Comparison
What we do that the category does not
“Has AI” is table stakes now — every incumbent shipped it. The question worth asking is narrower: when the AI says it fixed something, what exactly are you being asked to believe, and can you check it without trusting the vendor who is billing you for the answer?
How to read this page
The differences
| Dimension | The category norm | Bucker |
|---|---|---|
| What "verified" means | A model asserts the fix is correct, and a pull request appears. The claim is a sentence in a description field. | A repro test that failed before the patch and passed after it, a suite result, and a verification tier that an audit function refuses to inflate. Tier A requires a full suite that passed; tier C is what you get when there is no passing suite. |
| Whether you can check it yourself | Verification, where it exists, is something the vendor did and reports on. There is nothing to re-run. | The evidence bundle is signed Ed25519 over DSSE and carries an RFC 6962 Merkle inclusion proof. The bucker-verify CLI re-derives every claim offline, makes no network calls, and can check the signature against a key you supply rather than the one inside the document. |
| Where you approve | You leave your editor, open a dashboard, find the item, and click. MCP servers, where they exist, are read surfaces. | The MCP server implements input_required, the standards-track human-approval primitive, across its write tools — and renders the approval and evidence cards as MCP Apps when the client negotiates for them. You answer the prompt in Claude Code. |
| Payload shape for agents | Human-shaped JSON served through an MCP wrapper: whole stack traces, unbounded breadcrumb arrays, no published size. | A bounded projection under 500 estimated tokens with the count published on every response, a reduction ladder that reports what it dropped, hydration handles to fetch the rest deliberately, and a pinnable schema version. |
| AI application failures | Traces and evaluation scores in a separate observability product, with their own vocabulary and their own inbox. | Detectors for tool-schema violations, retry loops and silent truncation call the same ingest function your crashes do. One fingerprint, one lifecycle, one alerting path, one remediation loop. |
| Agent permissions | An organization-level AI toggle, and a setting for whether the bot may open a PR. | Agents are principals with sponsors, RFC 8693 delegation chains, budgets scoped to (agent, human, incident) that reserve before each generation, incident-bound blast-radius tokens, action-granular audit, and automatic token revocation on anomalous behaviour. |
| Who can merge | Configurable. Auto-merge is often a roadmap item or an opt-in setting. | A human, unconditionally. Refused to non-human principals before policy is consulted, the scope filtered out of every agent token, the trust ladder pinned so no rung reaches it — and no merge method in the source-control client to call. |
| Single sign-on | Frequently gated behind the enterprise tier; the "SSO tax" is a documented churn trigger. | On every paid tier, alongside SCIM — including SCIM for agent principals. A test fails the build if a paid tier stops including it. |
| Seats | Per-seat pricing, sometimes per contributor, so the bill grows as the team does. | Unlimited human seats on every tier. There is no seat-count field in the plan schema; the type is the literal string "unlimited". Agent principals are capped, because they have real marginal cost. |
| A spike in traffic | Metered per event, so an incident is also an invoice. Spike protection, where it exists, may stop ingesting. | Over-quota events cost nothing and degrade to deterministic stratified sampling, with every degraded event receipted. A storm from one deploy is one issue and can produce at most one billable fix. |
| Unused credits | Commonly expire at the end of the billing period. | Roll over on every tier, spent before you are metered — capped at three months of your allotment, which we state rather than bury. |
| Self-hosting | Where offered, often a large container topology with a broker, a column store and a separate ingest relay. | Community Edition is four containers — Postgres, API, worker, web — and a test fails the build if that number reaches five, or if a broker, column store or cache appears in the compose file. |
| The price | Frequently "contact us" from the first paid tier upward. | Published, and read at build time from the same public endpoint the product reads when it enforces your quota, so the page cannot drift from the ladder. |