Skip to main content
This page explains how Corridor helps secure AI-assisted development and the fundamental concepts you’ll encounter when using the platform.

Core concepts

Projects

A project represents a codebase that Corridor monitors. Projects are typically linked to a GitHub repository and track:
  • Guardrail invocations: Real-time security analysis during AI code generation
  • PR reviews: Automated security analysis of pull requests
  • Findings: Security issues discovered in your code

Teams

A team is a group of users who share projects, security policies, and billing. Every project belongs to exactly one team.

Team roles

Guardrails

Guardrails are security rules that analyze AI interactions in real-time. Corridor integrates directly into your AI coding workflow via MCP and Hooks. When developers use agents such as Claude Code, Cursor, or VS Code with AI assistants, Corridor evaluates code generation requests and provides security context back to the AI. Unlike traditional static analysis that runs after code is written, guardrails operate during the AI generation process itself: security context is provided before code is generated, allowing the AI to avoid vulnerable patterns and prevent vulnerabilities rather than detect them after the fact. When a Scheduled Agent or an AI assistant edits a guardrail, guardrail versioning (private beta) keeps an append-only history in the app and through MCP. You can restore an earlier version without losing later ones. Updating and archiving through MCP is a separate private beta. See Guardrails.

Context

Context is your own knowledge, added to Corridor so guardrails analyze code with your organization in mind. A context is a named note or uploaded document that you attach to a project. Where guardrails define the security rules to enforce, context supplies the background those rules need: internal libraries, approved patterns, coding standards, and policy excerpts specific to your codebase. Context makes guardrail analysis more relevant and reduces false positives. Each context applies to one or both of these places:
  • PR Reviews: Corridor considers your context when it reviews pull requests
  • MCP Plan: Corridor supplies your context to AI coding agents so they generate code that fits your standards
Custom context is available on Team and Enterprise plans. See Configuring Guardrails for how to add it.

Findings

A finding is a security issue discovered by Corridor. Findings can come from PR reviews, guardrail violations, or code scans. Enterprises can use the Corridor Agent to investigate and scan existing code. Scheduled Agents are in private beta. They run that same work on a cadence or when findings change. Each finding includes severity, state, code location, and actionable remediation steps. Track findings through resolution and monitor your security posture over time.

PR reviews

Every pull request is automatically reviewed for security issues. When enabled, Corridor receives a webhook when a PR is opened or updated, analyzes the code changes for security vulnerabilities, and posts a review with specific findings and remediation guidance directly on GitHub. You can also configure Corridor to block PRs with critical issues from merging.

MCP Compliance

MCP (Model Context Protocol) is the standard that allows AI assistants to use external tools. Corridor lets teams control which MCP servers are allowed through compliance policies. MCP servers can access files, make network requests, and execute code. Without oversight:
  • Sensitive data could leak to unauthorized services
  • Unapproved tools could introduce security risks
  • Shadow AI usage becomes invisible to security teams

Tier comparison

Next steps

Quickstart

Set up Corridor for your team

Guardrails

Learn about real-time security analysis