AUTOSAR C++14 · MISRA C++:2023 roadmap · On-prem ready · Powered by Coda

The compliance gap
Coda closes it.

Static analysis tools cover 329 of 397 AUTOSAR rules. The remaining 68 require human judgment. Until now. Meet Coda, the AI agent built for software that controls physical systems. Starting with automotive. Built for what comes next.

coda: analyze vehicle_controller.cpp
$ coda analyze src/vehicle_controller.cpp --ruleset autosar-cpp14
ℹ Running AST checks...
✓ 329 automated rules checked, 0 violations found
ℹ Coda evaluating 68 rules static analysis can't fully cover...
✗ VIOLATION A10-0-1 · line 42
VehicleController inherits from DataStore, but this is a "has-a" relationship. DataStore should be a member, not a base class. Public inheritance implies substitutability which is not intended here.
✗ VIOLATION A8-4-14 · line 87
Parameter 'config' typed as void*. The interface is not precisely typed. Use a specific struct or strongly-typed enum to express intent.
✓ A15-0-1: exception safety passed
Function exits cleanly in all identified paths. No evidence of partial state on exception.
⚠ 2 violations · 1 advisory · 10 rules checked by Coda
2 violations static analysis tools would not have caught
$
The Gap

Static analysis has a ceiling.
Coda breaks through it.

Existing static analysis tools are excellent at syntactic rule enforcement. But AUTOSAR explicitly marks 68 rules as non-automated or only partially automatable. These rules require understanding design intent, architectural relationships, and semantic meaning. These are the rules that cause the most serious safety failures. The same gap exists in MISRA C++:2023, and Coda's semantic reasoning layer applies directly to both.

329
Existing tool coverage329 of 397 AUTOSAR rules fully covered by existing static analysis tools. The syntactic ceiling.
68
Rules nobody fully checksNon-automated and partially automated rules requiring human judgment. Until Coda.
AUTOSAR C++14 Rule Coverage
Static analysis tools329 / 397
Uncovered gap68 rules
Codabase (AST + Coda)397 / 397
AST layer: deterministic, syntactic rules
Coda layer: semantic, intent-based rules
Gap closed by Codabase
Pipeline

How Codabase works

Five stages. Two layers of intelligence. One prioritised, noise-reduced compliance report.

01
Parse
Point coda at your compile_commands.json. Coda handles the rest.
02
AST Check
329 fully automated AUTOSAR rules checked against the parsed syntax tree. Fast, deterministic, exhaustive.
03
Coda Evaluates
Coda reasons about the 68 rules static analysis can't fully cover: non-automated and partially automated rules requiring design judgment.
04
Coda Triages
Coda reviews every AST finding for context — surfacing the design question behind each rule, classifying findings as genuine, borderline, or requiring a documented decision. Engineers spend time on decisions, not triage.
05
Unified Report
One prioritised report — genuine violations requiring remediation, borderline cases with the design question surfaced, and known patterns where Coda asks you to document your rationale. Every finding carries Coda's reasoning and becomes part of the certification evidence trail.
GENUINE— remediate
BORDERLINE— review context
RATIONALE— record decision
Common questions
Why not just auto-rewrite the code to be compliant?
In safety-critical systems, every code change requires human review, validation, and sign-off. An auto-rewriter produces changed code, not evidence that anyone reviewed it. Coda produces the auditable evidence that review happened. That evidence is what certification requires.
Can't Copilot or ChatGPT already do this?
LLMs generate code. Coda generates compliance evidence: rule-to-code traceability, deviation records, and a readiness score your auditor can act on. Code generation and compliance evidence are different jobs. One produces files. The other produces certification artifacts.
We already use Coverity or Helix QAC.
Those tools cover the 329 AUTOSAR rules that are fully and deterministically checkable — the same rules clang-tidy covers. Coda targets the 68 rules they can't fully check: non-automated and partially automated rules requiring design judgment. Coda also reviews every AST finding for context — surfacing the design question behind each rule so engineers make conscious documented decisions rather than triaging noise. Coda complements your existing tools, it doesn't replace them.
Why not just hire a safety engineer to review the code?
That's exactly what Coda helps your safety engineer do, faster, more consistently, and with a traceable record of every decision. Manual review of 397 rules across a large C++ codebase takes weeks per release. Coda runs it in minutes and produces the documentation that would otherwise take the safety engineer days to write.
The Agent

Meet Coda

Coda isn't a linter. It's a compliance agent that reads your code the way a senior engineer would. It understands why a design decision was made, not just whether it compiles.

