Pricing
Pre-launch — prices take effect at launch
Who pays, and for what.
“No publisher can pay for a rating, for a better rating, or for the removal of a finding — in money or in kind.” §17
Ratings free and public · Paid for by the people deciding whether to install
CLI and CI gate · per developer / month
Pre-install check
Look up the published verdict, its reason codes and the evidence hashes before a package is installed, on the command line and in the pull request.
Open
$0
forever
- Public packages
- Unlimited lookups
- GitHub Action in advisory mode
- Verdict and evidence hashes
Team
$15
per developer / month, annual · $19 monthly
- Private registries
- Org policy rules
- Failing pull requests
- 90-day history
- 5-seat minimum
Business
$29
per developer / month
- SSO / SAML
- Unlimited history
- Policy-as-code
- Time-boxed exemptions
- Audit export
- 250k API lookups included
Per lookup
Lookup API
The same published result, in the request path: verdict, reason codes, finding ids and evidence hashes for a package version.
Sandbox
$0
1,000 lookups / month · no SLA
Pay-as-you-go
$0.05
per lookup
Growth
$0.030
per lookup · $1,000 / month committed
Scale
$0.020
per lookup · $6,000 / month committed · 99.9% SLA
Platform
from $0.012
per lookup · annual
- Includes the attested-manifest endpoint: the canonical hash of every tool’s name, description bytes and schema, per version, for gateways to pin to §7
Per package watched
Change monitoring
Watch the packages you already depend on for a new version and a changed verdict, on the cadence the plan states.
Watch
$0
5 packages · weekly
Solo
$29
per month · 50 packages · daily
Team
$199
per month · 500 packages · 6-hourly · Slack
Fleet
$999
per month · 5,000 packages · continuous · API · SSO
A linter for publishers, never a rating
Pre-publish check
The same checks, applied to an artifact before it is published, so a publisher can fix what a finding would describe.
Open source
$0
for open-source publishers
Per run
$49
per run
Team
$19
per seat / month
“Its output is never published, never stored where the scheduled pass can read it, and never affects a grade.” §17
Quoted
No list price
Four things we price by conversation.
Private audits
The same methodology applied to a package or a set of packages you name, with the result delivered to you rather than published. A private audit never becomes a public grade, and it never changes one.
contact@attestari.ai →Attestation of inspection
Signed records of what was examined, when, under which methodology version and document hash, published to a public transparency log; control mapping to SOC 2, DORA, the Cyber Resilience Act and NIST SSDF; auditor access to the evidence behind each record.
contact@attestari.ai →Population dataset licensing
The decision rows, findings and evidence hashes across the examined population, as a dataset, for research, tooling and registries that want to build on the same record.
contact@attestari.ai →Registry white-label
Results shown inside your own registry or marketplace, under your name, with the evidence and the methodology version a click away. What is shown is what we published; a white-label never changes a result.
contact@attestari.ai →Free on purpose
Ratings are free and public
What never carries a price.
- A result page per package. The verdict, every finding with its evidence, and the methodology version that produced it.
- An embeddable badge. “Not examined” is a badge too; a badge never says more than the result page.
- A fix path per reason code. What a publisher can change so that the next version can be examined, or is examined and found clean.
- A quarterly population report. How many packages were examined, graded, refused and out of scope, and why.
- Opt-in installed-base telemetry. Anonymised reporting of which examined packages your CLI sees, so the population report can weight by what is actually installed. Off unless turned on; never carries personal data.
Independence is the product. Read how subjects are chosen §4 and what we do not examine §15, or the whole methodology.