Start free, pay when it pays for itself
Public repositories are free to scan and need no account at all. Paid plans are for private repositories, and Team is priced per organisation — seats are included, so adding an engineer never costs more.
Personal projects and a real look at the product
One engineer, every repository they own
One organisation, seats included
For the audit you already have a date for
Card payments through Lemon Squeezy.
No credit card needed to start — the free plan and the public scanner work immediately.
What each plan includes
| Capability | Free | Pro | Team | Compliance |
|---|---|---|---|---|
| Public repository scans | ∞ | ∞ | ∞ | ∞ |
| Private repositories | 3 | ∞ | ∞ | ∞ |
| AI analysis of each issue | 1/month | ✓ | ✓ | ✓ |
| Score history and trend | — | ✓ | ✓ | ✓ |
| Fix opened as a pull request | — | ✓ | ✓ | ✓ |
| Re-audit on every push | — | ✓ | ✓ | ✓ |
| PDF report | 1/month | ✓ | ✓ | ✓ |
| Organisation dashboard | — | — | ✓ | ✓ |
| Score comment on pull requests | — | — | ✓ | ✓ |
| SOC 2 / ISO 27001 mapping | — | — | — | ✓ |
| Evidence and SBOM export | — | — | — | ✓ |
Questions people ask before paying
Do I need an account to try it?
No. Any public repository can be scanned at /scan/ with no sign-up — you get the full result, the score and every finding. An account is only needed for private repositories.
What access does it need to my code?
Read access only. Repository code is never stored — only the check results. Access tokens are encrypted at rest with a key held outside the database, and you can revoke a token at any time in your GitHub or GitLab settings.
Why is Team priced per organisation?
Because per-seat pricing punishes you for adding the engineer who most needs to see the report. One price covers the whole organisation, however many people look at it.
How do I cancel?
Cancel from the billing page at any time. The subscription stays active until the end of the period you have already paid for, and nothing is charged after that.
Does it work with self-hosted GitLab?
Yes, from the Team plan. A custom GitLab URL, an internal DNS resolver and optional SSL verification are supported for instances that are not reachable from the public internet.