Every account starts free. Scan your live app and your code, and get a fix for every finding.
One person, one account. Priced per month.
£24/mo billed £202/yr
Save hours every week
£49/mo billed £412/yr
Ship fast, stay secure
£99/mo billed £832/yr
One developer, a large estate
Starter and Pro reports are licensed for internal use; Max adds white-label reports and the licence to deliver them to a client. Read the license terms
See where your app and code stand. Create account
Every scanner, every limit, every integration — side by side. No asterisks. Free is a column here, not a trial.
| Feature | Free$0Start free | Starter$24/moStart free | Pro$49/moStart free | Max$99/moStart free | Team Basic$25/seatStart free | Team Advanced$50/seatStart free | EnterpriseCustomTalk to us |
|---|---|---|---|---|---|---|---|
| Scanners | |||||||
| Assets you can scanFree scans your website and your code. Backend, clouds and domains open on any paid plan; containers are a Team asset. Locked pillars never run, so there is no count to wave at you either. | Website + Code | 5 of 6 | 5 of 6 | 5 of 6 | All 6 | All 6 | All 6 |
| 100+ security checksInjection, auth, exposed secrets, headers, storage rules, misconfigured hosting — run against your live site in a real browser. | Included | Included | Included | Included | Included | Included | Included |
| Performance & Core Web Vitals | Included | Included | Included | Included | Included | Included | Included |
| Accessibility (WCAG) | Included | Included | Included | Included | Included | Included | Included |
| Compliance & legal pages | Included | Included | Included | Included | Included | Included | Included |
| Domain, DNS & certificate checks | Included | Included | Included | Included | Included | Included | Included |
| Dependency scanning (SCA)Known-vulnerable packages in your manifests and lockfiles, with KEV-flagged exploits ranked first. | Included | Included | Included | Included | Included | Included | Included |
| Private package registriesAuthenticate to your internal npm, PyPI or Maven registry so dependency scanning resolves the packages your build actually installs, not only the public ones. Not shipped yet — dependency scanning resolves public registries today, and no credential of yours is stored or used. | Not included | Not included | Not included | Not included | Not included | IncludedSoon | IncludedSoon |
| License scanning (SBOM)Dependency licences resolved and reported under Compliance, so a copyleft package cannot reach production unnoticed. | Included | Included | Included | Included | Included | Included | Included |
| AI AutoFixA model writes the fix for a code or infrastructure finding in an isolated sandbox, the scanning rule that raised it re-checks the patch, and you review the diff before it opens as a pull request. Refine any patch with one instruction. Paid in AI credits — one per fix: Team Basic includes 10 a month per seat, Team Advanced 20, and more cost £1 each (less in bulk, up to 2,000 at a time). A fix the model could not produce is never charged. | Not included | Not included | Not included | Not included | Included | Included | Included |
| Source-code analysis (SAST)Requires a connected GitHub or GitLab repository. Code is one of the two assets free can scan, so a free account gets this too. | Included | Included | Included | Included | Included | Included | Included |
| AWS cloud postureConnect an AWS account by IAM role — we never hold a key of yours — and it gets checked for public buckets, over-broad policies and exposed credentials. Separate from the Supabase backend scan every paid plan already runs. | Not included | Not included | Not included | Not included | Included | Included | Included |
| Container scanningConnect a registry and every image layer gets read for known CVEs, leaked secrets and end-of-life base images — no Docker daemon, no agent in your cluster. A team capability since 2026-08: the person who builds the image and the person who runs it are rarely the same person, and the finding needs a queue with both of them in it. | Not included | Not included | Not included | Not included | Included | Included | Included |
| Live threat detectionReal attack traffic hitting your site — scrapers, credential stuffing, injection probes — captured and classified. | Not included | Not included | Included | Included | Included | Included | Included |
| Active security testsNon-destructive exploit attempts that confirm a finding is real before you spend time on it. | Not included | IncludedBeta | IncludedBeta | IncludedBeta | IncludedBeta | IncludedBeta | IncludedBeta |
| On-prem scan runnerA runner you host, so scans reach repositories and hosts that never leave your network. Not shipped yet — the plan reserves it, and nothing of ours runs on your infrastructure today. | Not included | Not included | Not included | Not included | Not included | IncludedSoon | IncludedSoon |
| Findings & fixes | |||||||
| Severity overview | Included | Included | Included | Included | Included | Included | Included |
