The migration passed review.
It still took down production.

Bolvrk catches dangerous Postgres, SQLite and SurrealDB changes and committed secrets before they ship, whoever or whatever wrote them. Deterministic, no model in the verdict, ever. The CLI is open source; the full corpus runs in the cloud.

npx bolvrk check migration.sql
Sign in with GitHub

Free for individuals and open source. Teams pay flat per team, never per seat, and start without a sales call.

01 · On the pull request

A PR opens. Rules judge it. The findings land in review.

The migration in the PR
migrations/0042_orders_region.sql
ALTER TABLE orders
  ADD COLUMN region text NOT NULL;
CREATE INDEX idx_orders_region
  ON orders (region);
The rules that fire
BV002 NOT NULL column without a default
BV003 Index built without CONCURRENTLY
BV034 No lock_timeout guard
See all 135 rules in the reference →
What we answer
bolvrkcommented on the PR
critical
Fails on any populated table: add the column nullable, backfill, then SET NOT NULL.
warning
The index build blocks every write to orders, use CREATE INDEX CONCURRENTLY in its own migration.

3 findings · exit 1, one evolving comment, not a pile.

02 · The failure mode

The change is fast. The queue behind it isn't.

A lock that takes milliseconds still parks every write behind it, and on a hot table the backlog is the outage. That's why Bolvrk reads your real schema's shape and traffic: the same ALTER is harmless on a quiet table and a production incident on a busy one, and a checker that can't tell the difference is just noise.

03 · Why now

AI writes more of your change stream every quarter

More of the change stream is written by AI now; review capacity hasn't kept up. Verification is the missing layer: judge the change, not the author. Your model proposes, our deterministic checker decides, and no AI is ever part of the verdict. Database changes and committed credentials are covered today; more surfaces are on the way.

04 · Workflow

Three layers of defense

  1. Check locally

    npx bolvrk check, the open-source CLI, runs the free outage rules over the database's real parse tree before the change ever leaves your machine.

  2. Gate every pull request

    The GitHub Action checks changed migrations and comments the findings where review happens, free rules on the Free plan, the full corpus on Startup and above. Connect a database and it checks against your live schema: table sizes, foreign keys, column types.

  3. Put it inside the agent

    Add bolvrk mcp to Claude, Cursor or any agent framework and the agent verifies its own work before it reports done, a deterministic verdict it can iterate against, with AI never part of the verdict. Every connected run is logged: your system of record for what an agent tried to ship and how often it was stopped.

05 · Frameworks

Your ORM writes the SQL. Bolvrk checks what it wrote.

An @@index line in a Prisma schema becomes a plain CREATE INDEX, which holds a SHARE lock on the table for the whole build. Nothing in the schema file says so, the reviewer approves the schema file, and every framework defaults away from the safe form. So the check runs on the SQL the framework generated, in the folder it keeps it.

No files named, no config: npx bolvrk check finds the layout, and the GitHub Action does the same with an empty migrations input. Prisma and Drizzle also say which database they target, so a SQLite project gets the SQLite corpus without a flag, and a surrealdb-migrations project gets the SurrealDB corpus the same way. Rails, Django, Knex and TypeORM keep no SQL on disk, so bolvrk capture runs their migrate command against a throwaway Postgres and checks what it executed. How it works.

ORMSQL
  • Prismaprisma/migrations/*/migration.sql
  • Drizzledrizzle/*.sql
  • Supabasesupabase/migrations/*.sql
  • FlywayV*__*.sql
  • Liquibaseformatted SQL changelogs
  • Hasuramigrations/**/up.sql
  • dbmatedb/migrations/*.sql, up section
  • golang-migrate*.up.sql
  • sqlxmigrations/*.sql
  • Atlasmigrations/*.sql + atlas.sum
  • Sqitchdeploy/*.sql
  • Martendb-patch output, or capture
  • surrealdb-migrationsmigrations/*.surql, SurrealDB
06 · Credentials

Secrets caught before the commit

A seeded admin with password 'admin', a role created with its password inline, a Stripe key in an INSERT: committed, reviewed, and kept in git history forever. The BC rules catch them before the commit, and every finding masks the value.

