Free forever for public repositories
Two public repositories, scanned by the same threat-model-driven engine our paying customers use. No credit card, no trial clock, no sales call. Your code is analysed on our own hardware in Europe.
Any world-readable repo on GitHub. Re-scanning a repo you have already connected never uses another slot.
A credit covers a full Smart scan of a normal repository. Small repos cost one credit; the allowance refreshes every month.
Your dependency tree checked for known-vulnerable and abandoned packages.
Threat-model-driven analysis, not a pattern matcher with a free plan bolted on. Same detection pipeline, smaller model.
Analysed on our own inference hardware in Europe. Your code is not sent to a US API and is not used to train anything.
Public issues and discussion. No SLA, and we answer honestly when something is a limitation rather than a bug.
We would rather you knew the edges up front than discovered them mid-scan.
Open-source maintainers carry a security burden without a security budget, and we benefit from the same ecosystem. It is also how we improve: scanning real code in public finds the gaps in our own detection faster than any internal benchmark, and we publish what we find — including when we get it wrong.
Sign in with GitHub, pick a public repo, and you will have findings in minutes.
Start freeNeed a consultant-led audit instead? Explore Codelight Audit →