Skip to main content
Pricing

Security automation priced per organisation, not per engineer.

OmniSentient reads your dependency manifests, explains what is actually exploitable, and opens the fix as a pull request. Every plan meters the same four things, and every limit on this page is one the product enforces.

Open Source

For individual maintainers and public repositories.

$0

Free while your repositories are public.

Install the GitHub App

Solo maintainers · public repos

  • Dependabot alert ingestion with delivery-level de-duplication
  • AI root-cause analysis on every finding
  • Fixes arrive as pull requests on their own branch
  • Tamper-evident forensic audit ledger
  • Slack and Discord notifications

Hard monthly caps. Nothing is charged on overage — metered operations pause until the next period.

Enterprise

For regulated environments and organisation-wide control.

Custom

Annual contract. Priced on repository count and required controls.

Request an architecture review

Regulated industries · 50+ engineers

  • Negotiated limits, provisioned per organisation
  • SSO via SAML and Okta, with SCIM provisioning
  • Bring your own model key (BYOK)
  • Custom policy enforcement engine
  • SOC 2 audit evidence packs
  • Multi-region data residency
  • Contractual SLA and a dedicated Slack channel

No shared tier ceiling. Limits are set per organisation as part of the contract.

The whole pipeline, on every plan

Dependabot alerts ingested with delivery-level de-duplication, AI root-cause analysis on each finding, the fix opened as a pull request, and Slack or Discord notification. None of it is gated behind an upgrade.

Never commits to a protected branch

Fixes arrive as pull requests on their own branch. Merging stays a human decision on every plan, including Enterprise.

Reads manifests, not your source

Analysis covers dependency manifests and advisory metadata. Your application source is not ingested, and nothing is used to train a model.

Every action is on the ledger

The tamper-evident audit trail is a baseline security property rather than a paid feature. Paid plans add signed export of it, not the record itself.

No seat pricing

Priced per organisation with unlimited seats. Adding engineers, reviewers or auditors never increases the bill.

Compare plans

The differences that decide a plan. Categories open as you need them.

Core platform 2 items
Feature Open Source Professional Enterprise
Repositories Public only Public and private
Custom branch prefix Not included Included
Monthly limits 5 items
Feature Open Source Professional Enterprise
AI analysis (tokens) 500K Negotiated
Remediation jobs 100 Negotiated
Webhook events 10K Negotiated
GitHub API calls 5K Negotiated
Per-organisation limit overrides Not included Included
Evidence and compliance 6 items
Feature Open Source Professional Enterprise
Signed forensic exports (Ed25519) Not included Included
SBOM export (CycloneDX) Not included Included
License allow / deny policy Not included Included
Custom policy enforcement engine Not included Included
SOC 2 audit evidence packs Not included Included
Multi-region data residency Not included Included
Team and access 4 items
Feature Open Source Professional Enterprise
Role-based access control Not included Included
Read-only auditor view Not included Included
SSO — SAML and Okta Not included Included
SCIM provisioning Not included Included
Integrations and support 3 items
Feature Open Source Professional Enterprise
Bring your own model key (BYOK) Not included Included
Support Community Dedicated Slack channel
Contractual SLA Not included Included

What actually gets metered

Four quantities, counted by the database rather than estimated. When one is exhausted, that operation pauses until the period resets — nothing is charged for overage and nothing is silently dropped.

AI analysis tokens / month

Root-cause analysis and fix generation. Refunded automatically when a model call fails, so a failed analysis costs you nothing.

500K
Negotiated
Remediation jobs jobs / month

One job per finding taken through the remediation pipeline. Retries of the same finding do not consume another job.

100
Negotiated
Webhook events events / month

Dependabot alerts and workflow results delivered by GitHub. Duplicate deliveries are de-duplicated before they count.

10K
Negotiated
GitHub API calls calls / month

Reading manifests, opening pull requests, and posting checks against your repositories.

5K
Negotiated

Professional limits can be raised for a single organisation without changing plan — useful when one metric runs ahead of the others.

Scoped against your environment, not a feature list.

An architecture review covers how OmniSentient reads your repositories, where evidence is stored, which controls you are required to demonstrate, and what the limits should be. It takes about forty minutes and produces a written scope.

  • Organisation-wide controls — SSO via SAML or Okta, SCIM provisioning, and policy applied across every repository rather than per project.
  • Evidence for auditors — SOC 2 packs and Ed25519-signed exports produced from the same ledger the platform writes to, not assembled afterwards.
  • Your keys and your region — bring your own model key, and pin data residency to the region your obligations require.
  • Negotiated limits — provisioned per organisation instead of inheriting a shared tier ceiling.

Request an architecture review

We reply within one business day. No automated sales sequence.

Pricing questions

What happens when I hit a monthly limit?

Metered operations stop until the period resets — nothing is charged for overage and no work is silently dropped. Findings stay queued, and the audit trail records that the pause was a quota decision rather than a failure. On Professional, an individual limit can be raised without changing plan.

How is AI usage counted?

Tokens are reserved before a model call and reconciled after it. A failed or empty analysis is refunded automatically, so you are only metered for analysis you actually received.

Can I change plans later?

Yes, in both directions and at any time. Upgrades take effect immediately with the new limits applied to the current period. Downgrades take effect at the end of the billing period, so you keep what you have already paid for.

Is there a free trial?

Professional includes a 14-day trial with no card required. If you do not continue, the organisation reverts to Open Source rather than being suspended.

Can I cancel anytime?

Yes. Cancellation stops the next renewal and the organisation drops to Open Source at the end of the paid period. There is no cancellation fee and no notice window.

What happens to my data if I cancel?

Findings, audit ledger entries and evidence exports remain readable for 30 days so you can export them, then the organisation's records are deleted. Pull requests we opened live in your repositories and are unaffected — they are yours.

Do you offer enterprise pricing?

Yes, on annual contracts priced by repository count and the controls you need — SSO, residency, custom policy, evidence packs. Request an architecture review and we will scope it against your environment.

Install the app, push once, read the pull request.

No card for Open Source or the Professional trial. The first analysis runs on your next push.