FAQ
What kinds of repositories can I audit?
Select an authorized repository from GitHub, GitLab, or Bitbucket — up to five from one provider, on every plan. Connected public repositories are allowed too. Alternatively, supply one public https://github.com/{owner}/{repo} URL or an uploaded tar.gz archive. The agents support Python, JavaScript/TypeScript, Go, Rust, Java, Kotlin, C++, C#, Ruby, PHP, and more.
How big a repository can I audit?
Up to five connected repositories, 300 MB compressed and 300 MB extracted source, 100,000 files, and 1,000,000 lines of code in one audit. Byte, file, and line limits apply to the combined source. Beyond that, reduce the selected scope or talk to us about larger limits.
How long does an audit take?
It depends on the size and complexity of the codebase. Larger repositories with more files and deeper call graphs take longer. The audit runs in the background and streams progress, and you can leave the page and come back.
Can a stopped audit keep its accepted work?
Yes, if its saved state allows recovery. The work that each stage has saved stays in place, and support can resume the audit from where it stopped. If the organizing step cannot place part of the code, it retries that part once and then records it as unplaced, so the audit can continue instead of stopping.
Does AISafe keep access to my repository after the audit?
No. For connected repositories, AISafe mints a short-lived, repository-scoped token to clone the code and discards it when the audit completes. The agents retain no access after the audit finishes.
What is the false-positive rate?
AISafe keeps it low with a triage pass. A separate triage agent re-examines each finding's evidence, confirms or rejects it, deduplicates findings sharing a root cause, and assigns a confidence score. Low-confidence findings are flagged for your review. Your team still makes the final decision on each finding's status. See Triage.
Can I see the exact code that is vulnerable?
Yes. Each finding includes the vulnerable locations (file, function, line range), the taint flow from source to sink, and a proof-of-concept description. See Findings.
What happens with my dependency manifests?
AISafe reads manifests and lockfiles locally and keeps dependency, declared licence, and SBOM facts in the scan artifact. The pricing scan runs offline and does not query OSV or package registries. AISafe claims an advisory only when the audit has separate evidence for it, and if something is absent from the local inventory, AISafe is not claiming that it is safe.
How do I know a class of vulnerability was actually checked?
Read the coverage record. The audit works through a methodology checklist and gives every check on it an answer: tested in this audit, already answered by other work in the run, not applicable to your application (with the reason), or out of reach because the check needs a running system. An empty findings section is different from a vulnerability class that was never examined, and the record tells you which of the two you are looking at. See Coverage.
What do the GDPR, HIPAA, and PCI DSS options do?
Ticking one adds that regime's checks to the methodology checklist, together with the recognition ability those checks need, such as spotting personal data in your code. The checks and the recognition ability are always added together, and you cannot select them separately. The checks cover the technical articles that a code audit can address. They leave out obligations that are met by documents rather than by code, such as staff training, processor contracts, and breach-notification timelines. An audit with a regime ticked is not an assessment of compliance, and AISafe is not an assessor. See Coverage.
Can I focus the audit on a specific concern?
Yes. Provide additional instructions when you start the audit to steer the agents, for example toward payment code or a specific compliance requirement. See Steer the audit.
What formats can I get beyond the report?
You can download findings in machine-readable formats (SARIF, OpenVEX, JSON, CSV) and export a CycloneDX or SPDX SBOM. See Concepts: Finding and SBOM export.
How much does an audit cost?
AISafe calculates a code audit's price from exact LOC and token units, after offline analysis and snapshot validation. Fixed-price assessment types use their catalogue price. AISafe shows the final cost before Start and refunds credits if an assessment fails due to a platform error. See Credits & billing.