VibeRaven

Claude Code Security vs a pre-deploy review: what does each one do?

Claude Code Security, which Anthropic now calls Claude Security, is a vulnerability scanner: Claude reads and reasons about your codebase, verifies its own findings and suggests patches you approve, as a managed service on Claude Enterprise or as a plugin inside Claude Code. A pre-deploy review for a Vercel + Supabase app asks a narrower question right before you ship: is this stack set up safely, with RLS on, secret keys on the server and webhooks verified. They overlap on some security bugs and are built for different moments, so using both is reasonable.

Why this matters

Searches for "claude code security" cover several things Anthropic ships, and they are easy to mix up: a managed scanning product, a plugin that runs the same kind of scan in your own session, a one-off /security-review command, a plugin that reviews code as Claude writes it, and Code Review on pull requests. Knowing which is which tells you what each one looks at and when, and where a stack-specific check before deploy still fits.

What we do not know yet

  • Whether Claude Security or /security-review reports a Supabase table without RLS, a using (true) policy or a secret key behind NEXT_PUBLIC_. Anthropic's docs describe classes of vulnerability, not checks for a particular host or database, and we have not run either tool on a fixture to find out.

Anthropic's security tools for Claude Code, from its docs

  • Claude Security, announced on February 20, 2026 as Claude Code Security, a limited research preview for Enterprise and Team customers: a managed service that scans connected repositories, puts each finding through an adversarial verification pass and proposes a patch for a person to approve. Anthropic's product page now lists it in public beta for Claude Enterprise, with scheduled scans and findings sent to Slack or Jira.
  • The Claude Security plugin: /claude-security in a Claude Code session runs a multi-agent scan of a whole repository, a branch diff, a pull request or a single commit, and writes the report as Markdown, JSONL and SARIF. Patches go to a folder and are never applied automatically. Anthropic's docs note that scans are nondeterministic: two scans of the same code can surface different findings.
  • /security-review: a built-in command that analyzes the diff between your branch and origin's default branch for risks such as injection, auth issues and data exposure.
  • The security guidance plugin: once installed, Claude reviews its own code changes for common vulnerabilities while it works and fixes what it finds in the same session.
  • Code Review: multi-agent reviews of GitHub pull requests for logic errors, security vulnerabilities and regressions, in research preview for Team and Enterprise. Findings are tagged by severity, and approving or merging stays with your existing review workflow.

Where each one fits

What Claude Security is built for

Anthropic describes it as reading and reasoning about code "the way a human security researcher would": understanding how components interact, tracing how data moves through the application, and catching vulnerabilities such as flaws in business logic or broken access control that rule-based tools often miss. Every finding is verified before you see it, and every patch needs a person to approve it.

What a pre-deploy review for Vercel + Supabase is built for

A narrower check of the places where a vibe-coded app on this stack often goes wrong: migrations that leave a public table without RLS or with a using (true) policy, a secret key behind NEXT_PUBLIC_, a Stripe webhook that skips signature verification, env vars the code reads that nobody documented, and env files git is not ignoring. It applies fixed rules to the files in the repo, and most findings name the file they come from. It does not reason about business logic the way a model-based scanner does.

AI code review tools: CodeRabbit and Greptile

CodeRabbit reviews each new pull request with multiple AI models, reviews later commits incrementally, and can also review uncommitted changes in the IDE or CLI. Its separate CodeRabbit Security product, in beta, adds an AI Deep Scan that analyzes the committed source code and infrastructure configuration beyond the pull request diff; the scan is usage-based and billed separately from the Advanced and Enterprise review plans. Greptile builds a graph of your whole repository, reviews each pull request with that context, posts its findings as comments in about 3 minutes, and learns from your team's reactions. In pull request review, both comment on the bugs, logic and security issues in the change in front of them.

How review tools differ from a pre-deploy review

A code review tool asks whether this change is good. A pre-deploy review asks whether the whole repo, as it stands right before you ship, has the stack-specific gaps that expose data or money. A migration merged months ago that never enabled RLS is not in today's diff, so a review of that diff may not mention it, unless the tool also scans the whole codebase, as CodeRabbit's AI Deep Scan does. A whole-repo check reads it again before each release. Use review tools on pull requests and a pre-deploy review before a release.

Go deeper: AI Code Review vs Launch Readiness

Optional repo check

For AI-built Vercel + Supabase apps, npx -y viberaven@1.6.3 check is a pre-deploy review for vibe-coded Vercel + Supabase apps of the kind described above. In runs on a fixture repo on 2026-10-05 it reported a public table without RLS, NEXT_PUBLIC_SUPABASE_SERVICE_ROLE_KEY in .env.example and a Stripe webhook handler with no signature check, each with its file. Results can differ by operating system for now: on Linux the same repo also got rate limit and health route findings, which 1.6.3 misses on Windows paths. It did not flag a Stripe secret key hardcoded in a client file, and it does not reason about business logic, so it does not replace a scanner such as Claude Security or a code review tool. It is advice, not a gate, and a repository check, not a live database or security test. It exits with code 1 when it finds a blocker and writes a .viberaven folder that it does not add to .gitignore.

Related guides

Sources

Is Claude Code Security free?

The managed Claude Security product is for Claude Enterprise. The Claude Security plugin runs in your Claude Code session on a paid plan, with Anthropic API access or on a supported cloud provider, and each scan counts toward your usage.

Does /security-review replace a pre-deploy review?

They answer different questions. /security-review looks at the changes on your branch for vulnerabilities; a pre-deploy review for Vercel + Supabase looks at the whole repo for stack setup gaps such as tables without RLS. Running both before a release is reasonable.

Do I need CodeRabbit or Greptile if I use Claude Code?

Not necessarily. Claude Code has its own /code-review command and the Code Review service for pull requests. Dedicated review tools add things such as learning from your team's reactions or context from related repositories, so it depends on how much you lean on pull request review.