Skip to main content

Credits & billing

AISafe uses a credit-based consumption model. Credits are the currency that funds assessment runs, report generation, and continuous capabilities like PR review and monitoring. You purchase credits upfront or subscribe to a plan that includes a monthly credit allowance.

How credits work

Each assessment run consumes credits based on its type, the size of the target (lines of code for code audits, number of endpoints for pentests), and the selected duration. You see the estimated credit cost before starting an assessment. AISafe debits credits when the assessment starts and refunds them if the assessment fails due to a platform error. Continuous capabilities like PR review and monitoring consume credits per invocation.

Purchasing credits

You can purchase credits in two ways: through the dashboard under Billing, or via the API. One-time credit packs are available without a subscription. Subscription plans include monthly credits that arrive each billing cycle.

Credits expire one year after they arrive. The Billing history table shows each purchase's expiry date. Credits are consumed oldest-first, so the ones closest to expiring are always spent first.

Duplicate charge prevention

Credit spend is idempotent. If duplicate events trigger the same operation twice, the system records a single debit. AISafe tracks each credit-consuming operation with a unique reference, so retries and duplicate deliveries resolve to a single debit. The same logical action incurs a single charge, even when upstream systems fire redundant events.

Plans

Every organization starts on Free, which includes a small number of projects and seats and a wait between free scans. Pro comes at four levels — $40, $100, $250 and $500 a month — and the level sets how many credits arrive each month: $100 a month includes 100 credits. All four levels unlock the same features; only the credit volume differs. A yearly plan costs less per month and adds the whole year's credits when it starts. Enterprise is a negotiated contract with its own limits.

Pro adds scheduled scans, issue export to Jira, Linear, GitHub, GitLab and Bitbucket, Slack and Teams alerts, API keys and outbound webhooks, project-level compliance posture, the suppression register, higher project and seat limits, and rescans with no wait.

Some of those also have a count limit. Free includes no API keys and no webhooks; Pro includes ten of each, and Enterprise negotiates its own. Revoked API keys do not count against the limit, and if a plan change puts you over one, the keys and webhooks you already have keep working — only new ones are blocked.

A plan never gates paid work. Any organization, Free included, can buy credits and run AI code audits, and every deliverable of a paid assessment, its report and its compliance mapping, is included on every plan. Attestation letters are not released yet; they follow the same rule when they arrive. The Pro compliance feature is the project posture: control coverage tracked across every assessment in a project over time. A single assessment's own mapping and export come with the assessment.

Subscribing

Open Billing in the dashboard. The Plan card at the top shows what you are on now; Upgrade opens a panel where you pick a level and a billing interval, then sends you to the payment provider's hosted checkout. When you come back, the page confirms the subscription. Payment confirmation arrives over a webhook, so your plan can take a few seconds to appear — refresh if the page says the payment is still processing.

You need the admin or owner role to change a plan or buy credits.

Changing or cancelling

Manage on the Plan card opens the payment provider's customer portal in a new tab. Changing your level, updating your card and cancelling all happen there, which keeps you billed once. A cancellation leaves you on Pro until the end of the period you already paid for, and credits already granted are never taken back.

Included allowances and extra usage

A Pro subscription includes a monthly volume of continuous AI work: PR reviews, monitor runs, and fix-verification reviews. Each run covered by that volume appears in your transaction list as a $0 included line, so you can see exactly what your subscription paid for. Your credit balance does not move.

Once a month's allowance is used up, further runs continue — they debit credits as extra usage and appear as ordinary spend lines. Nothing is silently unlimited and nothing is silently charged.

The allowance month is the calendar month in UTC, not your subscription anniversary. Every allowance resets at the start of the month.

If a run fails after it was counted, AISafe gives the unit back: an included run returns its unit to the month it was drawn from, and a charged run is refunded. A retried or duplicated event never counts twice.

Free organizations have no included allowances and are never blocked from paying for work: any organization can buy credits and run assessments.

Usage tracking

The Billing page in organization settings shows your current credit balance, recent transactions (purchases, assessment debits, refunds), and usage trends. You can set up low-balance alerts to receive notifications before credits run out.

Spend guardrails

Organizations can configure a monthly spend policy with alert thresholds and optional blocking enforcement. A policy can set an organization-wide cap, a per-project cap, a calendar-month or rolling-30-day window, and threshold percentages such as 80%.

When enforcement is set to warn, AISafe allows new spend but emits spend.threshold_crossed once per threshold and window. When enforcement is set to block, AISafe rejects new assessment starts and skips continuous capabilities before any debit if the projected spend would exceed the cap. Refunds reduce the current window spend.

The Spend posture view in organization settings shows current window spend, cap state, per-capability breakdown, and projected end-of-window burn.

Notifications

AISafe sends notifications for billing events, including spend thresholds and cap-reached states. You can route these to Slack, email, or other tools you already use.