AI API.

The separate local controller checks candidate Git trees and rejects changes outside the single editable policy file. Live public-MR review is separate from this sample workflow. Native Duo sessions, effective deployment permissions and production rollout remain unverified. The evidence view deliberately shows no live release.

What the checks can miss

Secret screening covers supported patterns, not every possible credential. Staleness is timestamp-based. Contradiction is a wording-and-score heuristic, not proof of meaning. Approved registry records express a human policy decision, not automatic truth.

Reports and sample packs are not authorization to release software. The public reviewer does not accept authentication tokens or private source uploads.

Built on open-source work

TrustBridge extends ContextFirewall’s deterministic checks with provenance screening and an independent release boundary. The original engine is MIT licensed.

Explore the upstream ContextFirewall project ↗

Ready to see the decision?

Open the demo ↗