Early Access β€’ Zero Monthly Subscriptions β€’ Pay-Per-Scan Credits

Budget-driven code security.
Set your price in PR/MR. We optimize the audit.

No seat licenses or monthly subscriptions. Simply comment @budgetscan $0.50 --max-delay 5m on any PR/MR. That is what we are building: BudgetScan plans how deep to scan so it fits your cap and deadline, then deducts only what the scan actually cost.

Early access, still in development. The open-source scanner (nano-analyzer) works today as a CLI, a GitHub Action and a GitLab CI job. The @budgetscan comment command, budget and deadline caps, and prepaid credits shown on this page are what we are building next. Nothing here can be purchased yet, and all examples and numbers are illustrative. Questions or want early access? Email us. Thanks for taking a look.

Illustrative example — mock output showing the intended flow, not a real scan result.

GitLab MR #418 β€” @budgetscan $0.50 --max-delay 5m
Example
reviewer-jane Looking at the C++ changes. @budgetscan $0.50 --max-delay 5m
BudgetScan Bot example
⚑

Use-After-Free Vulnerability in interpreter.cpp:142

Severity: High | Budget Cap: $0.50 | Max Delay: 5m

πŸ† Execution & Credit Summary Cost: $0.161 / $0.50 Cap
LLM Context + Scan Changed files $0.041 Within Cap
Skeptical Triage 5 rounds $0.120 Completed
Team Credit Deduction Prepaid Pool -$0.161 Remaining: $248.34

Granular PR/MR Command Control

Developers, reviewers, and PMs control the scan budget and deadline right from the comment thread.

Basic Quick Scan
@budgetscan $0.25

Lightweight Sanity Audit

Ideal for quick developer sanity checks. BudgetScan scans the changed files with a single, fast triage pass.

Real per-scan costs: published after benchmarks
@budgetscan $0.50 --max-delay 5m

Deep Audit with a Deadline

Perfect for release candidate PRs. Aims to finish within 5 minutes while spending up to $0.50 on deeper context, scanning and multi-round triage. If time runs out, you get a partial report instead of a stuck pipeline.

Real per-scan costs: published after benchmarks
High-Security Release
@budgetscan $5.00 --depth deep

Deepest Audit Your Budget Allows

Used for critical core changes. Spends the larger cap on wider context and more triage rounds, and the report lists what was covered.

Real per-scan costs: published after benchmarks

Why Pay Per Scan Instead of Per Seat

No idle seats. You pay for the scans that actually run.

Zero Waste

Credit Deducted Only on Execution

No seat licenses for developers who rarely open a PR. Credits are deducted only when a scan runs, based on what it actually cost. Failures are rare, and when one happens, nothing is charged.

Bring Your Own LLM Backend

By default, hosted scans run on our partner Kosmik Compute (EU, zero data retention). You can also choose OpenRouter, OpenAI, Google Gemini / Vertex AI, or any OpenAI-compatible endpoint such as vLLM or Ollama. Your code goes only to the provider you pick. Automatic routing to the cheapest backend is on the roadmap, not live yet. Where does my code go?

Deadline-Aware Scans

With --max-delay 5m, BudgetScan is designed not to hold up CI pipelines: when the deadline approaches, it stops starting new work and posts a partial report listing what was covered.

Skip Unchanged Files (roadmap)

Skipping unchanged files on re-scan, so you don’t pay twice for the same code, exists today in a community Go port and is planned for the main scanner.

Works With GitHub & GitLab

The scanner already runs as a GitHub Action and a GitLab CI job on every PR/MR. Triggering it from a comment with @budgetscan is what we are building next.

Simple Prepaid Credits

Top up a prepaid balance and each scan deducts only its actual cost. Team-level budget caps may come later.

A note on accuracy. AI-based scanners can flag things that turn out to be harmless (false positives) and can miss real issues (false negatives). Findings of medium severity and above go through a skeptical, multi-round triage step, and we work hard on keeping false positives to a minimum. Please treat results as strong leads for a human reviewer, not as verdicts.

