Focused review
A pull request or changed-file assessment scoped to the code that moved.
Try ZeroQuarry for 30 days, cover a private product from $40 per month on annual billing, and invite the people who need the outcome. ZeroQuarry costs like a developer tool while doing the continuous testing, validation, remediation, and evidence work a coding assistant does not.
A pull request or changed-file assessment scoped to the code that moved.
A complete source, release artifact, binary, or authorized live target review.
Review stages, decisions, reports, evidence sharing, and in-assessment reruns.
For maintainers validating incoming security reports against one qualifying public project.
For a founder or security-minded engineer adding independent review to one private product.
For a team establishing repeatable testing, remediation, and evidence around one product.
For teams running recurring review, inbound report triage, and remediation across several products.
For security teams standardizing decisions, automation, and assurance across a product portfolio.
Custom products, runs, controls, storage, procurement, and rollout terms are available when the standard plans no longer fit.
Review source, release artifacts, binaries, and authorized live behavior across the product boundary.
Separate discovery from skeptical review, proof, confidence, and explicit human risk decisions.
Generate controlled patches, route ownership, preserve approvals, and verify the actual fix.
Turn the same operating history into reports and controlled evidence for customers, auditors, and leadership.
| Capability | OSS | Developer | Coverage | Operations | Portfolio | Enterprise |
|---|---|---|---|---|---|---|
| Capacity | ||||||
| Protected products | 1 public | 1 | 1 | 5 | 15 | Custom |
| Security runs / month | 5 | 10 | 50 | 200 | 600 | Custom |
| Concurrent assessments | 1 | 1 | 3 | 8 | 20 | Custom |
| Collaborators | 1 | 3 | 15 | 50 | 150 | Custom |
| Assessment coverage | ||||||
| Public and private source review | Public only | Included | Included | Included | Included | Included |
| Scheduled and pull-request review | Not included | Included | Included | Included | Included | Included |
| Release artifact and binary review | Not included | Not included | Included | Included | Included | Included |
| Authorized live-application testing | Not included | Not included | Included | Included | Included | Included |
| Adversarial validation | Included | Included | Included | Included | Included | Included |
| Vulnerability PoCs | Not included | Included | Included | Included | Included | Included |
| Security operations | ||||||
| Finding retests | Included | Included | Included | Included | Included | Included |
| Patch proposals | Not included | Included | Included | Included | Included | Included |
| Jira issue creation | Not included | Not included | Included | Included | Included | Included |
| ServiceNow issue creation | Not included | Not included | Not included | Included | Included | Included |
| Inbound researcher-report email triage | Not included | Not included | Not included | Included | Included | Included |
| GitHub autofix with human approval | Not included | Not included | Not included | Included | Included | Included |
| Evidence and rollout | ||||||
| Controlled evidence shares | 3 | 5 | 25 | 100 | 500 | Custom |
| Maximum share expiry | 30 days | 30 days | 60 days | 180 days | 365 days | Custom |
| Report watermark | Required | Not required | Not required | Not required | Not required | Custom |
| Custom report branding | Not included | Not included | Not included | Included | Included | Included |
| Workspace appearance controls | Not included | Not included | Not included | Not included | Included | Included |
| Rollout and procurement support | Self-serve | Self-serve | Standard | Guided | Priority | Custom |
One additional protected product on annual billing; $100 when billed monthly.
Twenty-five additional security runs on annual billing; $50 when billed monthly.
Scope, onboarding, first baseline assessment, and a working session around the resulting operating plan.
One customer-facing product or service with a coherent codebase, release boundary, and evidence history. A monorepo can still be one product; unrelated products with separate owners and risk decisions count separately.
A focused pull-request or changed-file review consumes 1 security run. A full source, binary, or authorized live assessment consumes 5. Reports, lifecycle decisions, evidence sharing, and rerunning a pipeline stage inside the same assessment do not consume more. Any newly started scan is metered by its scope.
No. Each listed price covers the whole account and includes multiple collaborators. Developer includes 3 people and Coverage includes 15, so inviting engineering, product, or leadership does not multiply the subscription bill.
A coding agent helps one developer produce code. ZeroQuarry independently tests the product, challenges vulnerability claims, retains risk decisions, moves remediation, verifies fixes, and produces evidence for customers and auditors. The entry price stays in developer-tool territory; the product outcome is a continuous security operation.
No. Model input and output are metered separately at the posted rates below, so you can match model depth to the decision and see the cost by scan. Keeping it visible also lets ZeroQuarry price the platform aggressively without hiding a usage assumption in every subscription.
Yes. Add protected products or bundles of 25 monthly security runs. If that becomes a recurring pattern, moving to the next plan will usually provide better economics and more operating controls.
ZeroQuarry creates continuous assessment and evidence between point-in-time tests. Some regulations, customers, or insurance policies may still require a named independent human assessor; we will scope those requirements honestly rather than treating every report as interchangeable.
Try one private product for 30 days without a card. Choose a paid plan only after the workflow has earned a place in your security operation.