Skip to main content

Credits & billing

AISafe uses a credit-based consumption model. Credits are the currency that funds assessment runs, report generation, and continuous capabilities like PR review and monitoring. You purchase credits upfront or subscribe to a plan that includes a monthly credit allowance.

How credits work​

AISafe prices a code audit from its exact LOC and token units, which it computes after offline analysis and snapshot validation. Fixed-price assessment types use their catalogue price. AISafe shows the final cost before Start, debits credits when the assessment starts, and refunds them if the assessment fails due to a platform error. If a run is stopped before it ever starts, while it is still waiting for a slot, AISafe refunds it in full, because none of the credits have been used for work. If a run is stopped after it has begun, the credits it spent are not refunded, because that work was carried out. PR review, monitoring, and scheduled scans require Pro or Enterprise. Continuous capabilities like PR review and monitoring consume credits per invocation.

Purchasing credits​

You can purchase credits in two ways: through the dashboard under Billing, or via the API. One-time credit packs are available without a subscription. Subscription plans include monthly credits that arrive each billing cycle.

How long credits last depends on where they came from. A one-time credit pack lasts a year from the day it arrives. A subscription's monthly credits last for the month that paid for them: they expire when that billing period ends, and they do not roll over. For example, a $500 plan gives you $500 to spend each month rather than a balance that grows from month to month. A yearly plan grants the whole year's credits at once, and those credits last the year.

The Billing history table shows the expiry date of each entry. Check the date there instead of counting a year forward yourself. Credits are always spent soonest-to-expire first, so this month's subscription credits go before a credit pack you bought earlier.

Duplicate charge prevention​

Credit spending is idempotent. If duplicate events trigger the same operation twice, the system records a single debit. AISafe tracks each credit-consuming operation with a unique reference, so retries and duplicate deliveries resolve to a single debit. The same logical action incurs a single charge, even when upstream systems fire redundant events.

Plans​

Every organization starts on Free, which includes a small number of projects and seats and a wait between free scans. Pro comes at four levels — $40, $100, $250 and $500 a month — and the level sets how many credits arrive each month: $100 a month includes 100 credits. The level also sets how much continuous AI work is included each month, before credits are billed. A yearly plan costs less per month and adds the whole year's credits when it starts. Enterprise is a negotiated contract with its own limits.

Pro adds scheduled scans, PR security review, live regression monitoring, issue export to Jira, Linear, GitHub and GitLab, Slack and Teams alerts, API keys and outbound webhooks, project-level compliance posture, the suppression register, higher project and seat limits, and rescans with no wait.

Some of those also have a count limit. Free includes no API keys and no webhooks; Pro includes ten of each, and Enterprise negotiates its own. Revoked API keys do not count against the limit, and if a plan change puts you over one, the keys and webhooks you already have keep working; only new ones are blocked.

Every plan can run paid work. Any organization, Free included, can buy credits and run AI code audits, and every deliverable of a paid assessment, its report and its compliance mapping, is included on every plan. Attestation letters are not released yet; they follow the same rule when they arrive. The Pro compliance feature is the project posture: control coverage tracked across every assessment in a project over time. A single assessment's own mapping and export come with the assessment.

Subscribing​

Open Billing in the dashboard. The Plan card at the top shows what you are on now; Upgrade opens a panel where you pick a level, then sends you to the payment provider's hosted checkout. When you come back, the page confirms the subscription. Payment confirmation arrives over a webhook, so your plan can take a few seconds to appear — refresh if the page says the payment is still processing.

You need the admin or owner role to change a plan or buy credits.

Changing or cancelling​

Manage subscription, beside your balance on the Billing page, opens the payment provider's customer portal. You change your level, update your card and cancel there, so that you are only billed once. If you cancel, you stay on Pro until the end of the period you already paid for, and AISafe never takes back credits it has already granted.

If AISafe set your plan for you, as with an Enterprise contract or a plan arranged with us, you have no subscription to manage, and the Billing page tells you so instead. Email [email protected] to change it.

Included allowances and extra usage​

A Pro subscription includes a monthly volume of continuous AI work: PR reviews, monitor runs, and fix-verification reviews. Each one covered by that volume appears in your transaction list as a $0 included line, so you can see exactly what your subscription paid for. Your credit balance does not move.

What the subscription includes each month depends on the level:

Pro levelPR reviewsMonitor runsFix-verification reviews
$4030303
$1001006010
$25030015030
$50075030060

Once a month's allowance is used up, further work continues. It debits credits as extra usage and appears as ordinary spend lines. Each PR review past the allowance costs $1, subject to your available credits and spend caps. AISafe does not quietly give you unlimited usage, and it does not charge you for anything without showing the charge.

Each review counts once. One push reviews its latest commit, even when the push contains several commits. A new push, an authorized @aisafe review, or Run again requests another review and uses another included review or $1. Duplicate webhook deliveries and internal retries do not count again.

The allowance month is the calendar month in UTC, rather than a month that starts on your subscription anniversary. Every allowance resets at the start of the month.

When a review is confirmed as failed or incomplete, AISafe returns its included review or its credit charge. AISafe also returns the funding for unfinished work that a newer attempt replaced, and for reviews whose required publication cannot be delivered. AISafe shows a pending return until accounting confirms it. Completed reviews keep their charge when you request another review. A change with no reviewable code is not charged.

If funding prevents a review, AISafe posts a notice with the next action. Adding credits, upgrading, or changing a spend cap does not restart it automatically: comment @aisafe review, use Run again, or push a new commit.

Free organizations have no included allowances and are never blocked from paying for work: any organization can buy credits and run assessments.

Source fix reviews​

Source reviews check fixes submitted for code audits and white-box assessments. The first completed review of each finding is free. Later source reviews use your plan’s included fix-verification reviews, then cost $1 per finding by default. The quote shows the exact price before you start. Reusing a result for the same source and finding adds no charge.

When you start verification, AISafe reserves the quoted credits or included units. The receipt shows the reservation until the review completes. If verification fails, AISafe returns those credits or units, and a failed first review keeps its free review. A price change does not change a quote you already accepted.

Live black-box verification remains a separate, free beta with no source quote.

If a billing interruption cannot be resolved automatically, the receipt asks you to contact support, and you cannot retry until the balance has been checked. AISafe does not label an unresolved reservation as refunded.

Usage tracking​

The Billing page in organization settings shows your current credit balance, recent transactions (purchases, assessment debits, refunds), and usage trends. You can set up low-balance alerts to receive notifications before credits run out.

Spend guardrails​

Organizations can configure a monthly spend policy with alert thresholds and optional blocking enforcement. A policy can set an organization-wide cap, a per-project cap, a calendar-month or rolling-30-day window, and threshold percentages such as 80%.

When enforcement is set to warn, AISafe allows new spend but emits spend.threshold_crossed once per threshold and window. When enforcement is set to block, AISafe rejects new assessment starts and skips continuous capabilities before any debit if the projected spend would exceed the cap. Refunds reduce the current window spend.

The Spend posture view in organization settings shows current window spend, cap state, per-capability breakdown, and projected end-of-window burn.

Notifications​

AISafe sends notifications for billing events, including spend thresholds and cap-reached states. You can route these to Slack, email, or other tools you already use.