Priced on how much you watch, not on what it finds.
Every plan runs the same engine and the same checks. What changes is how many assets you cover, how often they are re-read, and what the platform does with the result.
Where this standsFree sign-up is open today. Pro and Business are published prices rather than checkouts — the purchase flow is not switched on and nothing on this page is metered. We would rather say that here than let you discover it after paying.
Pay yearly and get nearly 2 months free
Assess one thing properly.
Available now — limits not yet metered
Start free assessmentSign-up is open and free. The 1-domain limit below is the intended plan shape — quota enforcement is not implemented yet, so nothing currently blocks you at that line.
- 1 domain and 1 repository (intended limit, not yet enforced)
- Every check the engine runs — nothing held back
- AI/LLM usage risk detection on every code scan
- Severity and confidence on every finding
- Attack-path correlation within a scan
- HTML report
Continuous assessment for a growing surface.
or $399 a year — nearly 2 months free
Not yet purchasable
Talk to us about early accessThis is the published price, not a checkout. A payment integration (Polar) is built into the codebase but not yet switched on anywhere you can reach, so Pro cannot be bought today. Every capability listed below is already running — it is the purchase and quota layer that is not.
- 5 domains and 4 repositories
- Continuous monitoring on a schedule you set
- Cross-asset correlation — credential reuse, chronic regression
- AI red-team checks and agent-tooling risk analysis
- EPSS exploit-prediction on dependency findings
- SBOM export, JSON export, and scan attestations
- API keys, CLI, and CI/CD score gating
- Alerts to Slack, PagerDuty, Datadog, Splunk, or any webhook
The whole portfolio, watched together.
or $799 a year — nearly 2 months free
Not yet purchasable
Talk to us about early accessPublished price, same status as Pro: the capabilities below are running today, and the purchase flow is not yet switched on.
- 12 domains and 12 repositories
- Everything in Pro
- Compliance mapping: OWASP, NIST 800-53, CIS v8, ISO 27001, SOC 2
- Organisations with shared scanning scope
- Cross-portfolio risk sections and executive reports
- All four report types, attestation included
Need more than 12 of anything?
There is no larger plan to buy yet, and no sales process to enter. The governance, isolation and audit answers an enterprise review asks for are published in full.
Line by line.
| Capability | Free | Pro | Business |
|---|---|---|---|
| Scope | |||
| Domains | 1 | 5 | 12 |
| Repositories | 1 | 4 | 12 |
| Team members | 1 | Organisations | Organisations |
| Assessment | |||
| All check categories | Yes | Yes | Yes |
| AI/LLM usage risk detection | Yes | Yes | Yes |
| Severity and confidence | Yes | Yes | Yes |
| Correlation within a scan | Yes | Yes | Yes |
| Correlation across assets | — | Yes | Yes |
| AI red-team and agent-tooling checks | — | Yes | Yes |
| EPSS exploit prediction | — | Yes | Yes |
| Continuous monitoring | — | Yes | Yes |
| Output | |||
| HTML report | Yes | Yes | Yes |
| Compliance report | — | — | Yes |
| SBOM and JSON export | — | Yes | Yes |
| Scan attestations | — | Yes | Yes |
| Executive and portfolio reports | — | — | Yes |
| Workflow | |||
| API keys and CLI | — | Yes | Yes |
| CI/CD score gating | — | Yes | Yes |
| Slack, PagerDuty, Datadog, Splunk | — | Yes | Yes |
| Organisations with shared scope | — | — | Yes |
| Tamper-evident audit log | Yes | Yes | Yes |
| Two-factor authentication | Yes | Yes | Yes |
Every value in every column is the plan shape we intend, not a limit the software applies today — there is no quota enforcement and the purchase flow is not yet switched on. Scan history is kept unless this deployment sets a retention window: with one configured, older scans are swept, and with none set nothing is removed on a timer.
Before you commit.
Still unsure which plan fits? Start on Free — it is the same engine, and moving up later keeps every finding and every scan you have already collected.
Can I pay for Pro or Business right now?
No. A payment integration (Polar) is built into the codebase, but it is not yet switched on anywhere you can reach, so there is still nothing to check out with. The monthly ($39 / $79) and annual ($399 / $799) figures are the published prices so they are not a surprise later, and every capability listed under both plans is already built and running today — what is missing is the purchase flow and the quota layer, not the scanning.
So what actually stops me exceeding the Free limits?
Nothing, today. Quota enforcement is not implemented, so the numbers in every column describe the plan shape we intend rather than a limit the software currently applies. We would rather tell you that than let you find out when the meter is switched on.
Is the free tier a time-limited trial?
No. It is free indefinitely, and it runs the full check set rather than a reduced one — including the AI/LLM usage checks. The limits are on scope, not on quality: the engine is the same one in every plan.
What is the difference between Pro and Business?
Scope and the portfolio layer. Pro covers 5 domains and 4 repositories with monitoring, correlation, and CI/CD workflow. Business raises that to 12 and 12 and adds the portfolio layer: organisations with shared scanning scope, compliance mapping, and the executive and portfolio report types.
How long is my scan history kept?
Unless this deployment sets a retention window, indefinitely: with one configured, older scans are swept on a timer. You can export your data and delete your account yourself from the account page.
Does scanning slow down or affect my sites?
External checks are passive and equivalent to a handful of ordinary browser requests. Checks that go beyond that stay locked until you prove domain ownership with a DNS record or a hosted file.
Keep reading
Where most people go next
Start with one domain.
You will know within one scan whether this tells you something you did not already know.