Pricing
Everything that runs on one repository is free, forever. You pay when you want the whole organisation in one view, and to see it change over time.
Free
- Scan, explain, diff, fix and badge any repository
- Fix pull requests, GitHub Action, MCP server
- Org audit summary in your terminal
How paid plans are priced
By agent repositories: repositories with at least one agent instruction or MCP config file. The free audit summary tells you how many you have. Annual plans match the yearly audit cycle; the snapshot is for evidence once.
Not sure which fits? Ask us.
Snapshot audit
- One organisation, up to 100 agent repositories
- Full report: every repo graded, where teams disagree, ranked fix plan
- Compliance evidence pack (SOC 2, ISO 27001, ISO 42001, NIST AI RMF)
- 14 days to fix and re-run
- Credited in full toward an annual plan started within 30 days
Team
$1,188 per year
- One organisation, up to 50 agent repositories
- Unlimited audits and evidence packs all year
- Trends: what improved or regressed since the last audit
- Ongoing-monitoring control (TC-08) evidenced
On the roadmap: Scheduled weekly audits in your own GitHub, with regression issues.
Business
$3,588 per year
- One organisation, up to 500 agent repositories
- Everything in Team
- Priority email support
On the roadmap: Org-wide fix pull requests; Developer-machine MCP inventory; Policy baseline for every repository.
Agency
- Up to 10 client organisations
- Full reports and evidence packs for each
- Trends for every organisation
- More organisations: $249 a year each, by email
Enterprise from $12,000 per year
Unlimited agent repositories and organisations · Invoicing, procurement and security questionnaires · Custom rule packs for your policies · Priority support and rollout help.
Secure checkout by Stripe · Manage or cancel from the licence page · Licences are verified offline · Prices in USD, taxes may apply · Terms
What the org audit shows
- A fleet grade and every repository’s grade, worst first
- Where repositories disagree: package managers, test runners, linters, runtime versions
- A fix plan ranked by score gained per unit of effort, with what can be fixed automatically
- Security findings in one table: hidden characters, secrets in context, unpinned MCP servers
- An editable estimate of what duplicated and generic text costs in tokens
- A compliance evidence pack: 8 controls cross-referenced to SOC 2, ISO/IEC 27001, ISO/IEC 42001 and NIST AI RMF, with an agent and MCP server inventory (details)
- With Team or Agency: what changed since the previous audit
Try the free summary first: npx threadctx audit --org your-org