Semantic reasoning
Understands inheritance intent, interface design, exception contracts, and architectural relationships, not just syntax.
Explains every flag
Every violation includes a plain-English explanation. No more cryptic rule codes with no context.
Confidence scoring
Coda rates its own confidence 0–1 so your team knows which flags to review first and which to trust automatically.
C
Coda
AUTOSAR Compliance Agent · Codabase.ai

I analyse C++ codebases for AUTOSAR C++14 compliance with a focus on the semantic rules that static analysis tools can't reach. I understand the difference between a violation and a design decision, and I always explain my reasoning.

68
Rules owned
≥80%
True pos. rate
0.0–1
Confidence score
Coverage

Rules Coda owns

Showing 10 of 68 target rules
Rule IDDescriptionCategoryChecker
A10-0-1Public inheritance shall implement "is-a" relationshipsRequiredCoda
A10-0-2Membership or non-public inheritance shall implement "has-a" relationshipsRequiredCoda
A8-4-14Interfaces shall be precisely and strongly typedRequiredCoda
A10-4-1Hierarchies should be based on interface classesAdvisoryCoda
A15-0-1A function shall not exit with exception if it can complete its taskRequiredCoda
A15-0-4Unchecked exceptions represent errors caller cannot recover fromRequiredCoda
A27-0-1Inputs from independent components shall be validatedRequiredCoda
A7-2-5Enumerations should represent sets of related named constantsAdvisoryCoda
M0-3-1Runtime failures minimized via static/dynamic analysis or explicit checksRequiredCoda
A0-1-1 to A27-0-3329 additional rules enforced via clang-tidy AST layerRequiredAST
MISRA C++:2023C++17 semantic rule coverage, full Coda evaluation across the MISRA rulesetRoadmapQ3 2026
CUDA RuntimeKernel launch validation, memory transfer safety, synchronization analysis — for GPU-accelerated safety-critical systemsRoadmapComing 2026
What's next

Coda checks. Coda explains.
Soon, Coda builds your safety case.

Compliance reports get you to the starting line. The certification safety case gets you across it. We're building Coda's next capability: turning its analysis output into the structured artifacts your auditors actually need.

Coming soon
Traceability matrices

Auto-generated requirement-to-rule-to-code mappings in the format ISO 26262 Part 6 auditors expect. What used to take days, generated in seconds.

Coming soon
Deviation records

When a rule is deliberately broken, Coda drafts the formal deviation record: risk assessment, justification, and compensating measures, ready for safety engineer sign-off.

Coming soon
Safety case fragments

Structured GSN arguments generated directly from Coda's analysis: claim, evidence, confidence score, and run metadata, ready to drop into your functional safety case.

Expanding to
CUDA runtime checks

Kernel launch validation, memory transfer safety, and synchronization analysis — for GPU-accelerated safety-critical systems. Built for AV perception and robotics stacks running CUDA alongside AUTOSAR C++.

Coda is a compliance assistant. All certification artifacts are reviewed and signed off by your safety engineers.
Further ahead: compliance at the C++ ↔ model boundary for ML-integrated systems, humanoid robotics, and physical AI. CUDA runtime safety for GPU-accelerated perception and planning. Any software that controls a physical system will need Coda.
Early Access

Be first to run Coda
on your codebase

We're opening Codabase to a small group of teams building safety-critical and physical AI systems. Get early access to the PoC and help shape what Coda becomes.

No spam. We'll reach out when your slot is ready.

Evaluating MISRA C++:2023 or running CUDA in a safety-critical stack? Tell us. We're prioritising our roadmap around early feedback.

Deploys where your code lives
Cloud
PoC & evaluation
Private VPC
Network-isolated
Full On-Prem
Air-gapped