Iru · GTM Architecture · Market Intelligence
Every vendor that touches the path from prompt to merged code, mapped across the four segments briefed, plus a fifth cross-cutting layer the product documentation exposed. Built for Hyrax competitive positioning. Financial figures are shown only where a dated, named source exists.
Unclaimed. CodeRabbit owns AI code review. Sonar owns code quality. Cognition owns AI software engineer. Nobody has taken this one.
Same shape as Devin, Cursor and CodeRabbit. The noun is the category claim.
| Why | To keep human judgment at the center of software, so that speed never costs a team the quality of what they build. |
| How | Learn the system before judging the change. Bring specialist judgment, not generic rules. Prove every fix against the team's own tests. Hand the decision to a human, always. Give back what we learn to every tool the team uses. |
| What | Repo-wide audits. Merge-ready pull requests. Architecture published into the repo where Cursor, Copilot and Claude Code read it. |
The open question. Workflow naming. The approved framing is four workflows, Scan, Fix, Improve and Govern. The live product documentation lists seven: Full audit, Standard audit, Discovery, Revalidate, PR review, Fix and Publish. This map uses the seven because it has to match what a customer sees. That needs a decision before either list goes external.
The capability floor. Everything above this band either resells these models or competes with the labs that make them. The labs now ship their own end-user coding products, which puts them in direct competition with their own customers.
Assign a task, get back a pull request. This band separates on autonomy and on where the work runs. The best-capitalized players here are chasing the enterprise seat, not the individual developer.
The verification band, and the one that grew because bands 1 and 2 worked. More code written faster means more code to check. The split that matters commercially is whether a vendor stops at finding the problem or goes on to write and submit the fix.
Where the developer actually sits. This band captured the most enterprise value of the four, and it is now the least independent: the category leader is a subsidiary of a public aerospace company.
Not one of the four segments briefed, and it should have been. Coding agents rediscover the same architecture every session, guess at conventions, and invent file paths. A layer is forming that profiles a codebase once and feeds that knowledge to whichever agent is working. It sits underneath bands 1, 2 and 4 rather than beside them, and it is the quietest land grab on this map.
| Acquirer | Target | Band | Date |
|---|---|---|---|
| SpaceX | Anysphere (Cursor) | IDE | Closed Aug 14, 2026 |
| SpaceX | xAI | Model | Feb 2026 |
| Anysphere | Graphite | Review | Dec 19, 2025 |
| Anysphere | Continue | Assistant | Jun 2026 |
| Anysphere | Supermaven | Assistant | Nov 2024 |
| Cognition | Windsurf | IDE | Jul 2025 |
| ClickUp | Codegen | Agent | Dec 2025 |
| Nvidia | Poolside model licence + 109 staff | Model | Aug 2026 |
| Band | Anchor | Anchor value | Structure |
|---|---|---|---|
| Models and CLIs | Anthropic, OpenAI | $965B / $852B | Oligopoly. Capital barrier is absolute. |
| Coding agents | Cognition | ~$26B | Consolidating. Two funded leaders, long tail. |
| Readers and fixers | CodeRabbit | $1.5B | Fragmented. Widest field, lowest anchor. |
| IDEs and environments | Cursor | $60B | Captured. Leader is now a subsidiary. |
Hyrax occupies four rows across two bands, which is why a single chip in the remediation row understated it. Seven workflows run against a connected repo: Full audit, Standard audit, Discovery, Revalidate, PR review, Fix, and Publish. Every workflow is on every plan, including Free.
| Row it occupies | The workflow | What separates it there |
|---|---|---|
| Whole-repo audit band 3 | Full audit (~39 tools), Standard audit (24 tools) | Reads the whole codebase across security, correctness, maintainability, performance, architecture and operations, in 19 languages. Findings merge across runs rather than duplicating, so triage survives a re-audit. Most of the review row only ever sees a diff. |
| PR review band 3 | PR review | Must-fix and consider tiers, a Hyrax Review check run that can gate merges, capped at seven findings a pass. This is the row where CodeRabbit, Greptile and Bugbot already compete hard. |
| Autonomous remediation band 3 | Fix, Revalidate | The differentiator. Writes the edit, runs the repository's own test suite, reviews its own diff, opens a pull request, and revises the change when CI fails. A finding closes only when the pull request merges. Nothing else in the row carries verification through to a merge event. |
| Repo context for agents band 5 | Discovery, Publish, MCP server | Profiles architecture, conventions, definition of done and how-to guides, then commits them to the repo as HYRAX.md, .hyrax/discovery/ and a managed block in CLAUDE.md. An MCP server serves live findings and rules to Claude Code, Cursor and Copilot on request. |
Three horizons, widest to narrowest in confidence. Horizon 1 is the row Hyrax is judged in today. Horizon 2 is what the product already spans. Horizon 3 is what band 5 opens if the context layer becomes how agents get grounded. Every input is labelled sourced or assumed.
