- Is my code kept private?
- Yes. The platform connects via a read-only GitHub connector (Personal Access Token, scoped to read; native GitHub App auth is on the roadmap). We fetch only the files needed for evidence collection, we never clone or re-distribute your source, and we do not train AI models on your code or findings. For sovereign-grade privacy where source must never touch a third-party LLM, see the Sovereign tier. That's where we partner with you to scope a self-hosted deployment and a configurable AI endpoint to match your environment.
- What does BYOK mean and why would I choose it?
- Bring Your Own Key. You connect your existing Anthropic or OpenAI API key in your workspace settings. The platform makes its agent calls directly against the provider using your key, the AI cost lands on your provider invoice, not ours. Choose this if you already have a provider relationship, want negotiated rates to flow through, or need zero-token-margin pricing. We never see or store your provider invoice; we cap per-assessment spend ($5 default) so a runaway run can't burn your budget.
- What does managed tokens mean?
- We pay the AI provider; you pay us a per-assessment fee scaled by repository size: $49 small / $99 medium / $249 large. No provider account, no key handling, no surprise invoices. We mark up modestly to cover provider risk and operations. Available on Partner tier as an alternative to BYOK; default on Fund.
- Can I run this on-premise / self-hosted?
- Sovereign is our self-hosted track, scoped per engagement. Today we ship a Docker Compose distribution you run inside your own VPC. A configurable AI endpoint (for local OpenAI-compatible models like Ollama, vLLM, or in-house deployments of Llama / Qwen / Mistral), Helm packaging, air-gap support, and FedRAMP / IL evidence alignment are roadmap items we deliver case-by-case. Talk to us about your specific environment. We won't oversell what we haven't shipped yet.
- What does an assessment cost in AI tokens?
- BYOK: roughly $0.30–$8.00 per assessment on your provider, depending on repo size and how many of the 30 agents fire. The platform caps spend per assessment ($5 default), so worst-case a runaway agent set won't burn more than the cap. Managed: $49–$249 flat per assessment by size band. See the size-banding table on this page.
- I'm a founder, not an investor. Is this for me?
- Yes. Same platform, different side of the table. Founders use the assessment to be pitch-ready before the partner meeting: surface what an acquirer or VC would flag, ship the quick wins from the remediation workbook, and walk in already knowing the score. Many of our paid users are CTOs and founding engineers doing quarterly self-DD on their own codebase. The Scout tier ($499/mo) fits a single founder; Partner scales to small engineering teams.
- Is this a replacement for a full DD?
- No, and we say so on the front page. The platform compresses the technical-readiness portion of diligence: rules, code-quality, security baseline, ops maturity. It does not replace customer references, financial DD, legal review, pen testing, or the judgement of an experienced operator. See the methodology page for the full scope.
- Can I run a framework I have designed myself?
- Custom frameworks are available on Fund and Sovereign tiers. You bring the controls and remediation guidance; we run them with the same agent pipeline.
- What does onboarding look like?
- Book a demo. We walk through the product on one of your own companies, share example reports, and can have you running your first assessment the same day. Sovereign deployments take 1–2 weeks from kickoff including network design and LLM selection.
- Can I cancel any time?
- Yes. Monthly subscriptions cancel at the end of the billing period. Annual subscriptions come with a 30-day cooling off and a 15% prepay discount. Sovereign deployments are annual with a one-time setup fee.
- Do you sign NDAs?
- Yes. Standard two-way NDA is available on request. Fund and Sovereign tiers include a full Data Processing Agreement.