Success Stories

Real results on real open-source projects, with links you can check. Right now that is one; we will add more as they happen.

First hit on open source • September 2026

Yopass: unverified emails could pass OIDC domain restrictions

Yopass is an open-source tool (over 3,000 GitHub stars) for securely sharing secrets, passwords and files. When it is set to allow logins only from certain email domains, its OIDC login trusted the email address returned by the identity provider without checking the email_verified claim. Someone with an unverified account at an identity provider under an allowed domain could therefore get past the domain restriction.

  • 23 Sep 2026. BudgetScan flagged the missing check. We opened a pull request with a fix and tests.
  • 24 Sep. An automated review asked for stronger tests, which we added. The maintainer pointed out that email_verified is an optional claim, so enforcing it blindly could break existing setups.
  • 25 Sep. Maintainer Johan Haals built on our patch in a new pull request: he kept our commit as the first one, with its authorship, and added an explicit opt-out for providers that omit the claim, a startup warning, configuration validation, tests and documentation.
  • 26 Sep. Merged into Yopass. By default, OIDC logins now require a verified email.

How to read this. Thanks to Johan Haals for the quick, careful handling. The scanner found the problem and a human maintainer decided how to fix it safely, which is how we want it to work: findings are leads for people, not verdicts. It is one data point, not a benchmark. We will publish measured results once we have them.

Interactive Budget-Scan Simulator

Select a PR scenario and test budget caps like @budgetscan $0.50 --max-delay 5m — a conceptual simulation with mock numbers, not a live scan.

> [simulation] Click "Execute PR Command" to see how a budget cap and deadline shape a scan (mock data)...

Pay-Per-Scan Credit Savings Calculator

Compare estimated pay-per-scan costs with per-seat pricing. The inputs and assumptions here are illustrative.

Annual Savings vs Flat Subscriptions $8,748 Estimate: ~28% of cap per PR vs $50/dev/mo seat fees
Actual Monthly Spend $21 / month
Traditional SAST Seat Cost $750 / month
Effective Cost Savings 97% saved

Illustrative: assumes an average scan costs about 28% of its cap and a seat price of $50 per developer per month. Real per-scan costs will replace this once we have measured them. The seat price is a placeholder, not a quote from any vendor.

Transparent Credit Packs β€’ Zero Subscription Fees

Planned prepaid credit packs: no subscription, no seat fees. Prices and terms are a draft and may change before launch. Scans rarely fail, and a failed scan is never charged.

Developer Starter

For individuals & open-source contributors

$25/ prepaid credit
  • βœ“ $0 Monthly Subscription Fee
  • βœ“ Scans per pack depend on the caps you set; real costs published after benchmarks
  • βœ“ Support for @budgetscan $X syntax
Request early access

Enterprise / Self-Hosted

Bring your own infrastructure

Custom Pool
  • βœ“ Everything in Team Shared Pool
  • βœ“ Connect your own LLM endpoint (OpenAI-compatible, vLLM, Ollama)
  • βœ“ Zero compute markup (pay your provider’s rates)
  • βœ“ On-premise runners
  • βœ“ Custom invoicing
Contact us

Where Does My Code Go?

Short answer: to EU-hosted inference with zero data retention, or nowhere outside your own infrastructure.

Zero Data Retention by Default

Hosted BudgetScan scans run on inference from our partner Kosmik Compute, which operates with zero data retention: prompts and outputs are not stored and are never used to train models. Only operational metadata (such as request logs) is kept, for up to 30 days. Their privacy details.

Hosted in the EU

Kosmik’s servers are in Prague and the operator is a Czech company under GDPR. The inference API is OpenAI-compatible: see the API docs.

Or Keep It On-Prem

The scanner is open source (Apache-2.0) and can run on your own infrastructure against your own LLM endpoint (vLLM, Ollama or any OpenAI-compatible server), so your code never leaves your network.