{"slug": "how-bfi-finance-optimized-engineering-efficiency-and-consolidated-code-quality", "title": "How BFI Finance Optimized Engineering Efficiency and Consolidated Code Quality on One Platform", "summary": "BFI Finance moved roughly 170 developers and 180+ repositories from SonarQube to Codacy's seat-based static analysis platform, cutting direct static analysis costs by 18 to 20%, according to the Indonesian financial services company. BFI Finance Technology Development Head Okky Permana said the switch brought quality gates, AI pull request review and container scanning under one platform with no drop in analysis quality versus SonarQube. The company cited Sonar's jump from a 5 million to a 10 million line-of-code tier, which it said would have forced it to pay for unused capacity for two to three years.", "body_md": "[Home](https://www.codacy.com/)\n\n[All Posts](https://blog.codacy.com)\n\n[How BFI Finance Optimized Engineering Efficiency and Consolidated Code Quality on One Platform](<javascript:void(0)>)\n\nThe Indonesian financial services company moved its static analysis to Codacy's seat-based platform, cutting direct costs by 18 to 20% and bringing quality gates, AI pull request review and container scanning under one roof.\n\n- **18 to 20% direct saving on static analysis cost** \n- **~170 developers moved from SonarQube to Codacy**\n- **180+ repositories under one quality gate**\n\n*\"Codacy checked every box. Seat-based pricing that scales with the team, a dashboard that explains itself, GitHub integration that worked out of the box, and analysis quality on a par with SonarQube. We saw no drop in quality when we switched.\"*\n\n— Okky Permana, Technology Development Head, BFI Finance\n\n## \n**About BFI Finance**\n\nAbout BFI Finance\n\nBFI Finance is an Indonesian consumer and business financing company, and a regulated financial institution. Its engineering organisation is around 170 developers working in roughly 20 squads, with a Go, Java and React codebase hosted on GitHub.\n\n### **Challenge**\n\n## Growing codebase, evolving technology needs, per-line pricing\n\nOkky Permana is Technology Development Head at BFI Finance and owns tool selection for the development organisation. In 2025, BFI set a cost-efficiency target for engineering: improve productivity and equip the existing team with tools that could scale with its evolving technology needs. The team had used SonarCloud for two years and then moved to SonarQube on Sonar's own advice, since new features landed there first.\n\nThe per-line pricing worked against the headcount target. Every new system and repository added lines of code, the bill rose with them, and the team stayed the same size. AI coding assistants made it worse. Engineers were adopting AI tools for development, iteration got faster, and so did line count growth. The tier structure set the timing.\n\n\"We were on Sonar’s 5 million lines of code tier, and the next step up was 10 million, with nothing in between. On our growth curve we wouldn’t need that capacity for two or three years. We would have been paying for headroom we couldn’t use.\"\n\nSecurity scanning ran separately, on dedicated application security tools. Okky had seen quality and security tooling converging and put consolidation on the list as a nice-to-have: fewer vendors, and one platform that could grow with the rest of the development lifecycle. His one hard condition for any replacement: \"We don't want to compromise the quality of the static code analysis that we already have.\"\n\n### **Solution**\n\n## **Comparing three tools on the same pull requests**\n\nBFI shortlisted Codacy and two other vendors, all three priced by seat, which matched the intent of keeping cost linear with developers. The criteria, in Okky's order: analysis quality, with SonarQube as the control; ease of GitHub integration and the experience of managing issues in the dashboard; and security coverage as the bonus.\n\nThe evaluation ran in two stages. First, before any formal proof of value, three control repositories (a Go backend, a Java backend and a React frontend) ran all three tools at once on the same pull requests.\n\n“We picked three control repositories and ran all three tools on them at the same time. Every pull request carried comments from all three, side by side on the same code, so the team could judge them line by line.”\n\nOne vendor's analysis was still evolving and hadn't yet reached the depth BFI needed for its codebase. Another vendor performed competitively on analysis quality, but the team found the issue-triage workflow less efficient and less integrated with existing GitHub workflow.\n\nCodacy performed best of all three and was also the first vendor to respond to Okky’s request.\n\nBFI decided to launch an extended proof of value on Codacy with 30 repositories across five squads of seven engineers and one system architect each, around 35 to 40 engineers in total. The team tested the wider Codacy suite, beyond static analysis, which includes the AI Reviewer, Codacy Skills, and Container Image Scanning.