Pricing

Simple, honest, and free where it matters.

Open source is free forever. Small teams ship without paperwork. The enterprise edition adds compliance and the determinism attestor, not your security results.

Free
$0forever

For individual developers, open-source maintainers, and small projects.

  • Unlimited public repositories
  • 1 private repository
  • Up to 3 collaborators
  • All deterministic-core detectors
  • SARIF export
  • Community support
Start free
Enterprise
Custom

For regulated industries, compliance-bound orgs, and audit-driven teams.

  • Everything in Team
  • Determinism Attestor (signed provenance)
  • SAML SSO & SCIM
  • Audit logs & data residency
  • Per-customer spec inference
  • Unlimited finding history
  • Dedicated solutions engineer
  • 99.9% SLA
Talk to sales

Open source projects under a recognised OSS licence pay nothing on the Team plan. Just write to us.

Compare plans

What's in each tier.

FreeTeamEnterprise
Private repositories1UnlimitedUnlimited
Deterministic-core detectors
Oracle-passthrough detectors
Incremental analysis
Multi-SCM (GH/GL/BB/ADO)GH only
LLM-assisted triage
Signed provenance & attestor
SAML SSO & SCIM
Per-customer spec inference
Audit logs & data residency
Finding history7 days30 daysUnlimited
SupportCommunityEmailDedicated SE + 99.9% SLA
Questions

Pricing, answered.

What counts as a developer?

Anyone whose commits scanipy analyses in a billing month. Reviewers, bots, and read-only collaborators are free.

Do you actually offer free OSS?

Yes. If your project ships under an OSI-approved licence, the Team plan is free for that repository, regardless of contributor count. Email oss@scanipy.com.

Where does my source code live?

Scanipy clones into ephemeral, single-tenant worker containers that are torn down after each scan. The graph and findings persist; the source does not.

Can I run scanipy on-prem?

Not today. The platform is multi-tenant SaaS. We don't ship a self-hosted runner. We'd rather do one thing well.

What's the determinism attestor?

An Enterprise-only feature that re-runs every release-gated analysis under pinned spec and environment, asserts the deterministic-core SARIF is byte-identical to the original, and signs the provenance record.

How does annual billing work?

Annual prepay gets you two months free. Switch anytime; we prorate on the way down.

Still deciding?

Run scanipy on one repository, for free, forever. Upgrade only if you outgrow it.