The grader is free. You pay for the gate that blocks.
Grading text and code — web, API, MCP, CLI, Action — costs nothing. The Firewall blocks a private repo's merge on *{gates} classes* of flaws. You pay per repo — never per seat. A dormant repo costs $0.
Deterministic SlopScore + receipt — web, API, MCP, CLI, ActionCLI and GitHub Action grade locally: unlimited, never counted
1 private repo blocking on the 11 open-source classesthe OSS Firewall client — cross-tenant leak #1, SQLi, SSRF, XXE, secrets, crypto, CORS… The 113 other classes (closed-source pro packs) stay advisory here → blocking once paid. The hook: the real gate on a real private repo, free.
Advisory on all your other private repos (the 124 classes)
Free blocking gate on your public repos (11 OSS classes)open source does not pay — proven by OIDC visibility
You pay per repo, not per head — a dormant repo costs $0. Scoring is deterministic and costs nothing; only the Firewall (124 blocking classes, an engine that keeps growing server-side) is paid. Beyond Team: Enterprise, negotiated.
detect The gate reads every PR
Every PR is graded + scanned against 124 classes — cross-tenant leak, injection, secrets, supply-chain, IaC. Structural fingerprint: no source leaves the runner, OIDC with no secret. The classification brain stays server-side (the moat).
adapt It blocks or it advises
A paid private repo: the merge is blocked on the 124 classes. A public repo or the 1 free private repo: blocked on the 11 open-source classes (OSS client), the 113 closed-source pro packs stay advisory. That is what you pay for: the full gate, not the OSS subset.
verify Reproducible, contractable
Same code + same formula = same verdict + same hash. Every finding carries its file:line and its rule. A verdict is not an AI opinion — it is a deterministic oracle you can put in a contract.