\n\nIt didn’t take long for Okky and his team to reach a conclusion.\n\n\"Codacy checked every box. Seat-based pricing that scales with the team, a dashboard that explains itself, GitHub integration that worked out of the box, and analysis quality on a par with SonarQube. We saw no drop in quality when we switched.\"\n\n## **Codacy: Simpler gates, per-repo goals, fixes before the pull request**\n\nBFI switched over completely. There was no period of running SonarQube and Codacy in parallel. The quality gates carried across, and Okky found Codacy's gate model simpler than what he had left.\n\nThe change he valued most was how exceptions are handled.\n\n\"In SonarQube, a repository that needed to deviate from the quality gate meant building a whole new gate. In Codacy we set goals per repository. We keep governance across the organisation, and each team keeps the flexibility it needs to define its own success.\"\n\nDeveloper workflow shifted earlier without a mandate. Engineers using AI assistants tend to install the Codacy MCP server, so the assistant talks to Codacy and fixes findings before the pull request is opened, which cuts the loop of opening a PR, getting issues flagged, fixing them and pushing again.\n\nFor pull request reviews, BFI evaluated Codacy's AI Reviewer alongside an existing AI code review tool. Based on the team's experience, Codacy's AI Reviewer is better aligned with its workflow, particularly through its ability to incorporate context from Jira tickets and assess proposed changes against their intended purpose. Okky is specific about what made the AI Reviewer stand out: \"As long as the context is there, which Codacy pulls from the Jira ticket integration, it provides good feedback, because it looks at the ticket and understands the intent of the actual change.\" One squad has also tried Codacy Skills, which move analysis, configuration and reporting into the agent workflow, and reports them working well so far.\n\nOn onboarding, Okky's assessment of the Codacy team is about method as much as speed.\n\n“The Codacy team answered fast, and their recommendations came with code: here is how to configure it, here is how to maintain it. They know their product and how it behaves in a real codebase. That is what made my team feel we were in the right hands.”\n\n\"The Codacy team answered fast, and their recommendations came with code: here is how to configure it, here is how to maintain it. They know their product and how it behaves in a real codebase. That is what made my team feel we were in the right hands.\"\n\n### Results\n\n## **18 to 20% off static analysis cost, and a path to one consolidated platform**\n\nThe cost problem that started the search is gone: analysis cost now scales with the number of developers, and the 10 million line tier BFI would have paid for years early is no longer on the table. BFI puts the direct saving on static code analysis at around 18 to 20%. SonarQube is fully retired, the previous AI code review tool has been switched off, and Codacy’s quality gates, per-repo goals and the MCP server are now part of daily work for around 170 developers.\n\nThe larger benefit is consolidation. Static analysis, pull request review, container scanning and the MCP server already run on one platform. If Codacy proves it can replace BFI's application security tools as well, Okky expects a further 40 to 50% saving on top of the first.\n\nWhat Codacy has not yet changed is BFI's security stack. The existing application security tools stay in place until BFI's Enterprise Security team and Okky decide together whether to consolidate SAST, Secret scanning, SCA and DAST onto Codacy. Penetration testing is still manual, run every six months. The team is also still tuning noise out of the initial configuration.\n\n\"Enterprise Security and I are now assessing whether we can bring Codacy’s DAST into the CI/CD pipeline and cover application security end to end.\"\n\n## Try it for yourself\n\nFull scan in minutes. Free 14-day trial, no credit card needed.", "url": "https://wpnews.pro/news/how-bfi-finance-optimized-engineering-efficiency-and-consolidated-code-quality", "canonical_source": "https://blog.codacy.com/how-bfi-finance-optimized-engineering-efficiency-and-consolidated-code-quality-on-one-platform", "published_at": "2026-10-09 15:20:03+00:00", "updated_at": "2026-10-09 15:25:35.247782+00:00", "lang": "en", "topics": ["developer-tools", "ai-tools", "mlops"], "entities": ["BFI Finance", "Codacy", "SonarQube", "SonarCloud", "Okky Permana", "GitHub"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/how-bfi-finance-optimized-engineering-efficiency-and-consolidated-code-quality", "markdown": "https://wpnews.pro/news/how-bfi-finance-optimized-engineering-efficiency-and-consolidated-code-quality.md", "text": "https://wpnews.pro/news/how-bfi-finance-optimized-engineering-efficiency-and-consolidated-code-quality.txt", "jsonld": "https://wpnews.pro/news/how-bfi-finance-optimized-engineering-efficiency-and-consolidated-code-quality.jsonld"}}