| Component | 2026 | Forward | Source and date |
|---|---|---|---|
| AI code review, observed vendor ARR | ~$420M | n/a | IdeaPlan, May 2026 |
| AI code review, published market size | $2.08B | $3.56B by 2032 | QYResearch, Jan 2026 · 9.4% CAGR |
| Code quality tools | ~$2.0B | $3.29B by 2032 | QYResearch · $1.91B in 2025, 8.2% CAGR |
| Static application security testing | $0.68B | $1.89B by 2031 | Mordor Intelligence, updated Jan 2026 · 22.8% CAGR |
| All AI code tools | $9.46B | $22.2B by 2030 | The Business Research Company, Jul 2026 · 23.8% CAGR |
Bottom-up check against the ICP
| Step | Value | Basis |
|---|---|---|
| Developers at companies of 51–1,000 employees, globally | 14.5M | Sourced. SlashData, early 2025 |
| US share of professional developers | 18.3% | Sourced, dated. Stack Overflow. Treat as directional |
| US developers in the size band | ~2.65M | Derived |
| Share that is GitHub-centric, AI-native and post-Series B | 10–40% | Assumed. The widest single assumption here |
| Engineers inside the ICP | 265K–1.06M | Derived |
| Annual value at the $30/user floor | $95M–$382M | Floor pricing only, before any overage |
Two things this exposes. First, the published AI code review market sizes do not survive contact with observed revenue. CodeRabbit leads the row at roughly $50M ARR. If the category were genuinely $2.08B, the clear leader would hold 2.4% of it after a $143M Series C, which is not how a category with a recognised leader behaves. The ~$420M figure is the one consistent with what vendors actually bill, and the larger number most likely absorbs bundled platform revenue that nobody buys as code review. Second, winning the entire named ICP at floor pricing produces a business between $95M and $382M a year. That is a real company and it is not a $9B market. The horizon-1 row cannot get Hyrax where it needs to go on its own.
| Today | What it has to become | |
|---|---|---|
| The row | PR review. The most crowded row on the map, and the one buyers already have a default for. | Repo context and verified remediation. Two rows almost nobody is defending. |
| Who it competes with | CodeRabbit at $1.5B, Greptile, Qodo. Plus Bugbot and Copilot review, which are bundled into a $60B parent and 4.7M paid seats and are effectively free at the point of decision. | The agents become distribution rather than competition. Claude Code, Cursor and Copilot consume published context instead of displacing it. |
| What gets sold | A better reviewer. Judged on comment quality and noise, priced per seat, compressed by two competitors who give the capability away. | A merged fix and the knowledge that produced it. Priced on work completed, which is the one axis a bundled reviewer cannot match. |
| Who buys | The person choosing a PR bot. A tool decision, easily reversed. | The platform or developer-experience org standardising how every agent in the company reads the codebase. An architecture decision, rarely revisited. |
| Ceiling | $95M–$382M a year at floor pricing across the whole named ICP. | The AI code tools market at $9.5B in 2026 and $22B by 2030, because the buyer set stops being "teams shopping for a reviewer". |
The bridge. PR review is how Hyrax gets installed, because it is the recognised budget line and the fastest thing to prove. It should not be what Hyrax is understood to be. Every audit already produces the repo knowledge that Discovery and Publish distribute, and the MCP server already serves it live to the agents. The move is to make that the headline rather than the by-product: enter through review, become the layer the codebase is understood through. The risk of staying put is specific. Two of the three strongest competitors in the review row do not need to make money on review, and a row where the leader takes $50M against a $60B bundled rival is a price-compression row, not a growth one.
HYRAX.md writes code shaped by a Hyrax audit before any review runs. That is a distribution route into band 1 and band 2 that does not require beating either of them.