Start free. Upgrade when your app grows. Enterprise and VPC-hosted on request.
What counts as a scan? One full analysis run of one project (all analyzers + reasoner + report). Retests do not count.
What happens if I exceed my scan quota? You get soft-warned at 80%; further scans require a top-up credit pack ($99 / 5 scans) or an upgrade. Scheduled scans pause instead of failing.
Do you train on my code? No. Claude is called with zero-retention settings; prompt caches are keyed per-tenant. We never use customer code to improve generalized detection — new rules come from our own research and design-partner feedback.
Can I self-host? On Enterprise, yes — a VPC-hosted control plane option is available. On other tiers, no.
What's the evidence retention? Free 7 days / Indie 30 / Startup 90 / Growth 180 / Business 365 / Enterprise 7 years. Evidence lives in S3 Object Lock (WORM), per-tenant KMS key, immutable within the retention window.