Pricing
Priced per developer. Never per finding.
Scanning volume, AI triage, and remediation are included at every tier — you should never be billed more for looking harder at your own risk.
Starter
up to 5 developers
For small teams securing their first services.
- 2 repositories
- SAST, SCA, and secret scanning
- AI triage on critical and high findings
- Pull request checks
- Community support
Team
Most adoptedper developer / month
For engineering orgs running security as a shared responsibility.
- Unlimited repositories
- Full scanner coverage including IaC and DAST
- Exploitability engine and reachability analysis
- AI security assistant and drafted fix pull requests
- Jira, Linear, and Slack sync
- SLA policies and program analytics
Enterprise
annual agreement
For regulated organizations with dedicated security functions.
- SSO, SCIM, and granular RBAC
- EU, US, and UK data residency
- Compliance mapping and evidence exports
- Custom policy engine and private scanners
- Named security architect
- 99.9% uptime SLA
Common questions.
How is a developer counted?
Any contributor who pushed code to a connected repository in the billing month. Bots, CI identities, and read-only reviewers are free.
Is AI usage metered?
No. Triage, assistant conversations, and drafted fixes are included in Team and Enterprise without usage caps.
Do you need to store our source code?
No. Analysis runs against an ephemeral checkout. Only findings, metadata, and the evidence snippets you see in the console are retained.
Can we self-host the scanners?
Enterprise supports private runners inside your own VPC, with only findings metadata leaving your network.