Scanning is free. The fix is what you pay for.
From $19/month. No login to scan, and you see how many exposures you have before you pay anything. The tiers differ in how much you watch and how often, not in how deep we look: every plan runs the same checks.
Starter
$19/month
One app, watched.
- One connected target: a repo or a live URL
- All available checks, with evidence and the copy-paste fix
- Unlimited re-scans to confirm your fixes landed
- Weekly monitoring, alert only when something is new
Pro
$49/month
Everything you ship.
- Up to five connected targets
- All available checks, with evidence and the copy-paste fix
- Unlimited re-scans to confirm your fixes landed
- Nightly monitoring, alert only when something is new
- Scan history and resolved-since-last-scan tracking
Team
$99/month
The whole estate.
- Unlimited connected targets
- All available checks, with evidence and the copy-paste fix
- Unlimited re-scans to confirm your fixes landed
- Nightly monitoring, alert only when something is new
- Every repo the GitHub App can see, across organisations
Cancel any time · billed through Stripe · you pick the plan after the scan · 14-day refund
What the subscription is actually for
A one-off scan tells you about today. Your app ships tomorrow: a migration lands without RLS, a key gets pasted into a client component, a bucket is flipped public to debug an upload.
Sentris re-scans on a schedule and diffs against the last run. You hear from it only when something is new. The same finding never mails you twice, because a monitor you learn to ignore protects nobody.
When a scan comes back clean, that is the product working. You are buying the quiet.
Which one
- StarterOne app you actually care about. Checked weekly.
- ProYou ship across a handful of repos and want to hear about it the next morning.
- TeamMore projects than you can name from memory, across organisations.
Moving between plans is a click in Stripe, and the change takes effect here by itself.
Before you decide
What is free?
The scan itself, with no login. You see how many exposures were found and the grade before you pay anything: that is the proof there is something to buy. Where they are, what the evidence is and how to close them is the subscription.
Do the plans differ in what gets checked?
No. Every tier runs the same checks, including live confirmation against a verified target. The ladder is how many targets you watch and how often, never how hard we look. A $19 customer and a $99 customer get the same verdict on the same table.
What happens if I cancel?
Access follows your Stripe subscription automatically. You keep your account and your scan history; the findings lock again. Nothing to email us about, and no retention script on the way out.
Can I get a refund?
Fourteen days, no reason required, by email, on the first payment and every renewal. Once you have read the findings you have them, which is exactly why the window is unconditional rather than argued about.
Is there an annual discount or a free trial?
An annual plan, yes: the same tier, billed once a year, 20% off the twelve monthly payments. No trial: on a product that delivers its whole value in the first thirty seconds a trial is just a slower paywall, and the scan is already free. The 14-day refund covers the annual plan too.
Not sure it is worth $19? Read a full report first : a real scan, nothing held back.
Find out what you are buying first.
The scan costs nothing and needs no account. Pick a plan afterwards, once you know whether there is anything to fix.
No login, no signup: results in seconds. A URL scan only sees your client bundle, so it covers exposed secrets and response security headers.
Connect GitHub to scan the codeRead-only, nothing is cloned, revoke it whenever you like. Your RLS policies, storage buckets and route handlers live in the repo, and that is the only place they can be checked.
By scanning you confirm the app is yours or that you are authorised to test it. See the terms.