Vannus / Catalog / Qodo

Qodo C+ Moderate

Graded C+ on resilience. In Vannus's assessment it has not disclosed which model it runs — acceptable, with limits worth knowing.

AI code review and governance platform (formerly CodiumAI) covering both the IDE and the git host. Agentic issue finding with context-aware suggestions, cross-repository review, a "living rules" system for enforcing standards, and a governance portal with audit trails. Integrates with VS Code, JetBrains and Visual Studio, and with GitHub, GitLab, Bitbucket, Azure DevOps and Gerrit. The privacy pol

coding, AI, code-analysis
Model provenance

Not disclosed. Qodo does not publish which model it runs, so this criterion is excluded and the grade rests on what we could verify. We say so rather than guess.

Who controls it
Allied / Safe Harbor Origin
OriginISR
Data jurisdictionUS
Within U.S. CLOUD Act reachNo
Trains on your dataNo

This is a separate question from the grade above. The grade measures resilience — whether the tool endures and whether you could leave it. This measures who can compel your data. A tool can score modestly on one and strongly on the other, and many do.

Signals on file
Origin
Israel · data in United States
US legal control
No
Training on your data
Never trains on your data

The vendor's published or catalog-recorded posture — the concrete facts this grade is built from. A full audit verifies each against the vendor's current documentation.

Compliance signals on file
SOC 2 Type II
How this grade is set

Vannus grades Qodo against nine dimensions of trust — data sovereignty, training privacy, compliance posture, operational resilience, exit portability, and more. The heaviest criterion asks whether the tool builds its own AI or resells someone else's model; where the vendor discloses it, the grade cites the vendor's own documentation. No paid placements — scoring is walled off from affiliate revenue. See the methodology →

Related tools we grade
Visit Qodo ↗ Grade your whole stack →