MCM Labs apps

MCM CodeGuard

Code review and cleanup for iOS and Android.

CodeGuard reviews your merge requests, holds every change to a quality gate, and finds the code and images your app no longer uses. It runs on your Mac, so your code stays there too.

Every feature free for 14 days, no card needed. macOS 14 or later.

CodeGuard showing 47.2 MB of images that a project no longer uses. ShopApp Overview Assets Quality Security Review Unused images 47.2 MB not referenced anywhere in your code onboarding_hero@3x.png6.8 MB drawable-xxxhdpi/bg_login_v1.png5.1 MB promo_summer_2024.webp3.9 MB EmptyStateOld.imageset/empty@3x.png2.6 MB mipmap-xxhdpi/ic_launcher_2023.png1.9 MB and 212 more Show all
4 languagesSwift, Objective-C, Kotlin, Java
2 code hostsGitHub and GitLab review
0 serversEverything runs on your Mac
14 daysEvery feature, free, no card

Works with the tools your team already uses

  • Swift
  • Kotlin
  • Objective-C
  • Java
  • GitHub
  • GitLab
  • SwiftLint
  • ktlint
  • Claude
  • OpenAI
  • OpenRouter
  • Ollama
  • LM Studio
  • SARIF

One app for the whole review

From the first scan to the merge button, CodeGuard covers the checks your team runs by hand today.

A reviewer on every merge request

Point CodeGuard at a merge request on GitLab or a pull request on GitHub. It checks only what changed, marks the request passed or failed against your quality gate, and comments on the exact lines that need attention. Comments are posted in your name, from your own account.

A merge request comment from CodeGuard: the quality gate failed with two new issues, and an inline comment suggests replacing a force unwrap. Quality gate failed 2 new issues, 1 resolved, no new security findings Failed 41func load(_ response: ProfileResponse) { 42+ let user = response.user! 43 render(user) Force unwrap can crash If the response has no user, the app crashes here. Unwrap it safely and return early instead. Suggested change guard let user = response.user else { return } Rule: force-unwrap

Finds what your app no longer uses

Unused images and dead code, oversized files, and exact duplicates. Optimise images in place, with a backup of every file it changes.

One quality gate for the whole team

Rules and accepted findings live in a .codeguard folder in your repository. Commit it once and everyone works from the same rules.

Security and secret scanning

Catches risky code and leaked keys in source, XML, property lists, and .strings files before they reach a release.

Bring your own AI

AI fixes and reviews use the provider you already pay for, or a model running on your own Mac. CodeGuard adds nothing on top.

Export and share

HTML reports for people and SARIF for your other tools. Baselines let you adopt CodeGuard without fixing years of old findings first.

What it checks

CodeGuard recognises an iOS project by its Xcode project or asset catalog, and an Android project by its manifest or Gradle build.

CheckCovers
Quality rules, duplicate and dead code, complexity, hotspots, architectureSwift, Objective-C, Kotlin, Java
Security and secret scanningThe same four languages, plus XML, property lists, and .strings files
Dependency auditPodfile, Package.swift, build.gradle
LintersSwiftLint and ktlint, when installed
Image size, format, and exact duplicatesAny project
AI merge request reviewAny language, since it reads the raw diff

Not analysed: JavaScript, TypeScript, Dart, and other stacks. For React Native and Flutter apps, CodeGuard checks the native iOS and Android parts only.

Your code stays on your Mac

There is no CodeGuard server. Scans run locally, and there are no analytics or crash reports. The app connects to the internet only in these cases:

  • Licence checks send your licence key and your Mac’s name to our payment provider, about every 14 days.
  • Update checks ask mcmlabs.org for a newer version once a day. You can turn them off.
  • AI features send the code involved to the AI provider you set up, and to no one else.
  • GitHub and GitLab receive what you ask CodeGuard to fetch or post there.
Read the privacy policy
Your source code stays inside your Mac. Only the AI provider you choose receives code. Your Mac your code your AI provider Nothing reaches MCM Labs.

Simple pricing

Start with 14 days of everything. Keep the Free plan for as long as you like.

Billing period

Free

To try it on one project

$0

Download
  • 1 project
  • 50 image optimisations a month
  • Image scan and insights, oversized and duplicate images
  • Unused image and code detection
  • Quality and security findings, view only

Pro

For one developer

$10 a month

Start free trial
  • Everything in Free, with no limits
  • Quality rules and security scan
  • SwiftLint and ktlint
  • AI fixes with your own provider
  • HTML and SARIF export, baselines, custom rules
  • Email support

Team

For 3 or more developers

$20 per seat a month

Start free trial
  • Everything in Max
  • Shared team rules and baselines
  • One licence key for the whole team
  • Priority support and onboarding

Every new install gets 14 days of Max, with no card. After that it continues on Free unless you buy a plan. Prices are in US dollars; tax is added at checkout where it applies. Refunds within 14 days.

Compare every feature
FeatureFreeProMaxTeam
Projects1UnlimitedUnlimitedUnlimited
Image optimisations50 a monthUnlimitedUnlimitedUnlimited
Scan, insights, oversized and duplicate imagesYesYesYesYes
Unused image and code detectionYesYesYesYes
Quality rules and security scanView onlyYesYesYes
SwiftLint, ktlint, git client, open in your IDENoYesYesYes
AI fixes with your own providerNoYesYesYes
HTML and SARIF export, baselines, custom rulesNoYesYesYes
GitHub and GitLab review, quality gate, inline commentsNoNoYesYes
Architecture graph, hotspots, trendsNoNoYesYes
Shared team rules and baseline profilesNoNoNoYes
SupportCommunityEmailPriorityPriority and onboarding

Download MCM CodeGuard

Version 1.0 for macOS 14 Sonoma or later. Signed and notarised by Apple, and it updates itself when you allow it.

The first release is in final testing. Write to support@mcmlabs.org and we’ll email you when it’s out.

Download for macOS

For smaller images, install pngquant and webp with Homebrew. CodeGuard uses them when they’re present.

Questions

Does my code leave my Mac?

Only when you use an AI feature, and then only to the AI provider you set up. Use a model running locally through Ollama or LM Studio and it never leaves at all. MCM Labs never receives your code.

Do I need an AI subscription?

No. Scans, rules, and the quality gate work without one. AI fixes, explanations, and AI review use the Claude CLI, an Anthropic API key, or any OpenAI-compatible provider, which you pay directly.

What happens when the trial ends?

CodeGuard carries on as the Free plan. Nothing is charged, because the trial never asked for a card. Your projects, rules, and results stay where they are.

Does it work offline?

Yes. Scans are local. A paid licence is checked about every 14 days, and if CodeGuard can’t reach the licence server it keeps working for 30 more days.

How do Team seats work?

Each seat activates CodeGuard on one Mac, for someone who works for your company. To move a seat, deactivate that Mac in the app and activate another. Team starts at 3 seats.

How do I cancel or get a refund?

Cancel any time from the link in your receipt email; your plan runs until the end of the period you paid for. Ask within 14 days of your first payment, or of a yearly renewal, and we refund it in full. Refund terms.