DevGuardian AI — Multi-Agent Code Review & Architecture Governance Platform
DevGuardian AI is a code review platform I designed and built in 2024 and 2025 as a product of my own. A virtual senior engineering team of AI agents, an Architect, a QA reviewer and a Security reviewer, reads every change, backed by a retrieval layer built for code.
At a glance
- My role: Creator & Architect; I architected and built the platform end to end
- Years: 2024–2025
- Origin: my own product and startup idea, built for myself rather than for a client
- What it is: a virtual senior engineering team of role-based AI agents (Architect, QA and Security) that reviews code
- Retrieval: code-aware chunking, GraphRAG on Neo4j, incremental embedding refresh and hybrid retrieval
- Built on: ASP.NET Core, Blazor, Microsoft Agent Framework and Azure OpenAI
- Status: licensed once, to Valco AI; no longer in development or for sale
The challenge
Architecture governance doesn’t scale the way engineering teams do. The senior engineers who can catch a bad architectural decision, a security gap or a quietly growing pile of technical debt are the same people who are too busy to review every pull request that needs it. Their judgment can’t be written into a linter or a style guide. It depends on knowing how a change ripples through the codebase’s dependency structure, and a diff alone doesn’t show that.
The architecture
DevGuardian AI is built as a virtual senior engineering team. Three role-based agents, an Architect, a QA reviewer and a Security reviewer, each review a change with their own mandate. The platform runs on ASP.NET Core and Blazor, with Microsoft Agent Framework and Azure OpenAI behind the agents.
At the core is a retrieval architecture designed for code:
- Code-aware chunking. Source is parsed into chunks at the class, method, interface and SQL-statement level, so each chunk is a unit of code with meaning. Generic RAG systems split by token count.
- GraphRAG on Neo4j. The codebase’s dependency graph is modeled in Neo4j, so an agent can reason about what else breaks when a piece of code changes, as well as what looks similar to it.
- Incremental embedding refresh. The index is keyed to git commit hashes and updates only what a commit changed. A review never re-embeds the whole repository.
- Hybrid retrieval. Semantic, symbolic and graph-based signals are combined for each query, so vector similarity is one signal among three.
Repository analysis runs on Roslyn for semantic parsing and LibGit2Sharp for git history. Vectors are stored in SQLite, and Hangfire runs the background jobs. Every repository also builds up a “Project Memory Bank”: a persistent record of technical debt, architectural violations and review history, so each review starts from everything the system has already learned about that codebase.
My role
I architected and built the platform end to end: the multi-agent role design, the retrieval and graph infrastructure, and the repository-analysis pipeline underneath it.
Outcome
- Licensed once, to Valco AI, with changes I made for its internal development team
- Not developed further: it began as a startup idea of mine, and I’m no longer working on it or selling it
Stack
ASP.NET Core · Blazor · Microsoft Agent Framework · Azure OpenAI · Neo4j (GraphRAG) · SQLite · Roslyn · LibGit2Sharp · Hangfire