Skip to content
git.exposed
Pricing

Find vulnerabilities before attackers do

Free for open source. Pro for teams who ship fast. Enterprise for organizations that can't afford a breach.

Free

$0/forever

For open-source maintainers and quick checks.

  • Public repo scanning
  • 150+ secret patterns
  • 3,000+ SAST security rules
  • CVE vulnerability database
  • Shareable reports & badges
  • Private repo scanning
  • AI-powered fix PRs
  • Continuous monitoring
Recommended

Pro

$19/month

Ship fast without shipping vulnerabilities. Less than $0.63/day.

  • Everything in Free
  • Private repo scanning
  • AI-powered fix PRs
  • Continuous push monitoring
  • GitHub commit status checks
  • Priority scan queue
Upgrade to Pro

Cancel anytime · 7-day money-back guarantee

Enterprise

Custom

For security-critical organizations with compliance needs.

  • Everything in Pro
  • Dedicated scanner infrastructure
  • SSO / SAML authentication
  • Custom security policies
  • Org-wide dashboard & reporting
  • SLA & priority support
  • Self-hosted deployment option

Powered by OpenGrep · Trivy · Betterleaks— the same tools used by security teams worldwide

Frequently asked questions

What scanners are included?

Every plan includes OpenGrep (3,000+ SAST rules), Betterleaks (150+ secret patterns), and Trivy (CVE vulnerability database). All scanners run on every scan.

How does AI fix work?

Pro only. Click "Fix" on a finding and our AI agent reads the vulnerability, generates a targeted code fix, and opens a pull request in your repo. You review and merge.

What does continuous monitoring do?

Pro installs a GitHub webhook on your repo. Every push triggers an automatic scan, and results are posted as commit status checks — so your team catches issues before merge.

Can I cancel anytime?

Yes. Cancel from your billing portal with one click. You keep Pro access until the end of your billing period. No questions asked.

Is my code safe?

Code is downloaded to an isolated container, scanned, and immediately deleted. We never store your source code. Only scan results are persisted for reports.

What does Enterprise include?

Dedicated infrastructure, SSO/SAML, custom security policies, org-wide reporting, SLA guarantees, and optional self-hosted deployment. Contact us to discuss your needs.