Pricing
Pay for what we scan — not how many developers you have.
Priced by the amount of code we scan — not seats, not repos, not services. Unlimited repositories and users in every package, and the meter doesn't care what language the lines are in: a product built in five languages costs the same as one built in one, at the same size. No per-developer maths, no procurement conversation about headcount.
The first scan on every repo is free — always. One signed proof per scan, yours to share.
In every package
The measurement is never the variable.
Full CAI, every package
All dimensions, all lenses, same rubric, every language we cover — the number means the same whoever's paying and whatever they build in. Every report ships a changelog, a CycloneDX SBOM, CWE-tagged findings and behavioural signals.
First report €0
Run a full survey on any repo for free — depth is never the upsell; the volumes you're priced against are measured, not guessed.
∞ repositories
No per-repo cap and no per-seat fee. We meter lines scanned, not repos — fifty small services or one monolith, same meter.
Reproducible
Same commit, same frozen rubric → the same score, every run. Evidence, not opinion.
For developers & teams
Keep your code healthy.
Continuous, independent measurement of your own codebase. Transparent prices — self-serve, running in minutes. Every scan issues a signed proof you can share with clients, buyers or investors.
Every price above is the real, current price from our billing catalogue — not an example. The only thing we can't know yet is your size: the first free scan measures it, and that decides which row you land on. Above 500M line-scans a month the ladder stops climbing — you pay the XXL row and nothing more, whatever your volume.
How the price scales
You pay for the lines you scan each month.
A line-scan = one line of code read in one scan = codebase size × scan frequency, summed across every repo. A line is a line: fifty 10K-line services in five different languages come to the same 500K line-scans as one 500K-line monolith.
The table on each package above is that package's own ladder — the same rows our billing engine reads, so what you see here is what you would be charged.
Price = the volume bucket your monthly line-scans land in, multiplied by the value of the modules that package includes. Both halves are ours to publish and neither is hidden: the buckets are on every card, and the modules are listed under each package.
One model, two ways to buy
Business reports are not sold here.
Buyers, procurement & investors
Decision reports live on Assay — per activation
Consequences report, tender annex, contract appendix, compliance signing, portfolio roll-up and the signed Delivery are business modules, priced per activation on Assay — never by lines of code. The evidence copy a supplier shares with you is free; you pay for the decision report built on top.
Providers & consultancies
You sit in the overlap
You build code and prove it to your customers. Scan self-serve here — every scan already issues the signed shareable proof — and activate the delivery artifacts (attestation, contract appendix) on Assay when the hand-over comes.
Start with a free report. Decide what it's worth once you've read it.
Survey a repo — freeTalk to us about on-premSign in with GitHub · no card · C#, Java, TypeScript, Python, Go and more · the first full report is €0.