# CoStrict: Sangfor's strict AI coder, forked from Roo-Code for enterprises

> CoStrict is Sangfor's Apache-2.0 AI-powered coding assistant for enterprise-grade development, built on Roo-Code and shipping as a VS Code extension, JetBrains plugin, CLI and cloud product with private deployment. Its Strict Mode standardizes generation through requirements analysis, architecture design, task planning and test generation, and a RAG-based Code Review verifies changes with multi-expert models, releasing weekly on the v3.0 line.

**zgsm-ai/costrict** — Costrict - strict AI coder for enterprises, quality first, including AI Agent, AI CodeReview, AI Completion. 

- Repository: https://github.com/zgsm-ai/costrict
- Website: https://costrict.ai
- Stars: 4,438 · Forks: 202
- Language: TypeScript
- License: Apache-2.0
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/zgsm-ai-costrict

## Strict Mode as the product thesis

The core capabilities table leads with Strict Mode, and its description carries the product's argument, standardized AI code generation with requirements analysis, architecture design, task planning and test generation, standardizing AI-generated code workflows for enterprise scenarios to ensure high-quality and controllable outputs. The contrast with vibe coding is built into the same table, the Vibe Code capability offering rapid development through natural language dialogue sits beside Strict Mode as the two modes an enterprise chooses between per task. The ordering matters, requirements before architecture before tasks before tests is a waterfall-flavored pipeline imposed on generation, and the controllability it buys is the feature enterprises procurement actually evaluates, a traceable process rather than a prompt box. The table's pair of modes also maps to who approves what, vibe output suits a developer iterating on their own code where review follows, while strict output documents its own reasoning trail at each stage, which is what a reviewer or an auditor needs when the question is not whether the code runs but why it was written this way.

## Code Review with RAG and multi-expert verification

The second headline capability is repository-wide RAG-based code analysis with multi-expert model verification strategies. The mechanics implied are two-stage, indexing the repository so analysis retrieves real context rather than whatever fits a window, then running multiple models over the retrieved code so findings survive cross-examination rather than resting on one model's judgment. The VSCode SCM integration listed under more features connects this to the workflow, code review against Git for collaboration, and the bundle script in the package.json, generate-review-builtin, shows review logic compiled into the shipped artifact. For a team adopting AI review, the multi-model strategy answers the obvious objection, single-model reviews inherit that model's blind spots, and CoStrict's answer is paying for several opinions.

## Four delivery surfaces, one codebase

The installation table shows the four ways the product reaches users, CoStrict Cloud documented separately, a VS Code extension published to the marketplace in stable and nightly variants, a CLI tool with its own installation guide and download page, and a JetBrains plugin maintained in a sibling zgsm-sangfor organization repository. The TypeScript monorepo behind them is a pnpm and turbo workspace with a packageManager pin at pnpm 10.8.1 and a Node engine pinned exactly at 20.19.2, producing VSIX packages through dedicated scripts, with install:vsix building, cleaning and installing the extension locally for development. The Roo-Code lineage is visible in the repository itself, a .roo directory, .roomodes and .rooignore files at the root, and the acknowledgments credit Roo-Code, OpenSpec, opencode, agents.md and agentskills as open-source partners.

## Private deployment as the enterprise wedge

The privacy and security feature names the deployment model directly, professional private deployment with physical isolation and end-to-end encryption, and the documentation table gives private deployment its own introduction page alongside installation and CLI guides. The API and model customization feature completes the picture, built-in free models plus support for Anthropic, OpenAI, OpenAI-compatible APIs and local models, so an enterprise can run the assistant entirely against models inside its own perimeter or mix providers per team. The disclaimer's weight grows in this context, Sangfor does not make representations or warranties regarding code, models or outputs, and users assume all risks including intellectual property infringement, cyber vulnerabilities, bias and inaccuracies, the clause that makes the private deployment choice a real legal boundary rather than marketing. The tutorial videos linked for Strict Mode and code review give evaluators a zero-install way to judge the workflows before any deployment decision, which matters when the decision involves a vendor relationship rather than a single developer's download.

