Free
100 scans a month on private repositoriesPublic repositories scan free
- Included1 seat
- Included3 repositories
- IncludedEvery rule in the Managed Ruleset
- IncludedYour own YAML rules
- Included90 days of scan history
- Not includedInvite teammates
Start on Free and add seats as the team grows.
100 scans a month on private repositoriesPublic repositories scan free
Unlimited scans5 developers: $1,050.00 a year
Teams of more than 100 developersCustom terms
| Feature | Free | Pro | Enterprise |
|---|---|---|---|
| Scans on private repositoriesThe counter resets on the 1st of each month at 00:00 UTC. | 100 per month | Unlimited | Unlimited |
| Scans on public repositoriesOnce the platform verifies a repository is public, its scans are never counted. | Unlimited | Unlimited | Unlimited |
| Feature | Free | Pro | Enterprise |
|---|---|---|---|
| Code analysis (SAST)Follows untrusted input across your files. | JavaScript, TypeScript, Java, C# | JavaScript, TypeScript, Java, C# | JavaScript, TypeScript, Java, C# |
| Dependency analysis (SCA) | npm, Maven, NuGet | npm, Maven, NuGet | npm, Maven, NuGet |
| Checks whether your code reaches the vulnerable function | Included | Included | Included |
| Feature | Free | Pro | Enterprise |
|---|---|---|---|
| Managed RulesetEvery rule we maintain, for every language we support, on every scan. | Full | Full | Full |
| Your own YAML rules | Included | Included | Included |
| Feature | Free | Pro | Enterprise |
|---|---|---|---|
| Entry point, dangerous call and the full path on every finding | Included | Included | Included |
| Findings dashboardEvery finding with its trace, ready for team review. | Included | Included | Included |
| SARIF outputFor GitHub code scanning and other tools. | Included | Included | Included |
| GitHub pull request checks | Included | Included | Included |
| One sticky pull request comment | Included | Included | Included |
| Feature | Free | Pro | Enterprise |
|---|---|---|---|
| SeatsA seat is a member of your workspace. A pending invitation holds a seat too. | 1 | Your whole team | Custom |
| Repositories | 3 | 10 per seat | Custom |
| Invite teammates by email | Not included | Included | Included |
| Feature | Free | Pro | Enterprise |
|---|---|---|---|
| Where scans runThe platform never clones your repositories. | Your CI or your machine | Your CI or your machine | Your CI or your machine |
| Scan historyFindings and their triage are kept on every plan. | 90 days | While your workspace exists | Custom |
| What a scan uploadsFindings, rule ids, repository identity, branch, file paths, line numbers and hashes of committer emails. | Findings | Findings | Findings |
| Source lines in an uploadOff by default. Sent only if you pass the snippet option yourself. | Opt in | Opt in | Opt in |
Yes. Free includes 100 scans of private repositories per calendar month, and the counter resets on the 1st at 00:00 UTC. Signing up on the 28th gives you three days of that first month.
Once the platform verifies a repository is public, its scans never count toward the monthly limit. A fair use limit of 500 scan uploads per repository per day applies everywhere.
Free is the trial. Every plan runs the same engine and the same rules, so Free shows you exactly what Pro finds, with 1 seat, 3 repositories and 100 scans a month of private repositories. There is no card and no time limit.
A seat is a member of your workspace, and a pending invitation holds a seat too. Atmos also counts the developers active in your repositories over the last 90 days and warns you when they outnumber your seats. That comparison never blocks a scan.
Scans run in your CI or on your machine, and the platform never clones your repositories. What a scan uploads is the findings: rule ids, repository identity, branch, file paths, line numbers, the trace behind each finding, and hashes of committer emails. The lines of code themselves are not uploaded unless you turn the snippet option on yourself, and --no-upload keeps even the findings local.
Enterprise is for teams with more than 100 developers. Write to us from the contact page with the size of the team, and we set up procurement and invoicing, a security review and the scan history retention you need.
Subscriptions are governed by the Terms of Service, which covers cancellation and refunds. What a scan sends us is in the Privacy Policy.