Pricing

Priced on how much you watch, not on what it finds.

Every plan runs the same engine and the same checks. What changes is how many assets you cover, how often they are re-read, and what the platform does with the result.

Where this standsFree sign-up is open today. Pro and Business are published prices rather than checkouts — the purchase flow is not switched on and nothing on this page is metered. We would rather say that here than let you discover it after paying.

Billing cycle

Pay yearly and get nearly 2 months free

Free

Assess one thing properly.

$0forever

Available now — limits not yet metered

Start free assessment

Sign-up is open and free. The 1-domain limit below is the intended plan shape — quota enforcement is not implemented yet, so nothing currently blocks you at that line.

  • 1 domain and 1 repository (intended limit, not yet enforced)
  • Every check the engine runs — nothing held back
  • AI/LLM usage risk detection on every code scan
  • Severity and confidence on every finding
  • Attack-path correlation within a scan
  • HTML report
ProRecommended

Continuous assessment for a growing surface.

$39per month

or $399 a year — nearly 2 months free

Not yet purchasable

Talk to us about early access

This is the published price, not a checkout. A payment integration (Polar) is built into the codebase but not yet switched on anywhere you can reach, so Pro cannot be bought today. Every capability listed below is already running — it is the purchase and quota layer that is not.

  • 5 domains and 4 repositories
  • Continuous monitoring on a schedule you set
  • Cross-asset correlation — credential reuse, chronic regression
  • AI red-team checks and agent-tooling risk analysis
  • EPSS exploit-prediction on dependency findings
  • SBOM export, JSON export, and scan attestations
  • API keys, CLI, and CI/CD score gating
  • Alerts to Slack, PagerDuty, Datadog, Splunk, or any webhook
Business

The whole portfolio, watched together.

$79per month

or $799 a year — nearly 2 months free

Not yet purchasable

Talk to us about early access

Published price, same status as Pro: the capabilities below are running today, and the purchase flow is not yet switched on.

  • 12 domains and 12 repositories
  • Everything in Pro
  • Compliance mapping: OWASP, NIST 800-53, CIS v8, ISO 27001, SOC 2
  • Organisations with shared scanning scope
  • Cross-portfolio risk sections and executive reports
  • All four report types, attestation included

Need more than 12 of anything?

There is no larger plan to buy yet, and no sales process to enter. The governance, isolation and audit answers an enterprise review asks for are published in full.

Read the enterprise page
Compare

Line by line.

Feature comparison across Free, Pro, and Business plans
CapabilityFreeProBusiness
Scope
Domains1512
Repositories1412
Team members1OrganisationsOrganisations
Assessment
All check categoriesYesYesYes
AI/LLM usage risk detectionYesYesYes
Severity and confidenceYesYesYes
Correlation within a scanYesYesYes
Correlation across assetsYesYes
AI red-team and agent-tooling checksYesYes
EPSS exploit predictionYesYes
Continuous monitoringYesYes
Output
HTML reportYesYesYes
Compliance reportYes
SBOM and JSON exportYesYes
Scan attestationsYesYes
Executive and portfolio reportsYes
Workflow
API keys and CLIYesYes
CI/CD score gatingYesYes
Slack, PagerDuty, Datadog, SplunkYesYes
Organisations with shared scopeYes
Tamper-evident audit logYesYesYes
Two-factor authenticationYesYesYes

Every value in every column is the plan shape we intend, not a limit the software applies today — there is no quota enforcement and the purchase flow is not yet switched on. Scan history is kept unless this deployment sets a retention window: with one configured, older scans are swept, and with none set nothing is removed on a timer.

Questions

Before you commit.

Still unsure which plan fits? Start on Free — it is the same engine, and moving up later keeps every finding and every scan you have already collected.

Can I pay for Pro or Business right now?

No. A payment integration (Polar) is built into the codebase, but it is not yet switched on anywhere you can reach, so there is still nothing to check out with. The monthly ($39 / $79) and annual ($399 / $799) figures are the published prices so they are not a surprise later, and every capability listed under both plans is already built and running today — what is missing is the purchase flow and the quota layer, not the scanning.

So what actually stops me exceeding the Free limits?

Nothing, today. Quota enforcement is not implemented, so the numbers in every column describe the plan shape we intend rather than a limit the software currently applies. We would rather tell you that than let you find out when the meter is switched on.

Is the free tier a time-limited trial?

No. It is free indefinitely, and it runs the full check set rather than a reduced one — including the AI/LLM usage checks. The limits are on scope, not on quality: the engine is the same one in every plan.

What is the difference between Pro and Business?

Scope and the portfolio layer. Pro covers 5 domains and 4 repositories with monitoring, correlation, and CI/CD workflow. Business raises that to 12 and 12 and adds the portfolio layer: organisations with shared scanning scope, compliance mapping, and the executive and portfolio report types.

How long is my scan history kept?

Unless this deployment sets a retention window, indefinitely: with one configured, older scans are swept on a timer. You can export your data and delete your account yourself from the account page.

Does scanning slow down or affect my sites?

External checks are passive and equivalent to a handful of ordinary browser requests. Checks that go beyond that stay locked until you prove domain ownership with a DNS record or a hosted file.

Start with one domain.

You will know within one scan whether this tells you something you did not already know.

Contact

Talk to us.

Questions about what the engine checks, whether it fits your estate, or what it deliberately refuses to do. A person reads every message.

  1. 01You writePlain form, no qualifying call, no obligation. The marketing checkbox is optional and unticked.
  2. 02A person reads itMessages land with the team, not a queue-bot. Nothing is auto-replied.
  3. 03You get an answerTo the address you gave — including “this product is not the right fit”, when that is the honest answer.
Prefer email?
Use the form — no address is published on this deployment.
Reporting a vulnerability?
Read the disclosure policy first — it tells you what is in scope and what to expect.
New messagereplies go to your email

Personal addresses (gmail, outlook, and similar) are not accepted.

+91

0 / 4000