What CodeRabbit Actually Announced on August 12
CodeRabbit, a five-year-old AI code review startup, raised a $143 million Series C at a $1.5 billion valuation, co-led by European venture firm Atomico and Smash Capital. New backers BMW i Ventures, Datadog, Hirtle Callaghan, SineWave Ventures and Scenic Management joined existing investors CRV, Scale Venture Partners and Flex Capital, and Atomico partner Luca Eisenstecken is taking a board seat.
The company said revenue grew more than 5x year-over-year and it now runs over 2 million code reviews a week for more than 17,000 customers, up from 8,000-plus paying customers and roughly $15 million in annual recurring revenue when it closed a $550 million-valuation Series B in September 2025. Named customers now include Adyen, BMW, Indeed, JFrog and Nvidia.
From Review Tool to Approval Authority
Alongside the raise, CodeRabbit launched Agentic Change Management, which it calls 'the control layer for governing software created by people and AI.' It validates changes against a repository's own context and an organisation's coding standards, then routes anything judged consequential to a human reviewer while auto-approving changes it scores as low-risk. Two companion features, CodeRabbit Triage and CodeRabbit Change Stack, score pull requests by value, urgency and risk, and map the system-wide impact of a given change.
That is a material step past leaving comments on a pull request: it is decision authority over what code reaches production. CodeRabbit paired the launch with CodeRabbit Security, which scans already-shipped production code for vulnerabilities - meaning the same company that just decided what to auto-approve is also the one checking, afterward, whether that decision was safe.
The Governance Problem Hiding in the Upgrade
In most regulated control functions, the party approving an action and the party auditing it are kept separate on purpose, precisely so one entity's blind spot cannot silently pass its own review. CodeRabbit's new stack collapses both sides of that check into a single vendor's risk model: the same engine that decides a change is low-risk enough to ship is philosophically the same system family now scanning for what it may have missed.
The practical exposure for an owner is not whether CodeRabbit survives - it just proved it can raise capital at will. It is what happens the day the auto-approval threshold misjudges a change, a pricing tier quietly narrows what gets scanned, or CodeRabbit's own infrastructure is breached. A single vendor's judgment now sits between AI-written code and production systems at more than 17,000 companies, many of them, like Adyen and BMW, well outside the developer-tools world.
What Owners Running CodeRabbit Should Do Now
Start with an internal audit of which repositories have opted into Agentic Change Management's auto-approval mode versus advisory-only review, and confirm the threshold routing 'consequential' changes to a human matches your own change-management policy rather than CodeRabbit's shipped default.
For EU and UK entities operating under NIS2 or DORA, an automated third-party approval decision is an outsourced control function and needs its own audit trail, the same way an outsourced payment authorisation would. Don't let a vendor's product launch quietly become your organisation's code-approval policy by default.
Read next: Lumilens Raises $700M for AI Data Center Optics | London's Robotaxi Fleet Now Runs on One Company