| Full finding detail & evidenceThe request, the response and the exact location that proves the finding. Free shows half of each list, with the two loudest severities masked — the count and the severity are always visible. | Half | Included | Included | Included | Included | Included | Included |
| AI fix promptsEvery finding ships as a prompt written for the assistant you already use — paste it in your editor and ship the fix. | Not included | Included | Included | Included | Included | Included | Included |
| Fix verification re-check | Not included | Included | Included | Included | Included | Included | Included |
| Issue workflow statusMove a finding through To do, In progress, Solved or Ignored so a team can see what is actually being worked on. | Included | Included | Included | Included | Included | Included | Included |
| AutoFix pull requestsDeterministic security patches opened straight against your repository as a reviewable pull request. | Not included | Not included | Not included | Not included | Included | Included | Included |
| PR security reviewEvery pull request gets a GitHub check run, a review comment on each finding it introduces at or above your comment threshold (with a committable fix when one exists), and one summary comment that updates in place. Reply @checkvibe ignore to triage without leaving GitHub. | Not included | Not included | Not included | Not included | Included | Included | Included |
| CI merge gateA blocking check run on every pull request. You set the bar — which severity fails the build, whether only findings this pull request introduces count, and whether an admin can override on the record — account-wide or per project, and a PR that crosses it cannot merge. | Not included | Not included | Not included | Not included | Not included | Included | Included |
| Deep ReviewA second check run on every pull request, written by a model reading the diff with its surrounding code: authorization gaps, injection paths and logic errors the pattern scanners miss, each as a review comment you can reply to. One credit per pull request, a hundred a month included, and it never turns red unless you ask it to. | Not included | Not included | Not included | Not included | Not included | Included | Included |
| Custom rules & suppressionsWrite your own detection rules, mute a class of findings you have already accepted, and re-band a rule's severity for your codebase. Every suppression carries a reason, an approver and an expiry date. | Not included | Not included | Not included | Not included | Not included | Included | Included |
| Monitoring & alerts | |||||||
| Scheduled monitoring | Not included | Not included | Daily | Custom | Custom | Custom | Custom |
| Email alertsWhat a scheduled scan does when it finds something new: it emails you. No schedule, nothing to alert on — which is why this tracks monitoring rather than being sold on its own. Slack, Teams and signed webhooks are Team destinations and have their own rows under Integrations. | Not included | Not included | Included | Included | Included | Included | Included |
| Threat history retentionHow far back the attack traffic goes. Advanced holds a full year so a SOC 2 Type II observation window has the threats as well as the audit trail. | Not included | Not included | 7 days | 90 days | 90 days | 1 year | Custom |
| Runtime security | |||||||
| Protected AI tokens / monthThe one metered allowance, shared by the AI call log and AI spend. Past the allowance we keep counting every call and stop checking them for prompt injection, system-prompt leaks and personal data until the meter resets. Your own traffic is never touched either way — we are not in your request path. | Not included | Not included | Not included | Not included | 10M | 25M | Custom |
| Auth proberEvery night we log out and re-try the pages that should need a login, then flag any that stopped asking. | Not included | Not included | Not included | Not included | Included | Included | Included |
| CanariesWe plant decoy rows through the Supabase connection you already gave us and re-check them nightly. A touched decoy means someone read data they should not have. | Not included | Not included | Not included | Not included | Included | Included | Included |
| GuardThe optional package records which routes and server actions your app really exposes, so "needs a session" stops being a guess. It only watches — it never blocks a request. Needs the @checkvibe/guard package running in your app. | Not included | Not included | Not included | Not included | Included | Included | Included |
| AI call logThe optional package logs each AI call your app makes, with model and token counts. Your provider keys stay in your app — nothing is proxied through us. Needs the @checkvibe/guard package running in your app. | Not included | Not included | Not included | Not included | Included | Included | Included |
| AI spendThe optional package prices every AI call as it happens, so a runaway loop shows up as money on this page while it is still running. Needs the @checkvibe/guard package running in your app. | Not included | Not included | Not included | Not included | Included | Included | Included |
