Pricing

Start with a free scan of your website. Upgrade when you want your code checked before it ships, and your database rules tested.

Free

Passive scan of any website, A–F grade, fixes for each issue, shareable report, and a free badge for sites you own.

Scan for free

Paid plans

Billed monthly and you can cancel anytime, or buy a one-time audit for $15 if you are not ready to subscribe.

Code

Deep scan of your source code on every push.

$19/ month

  • GitHub Action on every push and pull request
  • 200 deep scans per month
  • Leaked secrets, vulnerable dependencies, risky code patterns
  • AI review of the risky lines, with a fix you can paste
  • Findings posted on your pull requests
  • Your code is never stored

Billing not configured (STRIPE_* settings)

Code + Backend

Most complete

Your source code, plus your database and APIs.

$49/ month

  • Everything in Code, with 500 deep scans per month
  • Supabase RLS and Firebase rules tested on your real project
  • Sign-up settings checked (email confirmation)
  • Weekly monitoring of up to 5 sites, with alerts when your grade drops
  • A “security” badge for your site and README, backed by these checks

Billing not configured (STRIPE_* settings)

You can cancel anytime, and prices are in USD excluding tax.

Questions

Do you store my code?

No, the GitHub Action sends only the files changed in a commit. They are encrypted in transit, scanned in memory inside a throwaway sandbox with no network access, then deleted, and we keep only the findings, with secrets masked.

Is the free scan safe to run on my production site?

Yes, it only sends ordinary GET requests to the exact address you enter, like a visitor’s browser would, with about 80 requests at most. It never logs in, submits a form or changes any data.

Who can see my report?

Free reports are shared by an unguessable link, and you can hide your domain on it. Code and monitoring reports are visible only to you, signed in.

How does the GitHub Action authenticate?

It uses the short-lived identity token GitHub gives each workflow run, so there is no API key to store in your repository. We also check that the token was issued for your repository and that exact commit.

What do backend checks access?

They access only what an anonymous visitor could, using the public keys you give us (never a service_role key), and only after you prove you own the site. For Supabase we count rows and never download them.

What happens when you find a leaked key?

We show where it is, masked (sk_live_****a3f9), with the exact steps to rotate it and move it to the server, and we never use a key we find.

Does this replace a penetration test?

No, it catches the mistakes AI coding tools make most often, on every change. If you handle payments or sensitive data, a pentest by a person is still worth it before a big launch.

Can I cancel anytime?

Yes, from Manage billing on your dashboard, and you keep access until the end of the period. Deleting your account cancels billing and erases your data immediately.