Pricing · Per-repo seat model

Pick the seat.
Per repo, not per engineer.

Codicrest bills the repository, not the team. Open Source stays free forever for public repos; Team expands the surface with multi-repo rollups and private registry ingestion; Enterprise adds the SSO, dedicated runner pool and SLA your AppSec team asks for.

The three tiers

One pricing axis: the repository.

No headcount math. No seat-puzzle. Choose the repo surface you need Codicrest to cover; upgrades are a single conversation, not a procurement cycle.

For OSS

Open Source

Free foreverPublic repos · unlimited

For solo maintainers and OSS repositories.

  • Continuous CVE monitoring on npm, PyPI and Maven
  • Patch-ready PRs in an isolated sandbox
  • CRA-ready audit trail & SBOM delta
  • Reachability-aware signal scoring
Most popular

Most popular

Team

$49per repo / month · seats included

Per-repo seats — bill the repo, not every engineer.

  • Everything in Open Source
  • Multi-repo aggregation rollups
  • Private registry ingestion
  • Volume discount above 10 seats

Custom

Enterprise

CustomSSO · SCIM · dedicated runner pool

For teams with dedicated AppSec, compliance and SRE review.

  • Everything in Team
  • SSO + SCIM provisioning
  • Private VPC & dedicated runner pool
  • SLA, support response times, audit log retention

Pay per repo, billed monthly · seats included per repo on Team · volume discount above 10 seats · cancel any time.

The full comparison

Every feature, every tier.

What ships in each plan — and what we deliberately hold back for the AppSec team to sign off.

  • Continuous CVE monitoring (npm / PyPI / Maven)

    Live advisory feeds + version diff on every committed dependency.

    OSSTeamEnterprise
    OSS:IncludedTeam:IncludedEnt:Included
  • Patch-ready PRs in an isolated sandbox

    Agent drafts the minimal source change, runs your tests, opens the PR.

    OSSTeamEnterprise
    OSS:IncludedTeam:IncludedEnt:Included
  • CRA-ready audit trail & SBOM delta

    Every shipped fix attaches an immutable SBOM delta + reviewer approval.

    OSSTeamEnterprise
    OSS:IncludedTeam:IncludedEnt:Included
  • Multi-repo aggregation rollups

    A single ingest per org — not per repo, not per engineer.

    OSSTeamEnterprise
    OSS:Team:IncludedEnt:Included
  • Reachability-aware signal scoring

    A CVE that never executes in your code no longer wakes your team.

    OSSTeamEnterprise
    OSS:Public reposTeam:IncludedEnt:Included
  • Private registry ingestion

    Declared once — your internal packages tracked alongside public ones.

    OSSTeamEnterprise
    OSS:Team:Add-onEnt:Included
  • SSO + SCIM

    Google Workspace, Okta, Azure AD — with SCIM seat provisioning.

    OSSTeamEnterprise
    OSS:Team:Ent:Included
  • Dedicated runner pool

    Private VPC, dedicated compute — your code never leaves your region.

    OSSTeamEnterprise
    OSS:Team:Ent:Included
  • SLA & support response times

    Named CSM, 99.9% uptime contract, audit log retention.

    OSSTeamEnterprise
    OSS:Team:Best-effortEnt:Included

All paid plans include unlimited watch on every repo you own or administer — no per-repository seat math. Multi-org rollups ship at no extra cost on Enterprise.

Start with the waitlist

One conversation away from a sandboxed patch on your repo.

Design-partner onboarding is open this quarter. Drop your email — we'll send a 30-minute walkthrough on a stack you actually care about, and a price quote for the repos you want covered.

or email us directly → codicrest@polsia.app