The same rules run over any file with bolvrk secrets. Published vendor formats only, never entropy guesses, so a uuid or a bcrypt hash stays silent. A credential scan never leaves your machine.

.env
DATABASE_URL=postgres://app:hunter2@db.internal/app
STRIPE_SECRET=sk_live_51H8zK2eZvKYlo2C…
JWT_SECRET=correct-horse-battery
npx bolvrk secrets ".env*" "src/**"
3 findings
BC003 critical  .env:1  connection string with an embedded password, postgres://app:***@db.internal/app
BC004 critical  .env:2  Stripe secret key in a literal, sk_live_***
BC006 warning   .env:3  JWT_SECRET given a literal value, ***
3 findings · exit 1 · nothing left this machine
07 · Rules

A rule corpus that earns its claims

Every rule ships with fixtures in both directions, dangerous variants that must fire, safe look-alikes that must stay silent. Every claim is proven against the real thing: observed lock modes, observed rewrites, never a guess. Credential rules match published secret formats only.

135rules across every engine
2×fixtures per rule, both directions
14rule categories, locks to credentials
08 · Why it holds

Deterministic, in an increasingly non-deterministic world

Real parser, never regex

Every rule runs over the database's actual parse tree. What parses in production parses in Bolvrk, and AI output never enters the verdict.

Checked against your schema

On a paid plan, findings are refined against your table sizes, foreign keys, and column types, read from catalogs in a read-only transaction, from the replica or shadow database you point us at. Findings about your database, not a hypothetical one.

Claims proven, not asserted

Every lock and rewrite claim is validated empirically against a live database in CI, observed lock modes, observed rewrites.

09 · The record

Every connected run, remembered

The cloud is your system of record: every check from every connected client lands in the run log, and Insights rolls it up, which rules fire most, how the clean-run rate trends, where the process is drifting. Recurring findings are process problems, not people problems; now they're visible.

10 · Pricing

Pricing

Startup

$29/month

Flat per team, never per seat, self-serve, no sales calls

  • Everything in Free
  • The full corpus: every rule, on every check
  • Live-schema (tier-2) refinement: table sizes, traffic, foreign keys
  • 2 stored connections
  • Insights over the last 30 days
  • Email support
Set up your team

Team

$99/month

Govern it as a team, protect more surfaces

  • Everything in Startup
  • Team policy: the block threshold and per-rule overrides, on every connected check
  • 8 stored connections
  • Insights over the last year
  • Migration rehearsal: how long each change would block traffic on your actual tables, in the PR
  • Database health: opt any connection into a weekly audit for unused, redundant and invalid indexes, unindexed foreign keys and unanalysed tables, or run one on demand
  • Hosted MCP server: the verifier as a tool inside Claude, Cursor and agent frameworks
  • Email support
Start on Team

Scale

$199/month

Every database, all of the history

  • Everything in Team
  • 25 stored connections
  • Insights, unlimited
  • Priority support
Start on Scale

Enterprise

Custom

Your limits, your terms, your servers

  • Everything in Scale
  • On-prem: one executable, one config file, your Postgres. Nothing leaves your network
  • GitHub Enterprise Server sign-in
  • Custom connection limits, set by us for you
  • Invoicing & procurement support
  • Direct line to the team
Talk to us

Prices in USD, flat per team. VAT is added at checkout where it applies; EU businesses with a VAT number are not charged VAT.

Free, forever

$0

For every individual and open-source project

  • Open-source CLI with the free rules, locally
  • The free rules, in the cloud: run log, PR comments, notifications
  • Sign-in, team and tokens, the GitHub Action, findings feedback
  • Unlimited checks: validation is never metered
  • Insights start on Startup: the run log itself is kept on Free
Install the CLI

Full pricing details and FAQ →