Dualzo

AI development governance for GitHub

Ship AI-written code you can actually trust.

Dualzo is the AI development governance platform for GitHub. It turns a GitHub issue or a prompt into a human-approved, sandbox-validated pull request, checked against your repo's own tests, with every step audited. Pick the model that does the work: Claude, Codex, or Gemini.

No card required · no API keys to manage · 🎁 300 free signup credits (valid until Oct 31, 2026)

execution #218 · @kathy/flipdisc
# issue: "Add rate limiting to the public API"
plan → 3 tasks · risk: low · confidence 82/100
approve → waiting for a human ✋
validate → install · lint · test ✓ (sandbox)
pr → opened #441 ▌

More time for the code you want to write.

◆
GitHub App

Connect a repo of any language. Dualzo indexes it and opens the PR for you.

▣
Sandbox validation

Runs your repo's own install / lint / test / build in an ephemeral container.

✋
Human approval

Nothing runs until a person approves the plan. Signed links or the web view.

◈
Full audit trail

Every webhook, plan, approval, and PR is recorded, append-only.

How Dualzo turns GitHub issues into pull requests

Four steps. A human stays in the loop on the one that matters.

1
Select a repo and describe the work.

Write a prompt in-app, or drop the dualzo label on a GitHub issue to start a task from there.

@kathy/flipdisc ▾
main ▾
Add rate limiting to the public API and cover it with a feature test.
2
Dualzo clones it and builds a plan.

It slices Project Memory for context and asks your chosen model — Claude, Codex, or Gemini — for an ordered, task-by-task plan.

Here is my plan:

Three tasks across the middleware and its tests.

Update 4 files ▾
3
You review the plan and the diff.

Approve, reject, or tell it what to change. Approval is required — code never runs on a plan no one signed off.

10 "middleware": [
11 − "throttle:60,1",
11 + "throttle:api",
12 ],
4
It validates, then opens a PR.

Each task is validated in a sandbox. A PR is impossible to open while validation is failing — enforced in code.

◆ Open pull request validation ✓

Use Claude, Codex or Gemini for AI pull requests

Dualzo is the governance layer — plans, approvals, validation, audit. The model underneath is yours to choose, per repository or per task. Dualzo runs it for you — no API keys to set up.

Claude
Default
Claude Code, headless
  • ›Anthropic Claude models
  • ›Deep multi-file edits
  • ›No API key needed
Codex
Available
OpenAI Codex CLI
  • ›OpenAI models
  • ›Great at focused fixes
  • ›Same plan → approve → PR flow
Gemini
Available
Google Gemini CLI
  • ›Gemini models
  • ›Long-context planning
  • ›Same governance guarantees

Human approval for AI code in Slack, Teams, Google Chat and email

Every plan is sent for approval by email and to your chat channels, with one-click Approve and Reject. The first person to act decides. All included free.

FREE
Email

Every workspace member gets the plan, risk, and signed single-use Approve / Reject links.

FREE
Slack

Approval cards land in the channel you choose, with Approve and Reject buttons.

FREE
Microsoft Teams

An Adaptive Card per plan, posted through a Teams Workflows webhook.

FREE
Google Chat

A card in your Chat space with the plan summary and one-click actions.

Dualzo vs running an AI agent directly on your repo

Same models, same repo. The difference is everything around the code. See how Dualzo compares with GitHub Copilot →

Agent on its own With Dualzo
Plan before code Starts editing straight away ✓ Written plan with tasks, risk, and files expected
Human approval Optional, ad hoc ✓ Required before anything runs
Validation Whatever you run locally ✓ Your repo's own lint, typecheck, test, and build in a sandbox
Failing checks Can still reach a PR ✓ A PR cannot be opened while validation fails
Secrets Runs with your local environment ✓ Ephemeral container, no Dualzo secrets, network only for installs
Audit trail Terminal history, if kept ✓ Append-only log of every step

AI code governance pricing

One plan. No seat tiers, no usage surprises on Dualzo itself.

✦ EVERYTHING INCLUDED
Team plan
$119 / month

5 seats included · billed via Paddle · cancel anytime

  • ✓Any language, any repo size
  • ✓Claude, Codex, or Gemini — no API keys needed
  • ✓Sandboxed validation on every task
  • ✓Human approval on every plan
  • ✓Full, append-only audit trail
  • ✓Email support

AI model usage included · credit-based usage limit

Questions people ask first

What is AI code governance?

AI code governance is the set of controls around AI-written code: a written plan before any change, human approval before anything runs, validation against the repository's own checks, and an audit trail of every step. Dualzo provides that layer for GitHub repositories.

How do I require human approval for AI-written code?

With Dualzo it is the default. Every plan is sent to your team by email, Slack, Microsoft Teams, or Google Chat, and nothing runs until a person approves it with a signed, single-use link or in the web view.

How is Dualzo different from GitHub Copilot?

Copilot helps a developer write code in the editor. Dualzo governs AI agents that work on their own: it turns a GitHub issue into a plan, waits for approval, validates the result in a sandbox, and opens a pull request that a human reviews and merges.

Which programming languages does Dualzo support?

Any language. Dualzo detects the ecosystem, parses the manifest, and validates using the repository's own install, lint, typecheck, test, and build commands, so support does not depend on hand-written per-language analyzers.

Does Dualzo merge code automatically?

No. Dualzo opens a pull request and stops. A human always reviews and merges. Nothing executes at all until a person approves the plan.

Which AI models can Dualzo use?

Claude, Codex, or Gemini — chosen per repository or per task. Dualzo runs the model for you, so there are no API keys to set up.

How is the generated code validated?

Each task runs your repository's own commands inside an ephemeral container with CPU, memory, and time limits, network access only during dependency install, and no Dualzo secrets in the environment. A pull request cannot be opened while validation is failing.

Does Dualzo keep a copy of my source code?

No. Your repository is cloned into an isolated working directory for the job at hand, and that directory is deleted when the job ends, including when it fails. Code is read only to plan, execute, and validate work you have approved.

How long is the audit trail kept?

Every step, from the issue to the approval, each task, each validation run, and the pull request, is written to an append-only audit log that cannot be edited. Entries are kept for 90 days and then pruned automatically.

How much does Dualzo cost?

One plan: Team at $119 per month with 5 seats included. Free credits are occasionally offered as a signup promotion — check the app for current offers. AI model usage is included in the plan, measured in credits, with a usage limit that refills automatically.

One plan. Every language. Full control.

Team — $119/month, 5 seats included. Connect a repo, choose a model, and let Dualzo open the pull request while you keep the final say.