Pricing

One audit. One price. $200.

Flat per-audit pricing — the full pipeline runs every time, with a working exploit on every critical. Re-runs on a new commit are the same flat price, never a quote or a scoping call, and your team gets free audits to evaluate first. No subscriptions, no seats, no surprises.

01What $200 buys

One flat price. The whole pipeline.

$200per audit

per audit — one repo, one commit

One-time payment
Full report
Every finding with severity, exact file:line, and the vulnerable code.
Working exploit for criticals
Each critical is reproduced on a mainnet fork — proof, not just a write-up.
Architecture artifacts
Extracted invariants, assumptions, and design decisions your code relies on.
Earned verdicts
A finding is dropped only when the validator can cite the line that defeats it — otherwise it stays in front of you, flagged for review.
Re-audit on every commit
Same flat price, diffed against your last scan. No new scoping call.
Versioned, shareable report
A report link pinned to the commit, plus PDF export.

Reentrancy · oracle and price manipulation · access control and privilege escalation · accounting and invariant drift · unchecked external calls and return values.

Ready to start?

Connect a GitHub repository, select the target branch and commit, and start the audit.

Start an audit

One-time payment per audit · Charged in USD at checkout · No card on file
If your audit doesn't complete, you don't pay — a re-run or a full credit.

02How billing works

No trap. No meter. No surprises.

You commit weekly — so the real question is what the bill looks like on a repo you keep pushing to. Here's exactly how it works.

What counts as one audit

vault-core@e7b2f4a$200

You're billed once when you start an audit on a commit, and codebase size doesn't change the price — one repo, one commit, one $200 charge.

Re-audits are the same flat price

e7b2f4atoday$200
c91d3e82 days ago$200
a3f8c1d5 days ago$200

−3 critical, −5 high vs previous scan

Push a fix, run again. Each re-audit is its own $200 audit, diffed against the last — no new scoping call, no subscription. Continuous security, billed per run.

A failed run isn't a charge for nothing

audit failed to completewe make it right

If an audit fails to complete, you shouldn't pay for nothing. Message us in the chat and we'll make it right — a re-run or a credit, not a charge for a report you never got.

Teams get free audits to start

team workspace2 free audits

A team workspace ships with a configurable allowance of free audits, so the whole team can evaluate Guardix on real repositories before paying. One chat message provisions it.

03Trust & operations

The rest of what a security buyer asks.

Cloned to audit, not to train

Not training data
Your code is cloned to run the audit and is never used to train models.
Data handling
What we can read, what we keep afterwards, which model providers see your code, and how to get it deleted — spelled out on the security page. Organization-specific questions: message us in the chat.

EVM Solidity, exploit on a fork

Ethereum
Arbitrum
Optimism
Base
Polygon

Solidity source analysis on any EVM chain. Exploit proofs for critical findings run on a mainnet fork.

What you can buy today

Code audit$200 per audit
Live
PR reviewRequest access
Early access
Release audit$200 per audit
Beta
04FAQ

Frequently asked questions.

One repository at one commit, run through the full pipeline, is one $200 charge. The size of the codebase doesn't change the price — a 200-line library and a 20,000-line protocol both cost $200.
Each re-audit is a fresh audit at the same flat $200, diffed against your last scan. There's no subscription and no discount tier — just the same price every run. To be clear: re-runs are priced the same, not free.
Prioritized findings with severity, file:line, and the vulnerable code; a working fork exploit for every critical; the extracted invariants, assumptions, and decisions your code depends on; and a versioned, shareable report link plus PDF export.
Earned verdicts. A finding is dropped only when the validator can cite the exact line of code that defeats the attack. If it can't prove the finding either way, it stays in front of you, flagged for review — nothing is silently hidden, and nothing is silently kept.
Every candidate finding is challenged from both sides: we try to prove it real — reproduce the attack, grade it against your system's invariants — and we try to disprove it by hunting for the code that stops it. Confirmed findings ship with their evidence; a finding is dropped only when the validator can cite the exact line that defeats it; anything that can't be proven either way is flagged for your review instead of being silently resolved.
No. Run it first and on every fix to clear the issues a machine can prove. A manual audit still wins on novel, bespoke attack paths and economic or game-theoretic design - spend that budget where a human is irreplaceable. For a human engagement, request a manual audit from Pessimistic.
Solidity on EVM chains — Ethereum, Arbitrum, Optimism, Base, Polygon, and other EVM networks for source analysis. Exploit proofs for critical findings run on a mainnet fork.
Your code is cloned to run the audit and is never used to train models. The full picture — what we can read, what we retain afterwards, which model providers see your code, and how to get it deleted — is on the security page (/security); for organization-specific questions, message us in the chat.
Most complete in 1–3 hours depending on codebase size and complexity, with live progress throughout the run.
Yes. A team workspace ships with a configurable allowance of free audits, so the whole team can evaluate Guardix on real repositories before paying. Message us in the chat (bottom-right corner) — provisioning takes one message and goes straight to the founders.
A one-time, per-audit charge in USD via Stripe at checkout. No subscription, no card kept on file, no hidden fees. If an audit fails to complete, message us in the chat — we'll make it right (a re-run or a full credit) rather than charge you for nothing.

Still weighing it against a manual engagement? Run Guardix first and on every fix, then spend the human budget on novel attack paths. Read the full comparison →

Pessimistic

Need a human audit?

Guardix is the machine pass. It will not replace a manual engagement. For novel attack paths, request a manual audit from Pessimistic.

Run your first audit.

Connect a GitHub repository, pick a commit, and get a full validated report in hours — $200, flat. Teams get a free-audit allowance to evaluate.