## The workspace features around the agent

The more-features list rounds out the daily surface. Multi-language support naming Python, Go, Java, JavaScript and TypeScript, C and C++ and all programming languages. Large repository context through automatic context inclusion with at-mentions of files and folders. Mode customization with default Code and Orchestrator modes plus custom modes. OpenSpec integration for standardized change proposal workflows through an openspec-init command. Auto cleanup of history to reduce disk usage, and history import and export for offline migration, the pair that matters on managed machines where local data policies apply. A Lite Mode reduces context usage and token consumption, the cost control that matters when every interaction bills tokens. MCP integration provides standardized connectivity to APIs, databases and custom tools, and multi-modal support accepts image context and visual inputs.

## A fork with its own engineering discipline

The repository's tooling shows a fork that grew its own practices. Husky and lint-staged guard commits, turbo orchestrates lint, check-types, test, format and build across packages with grouped log ordering, knip hunts dead code, renovate manages dependency updates, and an evals package runs through docker compose with dotenvx-loaded environment files, the evaluation harness that measures model behavior rather than assuming it. The Roo Code Cloud variables in the env sample, a Clerk authentication base URL and provider proxy URLs, mark the cloud product's development surface beside the open code. Changesets handle versioning, with a script copying the changelog into the source tree for the extension to display, and the changeset version flow is itself documented in the package scripts. The sync-upstream.md file at the repository root documents the fork's relationship to its parent project, the practical mechanism by which CoStrict tracks Roo-Code's changes while carrying its own enterprise features, a maintenance reality every long-lived fork must manage explicitly.

## v3.0.22, Sangfor, and the star history

The release train is tight, v3.0.20 on August 18, v3.0.21 on September 9 and v3.0.22 on 2026-09-24, the last tagged the same minute as the repository's final push, a release cadence measured in weeks. The license line names the owner, Apache 2.0, copyright 2025 Sangfor, Inc., placing the project under one of China's major security vendors, and the bilingual readme with a WeChat group beside GitHub issues shows the two communities it serves. A PRIVACY.md sits beside the SECURITY.md and code of conduct, the governance set an enterprise vendor brings to open source, and the star history chart closes the readme the way growth-stage projects do, with the curve itself as the argument.

## Conclusion

Use CoStrict when an organization wants AI-assisted coding with deployment control, since private deployment with physical isolation, end-to-end encryption, and built-in free models beside Anthropic, OpenAI, OpenAI-compatible and local APIs cover the procurement concerns most cloud assistants cannot. Choose a mainstream assistant when individual developer preference outweighs central control, the strict workflow is a discipline not everyone wants. Before adopting, check the four delivery surfaces and pick the one matching your IDE, read the private deployment documentation early since it drives infrastructure decisions, and note the disclaimer, Sangfor provides the tools as is with all risks on the user, a clause enterprises should route through legal review like any vendor terms.

## FAQ

### Is CodeAI free?

CoStrict is free and open source under the Apache 2.0 license, contributed by Sangfor, with the assistant shipping as a VS Code extension, JetBrains plugin and CLI. It includes built-in free models and can also connect to Anthropic, OpenAI, OpenAI-compatible APIs and local models.

### What is CoStrict's Strict Mode?

Strict Mode standardizes AI code generation for enterprise scenarios through a fixed workflow of requirements analysis, architecture design, task planning and test generation, producing high-quality and controllable outputs. It sits beside the Vibe Code capability, which offers rapid development through natural language dialogue.

### How does CoStrict handle private deployment?

CoStrict supports professional private deployment with physical isolation and end-to-end encryption, documented in its own deployment guide. Model APIs are customizable, so organizations can run the assistant entirely on built-in free models or local models within their own perimeter, or connect Anthropic, OpenAI and OpenAI-compatible endpoints.

## Sources

- [License: Apache-2.0](https://github.com/zgsm-ai/costrict/blob/main/LICENSE)
- [Project website](https://costrict.ai)
- [README](https://github.com/zgsm-ai/costrict/blob/main/README.md)
- [Releases](https://github.com/zgsm-ai/costrict/releases)
- [zgsm-ai/costrict on GitHub](https://github.com/zgsm-ai/costrict)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/zgsm-ai-costrict
