Q. What counts as a scan?
One review of one diff. Push event, MR open/update, manual click, or CI call — they all count as one scan, no matter the diff size.
Flat platform fee, then a per-scan rate. Trial is free for 14 days. No seat licenses, no per-repo upcharge, no minimum commit volume.
14 days, one workspace, one repo. See how the reports read before you roll it out.
For backend teams with one to a dozen repos. Webhooks on, CI optional, and full reporting on every change.
High-volume scanning, self-hosted GitLab fleets, audit trails, custom contracts.
One review of one diff. Push event, MR open/update, manual click, or CI call — they all count as one scan, no matter the diff size.
No. If your token expired, the diff was unreadable, or the review could not be completed, that scan is on us.
Yes — set a soft cap in workspace settings. We'll keep scanning but won't post comments or send invoices past it until you raise the cap.
From 2,000 scans / month, the per-scan rate drops. Above 10,000, talk to us — we'll tier it sensibly.
Not on its own — only your auditor signs off. But every scan persists a timestamped record (who, what, verdict, rationale, acceptance trail) that maps to SOC 2 CC7.1, CC8.1, ISO 27001 A.14.2 and PCI-DSS 6.3. That's the part teams usually scramble to assemble two weeks before the audit. CodeGuards has it ready.