Most "best self-hosted AI code review tool" lists repeat each other's claims and rarely say which edition they read or when. For a team on GitLab Self-Managed, Azure DevOps Server, or Bitbucket Data Center, that gap decides the answer, because "can this run inside our network" changes with the edition, not with the product name.
This page records what CodeRabbit and Qodo document for on-prem deployment, read from their own docs, and puts the Kodus self-hosted path on the same criteria. Where the docs do not establish something, I say so instead of filling the cell.
CodeRabbit self-hosted: Enterprise plan, 500+ seats
Per CodeRabbit's self-hosted overview, the self-hosted option is Enterprise plan only and starts at 500 user seats. The review agent runs inside your infrastructure as a container image, on a bare server, a container platform, or a serverless workload.
Supported platforms listed: GitHub Enterprise Server, GitLab self-managed, Azure DevOps, and Bitbucket Data Center.
Code and pull request data stay in your environment. The review prompts and source code leave it only to reach the LLM provider you configure, so you bring your own model. For a forge that cannot accept inbound connections, the CodeRabbit Reverse Tunnel keeps all connections outbound from your network.
The install instructions are handed to customers during onboarding and are not published. Worth stating plainly, because the absence of a public install guide is not the absence of the feature.
Qodo on-premises: Kubernetes, six Git integrations
Per Qodo's on-premises page, Qodo deploys on Kubernetes inside your infrastructure. Git integrations cover GitHub App, GitLab App, Bitbucket Cloud App, Bitbucket Data Center, Azure DevOps App, and Gerrit. Qodo keeps a separate install path for cloud-hosted Git instances, which is the detail people miss when they assume one on-prem flow covers both.
Same documentation gap as CodeRabbit: the architecture and Helm chart pages sit behind an Enterprise engagement rather than in the public docs.
Kodus self-hosted: the free tier runs on your own key
Kodus splits on pricing rather than on a hidden install guide. The Community plan is free, and per the Kodus pricing page it runs self-hosted or cloud with unlimited users and unlimited pull requests, running on your own provider key. BYOK is the default across every plan, so tokens are billed by your provider and Kodus does not mark them up.
The self-hosted path is documented, not hand-held. The Kodus CLI has a self-hosted setup guide that points the CLI at your own API, including a team key for shared environments and Cloudflare Access service-token support for instances behind Zero Trust. That is enough to run reviews from a pipeline with --fail-on error and fail the build on findings above a severity threshold.
The trade-off sits at the feature level, not the deployment level. Community caps Kody Rules at 10 and plugins at 3, while Teams and Enterprise lift those limits. Cockpit metrics, SSO, and RBAC are Teams and Enterprise. A small self-managed team can run Kodus free and on-prem and pay only for the features it needs, which is a different shape from a 500-seat Enterprise floor.
Where the self-managed edition is the whole question
Both verified vendors cover self-managed GitLab, Azure DevOps, and Bitbucket Data Center in their on-prem docs. That is not universal across the market. GitHub Copilot code review for Azure Repos, for example, is documented for Azure DevOps Services only, and it is in limited preview. There is no Server edition of it. So a team on Azure DevOps Server is not choosing between Copilot and a third-party reviewer; it has no native option to choose from.
If you want the fuller picture of what runs natively on each forge versus what has to come in through a pipeline task or webhook, that is covered per platform elsewhere. For the self-managed code review options that install as a pipeline job or webhook rather than a hosted app, PR-Agent is the one worth reading about.
The comparison, on shared criteria
| CodeRabbit self-hosted | Qodo on-premises | Kodus self-hosted | |
|---|---|---|---|
| Minimum to start | Enterprise plan, 500+ seats | Enterprise contract | Community (free) |
| Deployment unit | Container image, server or serverless | Kubernetes | Self-hosted instance, CLI points at your API |
| Git platforms documented | GitHub Enterprise Server, GitLab self-managed, Azure DevOps, Bitbucket Data Center | GitHub, GitLab, Bitbucket Cloud, Bitbucket Data Center, Azure DevOps, Gerrit | GitLab, Azure DevOps, Bitbucket among supported providers |
| Model / tokens | BYO model | Not stated on the public on-prem page | BYOK on every plan, no markup |
| Install instructions public | No, onboarding | No, behind Enterprise engagement | Yes, documented CLI setup |
| Air-gap-friendly | Outbound-only via Reverse Tunnel | Not stated on the public page | Not stated as a packaged air-gap mode |
Not stated means the public docs do not establish it. For an air-gapped network, that cell is the one to confirm with each vendor directly, because none of these pages commit to a full offline model cache.
What actually decides it
The seat floor is the first filter. If you have 40 developers on GitLab Self-Managed, CodeRabbit self-hosted is not on the table at 500 seats, regardless of how good the agent is. Qodo and Kodus both start lower, and Kodus starts at zero for the deployment itself.
The second filter is how much you trust an unpublished install. Enterprise onboarding is fine for a large org with a procurement process. A five-person platform team trying to stand something up this week is better served by a documented CLI and a BYOK key they already have.
The third is feature limits against your own rules. If your review needs come down to enforcing your team's coding standards, check where the rule ceiling is before you commit: 10 Kody Rules on Community is a real constraint for a large codebase, and the same is true of a 3-plugin cap.
Read the vendor's own page for the edition you plan to run, not the marketing page for the product. The edition is where the answer actually lives.
Top comments (0)