Pricing

Start on Free and add seats as the team grows.

Free

$0/ mo

100 scans a month on private repositoriesPublic repositories scan free

  • Included1 seat
  • Included3 repositories
  • IncludedEvery rule in the Managed Ruleset
  • IncludedYour own YAML rules
  • Included90 days of scan history
  • Not includedInvite teammates
Get started

Pro

$17.50/ dev / mo

Unlimited scans5 developers: $1,050.00 a year

  • IncludedAll Free features
  • IncludedSeats for the whole team
  • Included10 repositories per seat
  • IncludedInvite teammates by email
  • IncludedScan history while the workspace exists
  • IncludedBilled once a year at $210 per developer, $30 less than monthly
Get Pro

Custom

Enterprise

Teams of more than 100 developersCustom terms

  • IncludedAll Pro features
  • IncludedProcurement and invoicing
  • IncludedSecurity review
  • IncludedCustom scan history retention
Contact us

Scanning

FeatureFreeProEnterprise
Scans on private repositoriesThe counter resets on the 1st of each month at 00:00 UTC.100 per monthUnlimitedUnlimited
Scans on public repositoriesOnce the platform verifies a repository is public, its scans are never counted.UnlimitedUnlimitedUnlimited

Engines

FeatureFreeProEnterprise
Code analysis (SAST)Follows untrusted input across your files.JavaScript, TypeScript, Java, C#JavaScript, TypeScript, Java, C#JavaScript, TypeScript, Java, C#
Dependency analysis (SCA)npm, Maven, NuGetnpm, Maven, NuGetnpm, Maven, NuGet
Checks whether your code reaches the vulnerable functionIncludedIncludedIncluded

Rules

FeatureFreeProEnterprise
Managed RulesetEvery rule we maintain, for every language we support, on every scan.FullFullFull
Your own YAML rulesIncludedIncludedIncluded

Evidence and reporting

FeatureFreeProEnterprise
Entry point, dangerous call and the full path on every findingIncludedIncludedIncluded
Findings dashboardEvery finding with its trace, ready for team review.IncludedIncludedIncluded
SARIF outputFor GitHub code scanning and other tools.IncludedIncludedIncluded
GitHub pull request checksIncludedIncludedIncluded
One sticky pull request commentIncludedIncludedIncluded

Workspace

FeatureFreeProEnterprise
SeatsA seat is a member of your workspace. A pending invitation holds a seat too.1Your whole teamCustom
Repositories310 per seatCustom
Invite teammates by emailNot includedIncludedIncluded

Data

FeatureFreeProEnterprise
Where scans runThe platform never clones your repositories.Your CI or your machineYour CI or your machineYour CI or your machine
Scan historyFindings and their triage are kept on every plan.90 daysWhile your workspace existsCustom
What a scan uploadsFindings, rule ids, repository identity, branch, file paths, line numbers and hashes of committer emails.FindingsFindingsFindings
Source lines in an uploadOff by default. Sent only if you pass the snippet option yourself.Opt inOpt inOpt in

Frequently asked questions

Do the 100 scans reset?

Yes. Free includes 100 scans of private repositories per calendar month, and the counter resets on the 1st at 00:00 UTC. Signing up on the 28th gives you three days of that first month.

How do public repositories work?

Once the platform verifies a repository is public, its scans never count toward the monthly limit. A fair use limit of 500 scan uploads per repository per day applies everywhere.

Is there a free trial?

Free is the trial. Every plan runs the same engine and the same rules, so Free shows you exactly what Pro finds, with 1 seat, 3 repositories and 100 scans a month of private repositories. There is no card and no time limit.

What exactly is a seat?

A seat is a member of your workspace, and a pending invitation holds a seat too. Atmos also counts the developers active in your repositories over the last 90 days and warns you when they outnumber your seats. That comparison never blocks a scan.

Does Atmos see my source code?

Scans run in your CI or on your machine, and the platform never clones your repositories. What a scan uploads is the findings: rule ids, repository identity, branch, file paths, line numbers, the trace behind each finding, and hashes of committer emails. The lines of code themselves are not uploaded unless you turn the snippet option on yourself, and --no-upload keeps even the findings local.

Who do I contact about Enterprise?

Enterprise is for teams with more than 100 developers. Write to us from the contact page with the size of the team, and we set up procurement and invoicing, a security review and the scan history retention you need.

Put your codebase underĀ Atmos