Let AI write your code, safely.
nimblegate checks every change your AI agents make - before it reaches your code. Self-hosted, same rules every time.
- Every change is checked before it lands. No exceptions, no tired reviewer.
- Mistakes go back to the AI to fix. You stay out of the loop.
- Secrets are stopped at the door. Keys, passwords and dangerous code never slip out.
- Every decision, visible in one place. What passed, what was blocked, and why.
Checked at push time, the same way, every time.
Every push your agent makes is checked against the rules you turned on. Leaked credentials, force-pushes to main, schema drifting from code, customer data in fixtures, dependencies bypassing your registry mirror: held at the gateway, never landing in your real repo's history. Clean pushes forward to your upstream in under a second, byte-for-byte unchanged.
- Blocks unsafe pushes, forwards clean ones in <1s
- Same answer every push, deterministic, no AI-reviewer drift
- Sits between your agent and your real git host
Agents fix their own rejections.
A rejected push posts its findings as a structured comment on the PR and fires a webhook, so your agent (Claude Code, Cursor, Copilot) reads what failed and pushes a fix. The sticky comment tracks attempt N/M and @-mentions the agent; when a push finally passes, the loop closes itself.
- Structured PR comment + webhook on every rejection
- @bot mention with multi-bot rotation and loop guardrails
- Self-closes on a clean push, no babysitting
- security/no-hardcoded-secrets
- git-safety/no-force-push-main
See what your agents are actually doing.
Reporting built into the gate: every push becomes a report, what was caught, what changed, which rules fire most, how clean each repo is. On the dashboard, and as a read-only MCP + REST API your agent can query. The gate even estimates the review time it saved.
- One-click reports, pick a repo and a window, no query language
- Ask the gate over MCP: “what did you block this week?”
- Time-saved + recurring-finding stats, per repo and per stack
Free for your own work. A small license for commercial use.
Same full app either way, no feature gating, no time limit. The license is how a for-profit team stays legit and keeps a solo dev building.
Personal projects, learning, research, non-profits, and trying it out.
- The full app, no feature gating, no time limit
- 51 built-in frames + your own regex rules
- Auto-PR fix-loop: PR comments + webhooks
- Dashboard, time-saved stats, MCP / REST analytics
- Self-hosted; nothing phones home
- Under PolyForm Noncommercial, today and for good
For-profit use, per company, including gating code that ships paid product.
- Everything in the non-commercial version
- The legal right to use it commercially
- One license per company, all your developers
- Best-effort email support
- Updates published while subscribed
- Proper invoice / receipt (tax handled)
Larger organisations needing an SLA, signed terms, or bespoke features: contact@nimblegate.com.
Which use needs a license?
The free and commercial versions are the same full app - no feature is locked behind the license. The only question is whether your use is commercial.
Does the free version leave anything out?
I'm a solo developer or freelancer using it on paid work.
Can we try it at our company before deciding?
It's only internal tooling - we don't resell nimblegate.
We have many developers, repos, and gateways. How many licenses?
We're a non-profit, or it's a personal project that earns nothing.
The license is authoritative; unsure about your case? contact@nimblegate.com - a quick question beats a wrong guess.
New rules ship regularly. Hear when they do.
An occasional email when a new rule pack, an agent-security advisory, or a notable release lands. No tracking, no drip campaign - just the update.
A couple of emails a month at most. Your address goes nowhere else, and you can unsubscribe anytime.