Yearly running cost Assuming 2,400 findings a year
By hand $90K / year 1,200 hours of work
Subscription $11.8K+ / year
This workflow $288 / year Machine usage only; setup, hosting and review are extra. What should the workflow do with scanner findings? Fix issues in your code, or also handle vulnerable packages and issue tracking.
Check and fix code findings Explain each finding and propose tested fixes. $1,224 – 3,480 setup Add package upgrades and tickets Also upgrade packages and track unresolved issues. $1,872 – 5,400 setup
Which scanner reports your findings?GitHub code scanning Semgrep Snyk SonarQube Checkmarx Other Your engineers merge fixes and your security team closes findings. It never merges code, never closes a finding without a recorded verdict and never changes scanner rules.
What is included Import findings from your code scanner, check each against the surrounding code, record whether it is real, not reachable or a false alarm with the reason, and open a fix pull request with a test for real findings.
Start with the scanners you already run, the repositories in scope, your rules for what must be fixed and a set of past findings your security engineers have already judged. The wider option adds vulnerable package upgrades with a check of what the upgrade changes, issue tracker tickets and recorded reasons for findings that are set aside.
How reliable should verdicts and fixes be? Set targets for identifying real vulnerabilities and producing fixes your engineers can accept.
Standard Verdicts with evidence for each finding and tested fixes for real ones, with unclear cases handed to a security engineer. Verdicts correct: ≥85% Real findings fixed: ≥75% Included Strict A second check on each verdict and fix, and more tests on labelled and planted findings. Verdicts correct: ≥90% Real findings fixed: ≥85% Setup +$288 – 960 My own targets Agree your own acceptance requirements with the provider. Quote separately
How these standards are measured Test on held-out past findings your security engineers have labelled and on vulnerabilities planted in a copy of your code. A fix counts only when the rescan clears the finding and your tests pass. Calling a real planted vulnerability a false alarm counts as a critical failure.
Targets for your selected standard What is checked Target Verdicts correctFindings sorted the same way as your security engineer, as real, not reachable or a false alarm, divided by all findings in the test set. A real planted vulnerability called a false alarm is a critical failure. ≥85% Real findings fixedReal findings that get a fix which clears the scanner rescan and passes your tests, divided by all real findings in the test set. ≥75% Fixes mergedFix pull requests your engineers merge without rework, divided by all fix pull requests opened. ≥60% Verdicts with evidenceEvery verdict must cite the scanner rule, the code path and the reason. ≥100%
Verdicts and fixes are proposals for your engineers and security team; they are not a security sign-off. People still merge fixes and close findings.
How quickly should a fix or verdict appear? Choose how soon after a finding arrives the verdict and, for real findings, the fix pull request appear. Your engineers' review time is separate.
Within 15 minutes Included Within 10 minutes Setup +$144 – 480 Within 5 minutes Setup +$288 – 840
Timing details Time from a new finding to a recorded verdict or opened fix pull request, including reading the code, model calls, running your tests and the rescan, queueing and retries. Long test suites may need agreed limits. Confirm repository size and runner capacity with your provider.
The target applies to at least 95% of agreed test runs, with 4 in progress at a time.
How much do you want to spend per finding? Set the AI processing budget for checking and fixing each finding.
Up to $0.60 Included Up to $0.35 Setup +$72 – 360 Up to $0.20 Setup +$216 – 600
Cost details Includes model calls, retries and a shared hosting allocation. Scanner licences, CI minutes, your engineers' time and the calling agent are separate. A finding that needs a second fix attempt is counted again.
Reference machine cost: $0.22 – 0.42 per finding at 200 findings a month. The selected cap is a target to test, not a replacement for this estimate.
Where do you want it to run? Run it in your cloud or on your own server. Choose whether code may go to an approved AI service.
Run it onYour cloud Local environment AI model accessApproved model API Private model only
Data and access details Runs in a cloud account you control, with access controls and logs.
Only the finding, the related code and your fix rules go to the selected external model, with secret files excluded. Agree access and retention first.
Give it read access to code and permission to open pull requests and comment only. Exclude secret files from what the model reads. Private model only keeps source code on your hardware; the workflow still connects to your own code host and scanners.
How do you want to use it? Choose where you want to use it. You can select more than one.
Fix pull requests in my code host Each real finding gets a pull request with the fix, a test and the reasoning; other findings get a recorded verdict. Included My existing AI agent Let your coding agent ask whether a finding is real and request a fix while it works on the code. Setup +$72 – 240 A findings dashboard See verdicts across repositories, open fixes, merged fixes and findings waiting for a security engineer. Setup +$144 – 480