Pricing

Pre-launch — prices take effect at launch

Who pays, and for what.

“No publisher can pay for a rating, for a better rating, or for the removal of a finding — in money or in kind.” §17

Ratings free and public · Paid for by the people deciding whether to install

CLI and CI gate · per developer / month

Pre-install check

Look up the published verdict, its reason codes and the evidence hashes before a package is installed, on the command line and in the pull request.

  • Open

    $0

    forever

    • Public packages
    • Unlimited lookups
    • GitHub Action in advisory mode
    • Verdict and evidence hashes
  • Team

    $15

    per developer / month, annual · $19 monthly

    • Private registries
    • Org policy rules
    • Failing pull requests
    • 90-day history
    • 5-seat minimum
  • Business

    $29

    per developer / month

    • SSO / SAML
    • Unlimited history
    • Policy-as-code
    • Time-boxed exemptions
    • Audit export
    • 250k API lookups included

Per lookup

Lookup API

The same published result, in the request path: verdict, reason codes, finding ids and evidence hashes for a package version.

  • Sandbox

    $0

    1,000 lookups / month · no SLA

  • Pay-as-you-go

    $0.05

    per lookup

  • Growth

    $0.030

    per lookup · $1,000 / month committed

  • Scale

    $0.020

    per lookup · $6,000 / month committed · 99.9% SLA

  • Platform

    from $0.012

    per lookup · annual

    • Includes the attested-manifest endpoint: the canonical hash of every tool’s name, description bytes and schema, per version, for gateways to pin to §7

Per package watched

Change monitoring

Watch the packages you already depend on for a new version and a changed verdict, on the cadence the plan states.

  • Watch

    $0

    5 packages · weekly

  • Solo

    $29

    per month · 50 packages · daily

  • Team

    $199

    per month · 500 packages · 6-hourly · Slack

  • Fleet

    $999

    per month · 5,000 packages · continuous · API · SSO

A linter for publishers, never a rating

Pre-publish check

The same checks, applied to an artifact before it is published, so a publisher can fix what a finding would describe.

  • Open source

    $0

    for open-source publishers

  • Per run

    $49

    per run

  • Team

    $19

    per seat / month

“Its output is never published, never stored where the scheduled pass can read it, and never affects a grade.” §17

Quoted

No list price

Four things we price by conversation.

Private audits

The same methodology applied to a package or a set of packages you name, with the result delivered to you rather than published. A private audit never becomes a public grade, and it never changes one.

contact@attestari.ai

Attestation of inspection

Signed records of what was examined, when, under which methodology version and document hash, published to a public transparency log; control mapping to SOC 2, DORA, the Cyber Resilience Act and NIST SSDF; auditor access to the evidence behind each record.

contact@attestari.ai

Population dataset licensing

The decision rows, findings and evidence hashes across the examined population, as a dataset, for research, tooling and registries that want to build on the same record.

contact@attestari.ai

Registry white-label

Results shown inside your own registry or marketplace, under your name, with the evidence and the methodology version a click away. What is shown is what we published; a white-label never changes a result.

contact@attestari.ai

Free on purpose

Ratings are free and public

What never carries a price.

  • A result page per package. The verdict, every finding with its evidence, and the methodology version that produced it.
  • An embeddable badge. “Not examined” is a badge too; a badge never says more than the result page.
  • A fix path per reason code. What a publisher can change so that the next version can be examined, or is examined and found clean.
  • A quarterly population report. How many packages were examined, graded, refused and out of scope, and why.
  • Opt-in installed-base telemetry. Anonymised reporting of which examined packages your CLI sees, so the population report can weight by what is actually installed. Off unless turned on; never carries personal data.

Independence is the product. Read how subjects are chosen §4 and what we do not examine §15, or the whole methodology.