Skip to content

Fair use policy

Every paid module is sold per seat, or per organisation for the org-wide add-ons, and every one of them is subject to fair use. A module’s price buys normal working use for the seats on your subscription. It is not unlimited compute, and one seat cannot stand in for a fleet.

This page is the policy the pricing page and the landing page point to. The Acceptable Use Policy in the Terms of Service is the binding document; this page explains how it applies module by module.

  • The price covers the normal working use of the seats you have: the people on your team scanning the projects your organisation owns, at the cadence real development needs.
  • Usage is metered per seat. What is metered depends on the module: scan frequency, concurrent jobs, targets, hosted compute, API and MCP calls, and for AlertaVuln AI, tokens.
  • The limits behind the metering are operational. They are tuned to keep the service fast for everyone and can change without a price change, so this page describes behaviour rather than quoting hard numbers.
Module What is metered
DAST Scans run only against targets you own and have verified. Scan frequency and concurrent jobs are metered per seat.
Attack Scanning Authorised, verified targets only. Payload runs are metered per seat and rate-limited.
SAST (AV-hosted) Hosted scan runs and repository size are metered per seat. The CLI included in Base stays unlimited on your own runners.
Container scanning Image scans and monitored tags are metered per seat. Monitoring polls on a cadence, not continuously.
Reachability Analysis runs are metered per seat and queued behind your scans.
Automation & API API and MCP calls are rate-limited per key. Bulk exports are metered.
AlertaVuln AI Hosted AI is metered in tokens per seat, with a monthly allowance set by your AI tier. See AlertaVuln AI.
Compliance and Governance One organisation per subscription. Assessments, reports, exec views and suppression apply to your own projects.

Self-hosted delivery runs on your own runners and compute, so the metering there is about what the platform ingests and stores rather than compute we provide.

  • Sustained use well beyond the allowance is throttled. It is never silently billed: you will not find a surprise line on an invoice.
  • Throttling is visible, not disguised as a failure. A request that is over the allowance reports that state distinctly, so you can tell “we are over the allowance” from “something broke”. AlertaVuln AI, for example, reports a throttled state rather than a model error.
  • If you keep reaching the allowance, the fix is more seats or a higher tier, and we will say so rather than quietly degrading the service.

Fair use is about volume. The following are not volume questions; they are breaches of the Acceptable Use Policy and can end the subscription:

  • Scanning, monitoring or attacking targets you do not own or are not explicitly authorised to test.
  • Working around a limit, rate limit, tier restriction, licence check or feature flag.
  • Sharing one seat across many people, agents or integrations to avoid paying per seat.
  • Automated abuse of the alerting, integration or AI channels.

If you use your own AI assistant with AlertaVuln rather than the hosted AlertaVuln AI module, none of the AI metering applies. You are paying your own provider, and we are not in the loop to meter anything.