| Reports & exports | |||||||
| PDF report export | Not included | Included | Included | Included | Included | Included | Included |
| Markdown export | Not included | Included | Included | Included | Included | Included | Included |
| Shareable report link | Not included | Included | Included | Included | Included | Included | Included |
| SOC 2 & ISO 27001 evidence reportsA frozen, hash-stamped report for a stated period. Covers the technical controls a scanner can genuinely prove, and names the ones it cannot. | Not included | Not included | Not included | Not included | Not included | Included | Included |
| GRC evidence syncPush SOC 2 and ISO 27001 control evidence to an HTTPS endpoint you own, on a schedule you set. Every delivery is a versioned JSON bundle signed with a shared secret, so whatever reads it — your GRC platform, your SIEM, your ticket queue — gets the evidence from the scanner instead of from a screenshot someone took. | Not included | Not included | Not included | Not included | Not included | Included | Included |
| White-label reportsYour logo and domain on delivered reports, plus the licence to hand them to a client. | Not included | Not included | Not included | Included | Not included | Included | Included |
| Client portalA read-only portal per client, on your branding, showing that client their own findings and nothing else. Every surface that implements it — the Clients page, /api/account/clients and the public /p/<agency>/<client> page — gates on canUseClientWorkspaces, which reads the reseller columns the webhook writes rather than the plan table. That is Max (its price carries the reseller bundle) and the grandfathered agency accounts; neither Team tier has it. | Not included | Not included | Not included | Included | Not included | Not included | Not included |
| Integrations & API | |||||||
| MCP serverRun scans and read findings from Claude, Cursor or any MCP client without leaving your editor. | Not included | Included | Included | Included | Included | Included | Included |
| Public REST API | Not included | Included | Included | Included | Included | Included | Included |
| GitHub App | Included | Included | Included | Included | Included | Included | Included |
| GitLab connection | Included | Included | Included | Included | Included | Included | Included |
| Two-way Jira & Linear syncFindings open issues in your tracker, and closing one there marks it solved here. A regression reopens it. | Not included | Not included | Not included | Not included | Not included | Included | Included |
| Slack & Microsoft Teams alerts | Not included | Not included | Not included | Included | Included | Included | Included |
| Signed outbound webhooksFor PagerDuty, Opsgenie or anything else behind an HTTPS endpoint. | Not included | Not included | Not included | Included | Included | Included | Included |
| SSO (SAML)Your identity provider decides who gets in. Claim your email domain, hand us the IdP metadata, and everyone on that domain signs in through it — with enforcement on, passwords and social logins stop working for that domain. Offboarding is still a step you take here: there is no SCIM feed yet, so disabling someone at your IdP blocks their next sign-in but does not end an open session or release their seat. Remove them under Settings → Users and access stops immediately. | Not included | Not included | Not included | Not included | Not included | Included | Included |
| Team & access | |||||||
| SeatsWithout a Team plan an account is one person — the owner. Team plans are sold per seat in blocks of 5, from 5 up to 25, and are what open the account to anybody else. Past 25 seats the pricing goes custom. | 1 | 1 | 1 | 1 | 5+ | 5+ | Custom |
| Invite people to your accountA Team plan is what makes the account hold more than one person. Anyone invited before is unaffected — they keep working, and they stay removable. | Not included | Not included | Not included | Included | Included | Included | Included |
| Roles: admins, read-only viewersWithout a Team plan everyone you invite is a Member — they scan, triage and dismiss, and change none of the wiring. Team plans add admins (who run connectors and settings) and read-only viewers for an auditor or a manager. Taking a role back never needs the plan, so an account that lapses can still demote somebody. | Not included | Not included | Not included | Included | Included | Included | Included |
| Separate teams (workspaces)Several teams under one payer, each with its own domains and its own people, so the group that owns a product sees that product. Everyone else runs as a single workspace. Gated on canUseWorkspaces, which is hasTeamSubscription — so the grandfathered agency bundle keeps it. | Not included | Not included | Not included | Included | Included | Included | Included |
| Shared queue: assign, comment, trackOne queue for the whole account. Every seat can move work through it, and who moved what is recorded. Free gets it too — the queue is the product, not the upsell. What you buy are the exits off it: AutoFix pull requests, Slack, Jira and Linear, deadlines. | Included | Included | Included | Included | Included | Included | Included |
| Remediation deadlines (SLA)Days-to-fix per severity, with overdue tracking and an attainment figure you can show a customer. | Not included | Not included | Not included | Included | Included | Included | Included |
| Audit logAppend-only. Cannot be edited after the fact, including by us. Advanced keeps a year because that is the window a SOC 2 Type II observation period needs. | Not included | Not included | Not included | 180 days | 180 days | 1 year | Custom |
| Risk exceptions with approval & expiryAn accepted risk gets a reason of real length, a named approver and a review date. It expires on its own; nobody has to remember it. | Not included | Not included | Not included | Not included | Not included | Included | Included |
| DPA, SLA & invoice billing | Not included | Not included | Not included | Not included | Not included | Not included | Custom |
| Limits | |||||||
| Projects | 1 | 1 | 5 | 25 | 25 | 100 | Custom |
| Scans per monthFree is a real monthly allowance on one project, not a one-shot preview. Team allowances are pooled across every seat. | 4 | 10 | 250 | Unlimited | 1,000 pooled | 5,000 pooled | Custom |
| API keys | Not included | 1 | 5 | 25 | 10 | 25 | Custom |
| Pages crawled per scan | 1 | 50 | 75 | 150 | 150 | 500 | Custom |
| Crawl depth | 0 | 3 | 4 | 5 | 5 | 8 | Custom |
| Support | |||||||
| Support channel | Docs | Priority email | Priority email | Priority email | Dedicated | ||
| Onboarding & training | Not included | Not included | Not included | Not included | Not included | Not included | Custom |
Starter, Pro and Team Basic reports are licensed for internal use; Max and Team Advanced buy white-label reports and the licence to deliver them to a client. Read the licence terms. Existing subscribers keep the limits they bought — plan changes never reduce an active plan.
What the team tiers are for, written out in full.
CheckVibe starts at $0 and stays there: 1 project, Website + Code scanning, 4 scans a month, one person, and the shared queue if you bring a team. For one person, Starter is $24/month (1 project, 10 scans, AI fix prompts, PDF export, API access) and Pro is $49/month (5 projects, 250 scans, daily monitoring, live threat detection). For teams, Team Basic is $25 per seat per month and Team Advanced is $50 per seat per month, sold in blocks of 5 seats from 5 up to 25. Annual billing saves 30% on Starter and Pro, and about two months on Team plans.
No trial, because there is no clock. Free is a permanent tier: 1 project, Website + Code scanning, 4 scans a month, one person, and the full shared queue the moment a Team plan brings colleagues in — assign, comment and track together. You see half of each pillar's findings, and Critical and High detail stays masked until you upgrade.
The exits, not the queue. Paid plans unlock every finding in full instead of half, the backend audit (a connected Supabase project's tables, RLS policies and buckets, on top of the sites and repositories free already scans), AI fix prompts, PDF and Markdown export, and the API. Scheduled re-scans start on Pro — Starter scans on demand. Team Basic adds AI AutoFix — a model writes the fix for a code or infrastructure finding in an isolated sandbox, the scanning rule re-checks it, and it opens as a pull request you review. It runs on AI credits, one per fix: 10 a month per seat on Team Basic, 20 on Team Advanced, and more from £1 each, cheaper in bulk (no solo plan has it) — and the things a group of people needs: container scanning, cloud posture across AWS, Azure, Google Cloud and Kubernetes, PR security review, Slack and Microsoft Teams alerts, remediation deadlines, 180 days of audit log, and the 5 zero-install runtime protection features (Auth prober and Canaries and Guard and AI call log and AI spend) running against your live app, metered at 10M protected AI tokens a month. Team Advanced adds SSO (SAML), a CI merge gate, Deep Review, custom rules and suppressions, GRC evidence sync, white-label reports, plus two-way Jira and Linear sync and a full year of audit history.
SSO (SAML), a CI merge gate, Deep Review, custom rules and suppressions, GRC evidence sync, white-label reports, two-way Jira and Linear sync, SOC 2 and ISO 27001 evidence reports, risk exceptions with approval and expiry, 100 projects instead of 25, 5,000 pooled scans instead of 1,000, 1 year of audit history instead of 180 days, 1 year of threat history instead of 90 days, and priority support. Both tiers share the scanners, container scanning, the shared queue and the runtime protection suite — the full row-by-row split is in the comparison table above.
Yes. All paid plans are month-to-month or annual. Cancel anytime from your dashboard with no fees.
We accept all major credit cards, Apple Pay, and Google Pay through Stripe. Prices are available in USD, EUR, GBP, and CHF.
Still have questions? Contact us or book a 30-minute demo.