Pricing

Per-audit pricing, from $50.

A $50 quick scan for a fast first look, or the $200 full audit — the complete pipeline with a working exploit on every critical. Re-runs on a new commit don't re-bill, and your team gets free audits to evaluate first. No subscriptions, no seats, no scoping calls.

01Pick your depth

A fast first look, or the whole pipeline.

Quick scan

Fast first look
$50per scan

A fast, focused first pass over the core risk checklist — the same earned-verdict validation, at a fraction of the cost. The cheapest way to triage a contract.

Core checklist coverage
Access control, external calls, DeFi and ERC-4626 token logic, integrations, centralization, and version issues.
The same earned verdicts
Findings run through the same validation — unproven ones stay as needs_manual, never a false-positive dump.
Findings you can act on
Severity, exact file:line, and the vulnerable code for each issue.
Versioned, shareable report
A report link pinned to the commit, plus PDF export.

Narrower by design — no deep adversarial passes and no fork-exploit proof. Step up to the full audit for those.

Full audit

Recommended
$200per audit · one repo, one commit

The complete pipeline — deep adversarial analysis, architecture grounding, and a working exploit for every critical.

Full report
Every finding with severity, exact file:line, and the vulnerable code.
Working exploit for criticals
Each critical is reproduced on a mainnet fork — proof, not just a write-up.
Architecture artifacts
Extracted invariants, assumptions, and design decisions your code relies on.
Earned verdicts
A finding is dropped only when the validator can cite the line that defeats it — otherwise it stays in front of you as needs_manual.
Re-audit on every commit
Same flat price, diffed against your last scan. No new scoping call.
Versioned, shareable report
A report link pinned to the commit, plus PDF export.
Start an audit

One-time payment per audit · Charged in USD at checkout · No card on file

Reentrancy · oracle and price manipulation · access control and privilege escalation · accounting and invariant drift · unchecked external calls and return values.

02How billing works

No trap. No meter. No surprises.

You commit weekly — so the real question is what the bill looks like on a repo you keep pushing to. Here's exactly how it works.

What counts as one audit

vault-core@e7b2f4a$200

You're billed once when you start an audit on a commit, and codebase size doesn't change the price — one repo, one commit, one charge: $50 for a quick scan, $200 for a full audit.

Re-audits are the same flat price

e7b2f4atoday$200
c91d3e82 days ago$200
a3f8c1d5 days ago$200

−3 critical, −5 high vs previous scan

Push a fix, run again. Each re-audit is its own $200 audit, diffed against the last — no new scoping call, no subscription. Continuous security, billed per run.

A failed run isn't a charge for nothing

audit failed to completewe make it right

If an audit fails to complete, you shouldn't pay for nothing. Reach out and we'll make it right — a re-run or a credit, not a charge for a report you never got.

Teams get free audits to start

team workspace2 free audits

A team workspace ships with a configurable allowance of free audits, so the whole team can evaluate Guardix on real repositories before paying. Reach out to provision one.

03Trust & operations

The rest of what a security buyer asks.

Cloned to audit, not to train

Not training data
Your code is cloned only to run the audit. It is not used to train any model.
Data handling
Need specifics on retention and access for your organization? Reach out and we'll walk you through it.

EVM Solidity, exploit on a fork

Ethereum
Arbitrum
Optimism
Base
Polygon

Solidity source analysis on any EVM chain. Exploit proofs for critical findings run on a mainnet fork.

What you can buy today

Code audit$50 quick scan · $200 full
Live
PR reviewRequest access
Early access
Release audit$200 per audit
Beta
04FAQ

Frequently asked questions.

One repository at one commit, run through the full pipeline, is one $200 charge. The size of the codebase doesn't change the price — a 200-line library and a 20,000-line protocol both cost $200.

The quick scan is a fast, focused first pass for $50 — it runs the core risk checklist (access control, external calls, DeFi and ERC-4626, integrations, centralization, version issues) with the same earned-verdict validation. The full audit adds the deep adversarial analysis, architecture and invariant extraction, and a working fork exploit for every critical, for $200. Use the quick scan to triage; run the full audit before you ship.

Each re-audit is a fresh audit at the same flat $200, diffed against your last scan. There's no subscription and no discount tier — just the same price every run. To be clear: re-runs are priced the same, not free.

Prioritized findings with severity, file:line, and the vulnerable code; a working fork exploit for every critical; the extracted invariants, assumptions, and decisions your code depends on; and a versioned, shareable report link plus PDF export.

Earned verdicts. A finding is dropped only when the validator can cite the exact line of code that defeats the attack. If it can't prove the finding either way, it stays as needs_manual in front of you — nothing is silently hidden, and nothing is silently kept.

No. Run it first and on every fix to clear the issues a machine can prove. A manual audit still wins on novel, bespoke attack paths and economic or game-theoretic design — spend that budget where a human is irreplaceable.

Solidity on EVM chains — Ethereum, Arbitrum, Optimism, Base, Polygon, and other EVM networks for source analysis. Exploit proofs for critical findings run on a mainnet fork.

Your code is cloned only to run the audit, and it is not used to train any model. For specifics on data handling and retention for your organization, reach out and we'll walk you through it.

Most complete in 1–3 hours depending on codebase size and complexity, with live progress throughout the run.

Yes. A team workspace ships with a configurable allowance of free audits, so the whole team can evaluate Guardix on real repositories before paying. Reach out to provision one and set the allowance.

A one-time, per-audit charge in USD via Stripe at checkout. No subscription, no card kept on file, no hidden fees. If an audit fails to complete, reach out — we'll make it right rather than charge you for nothing.

Still weighing it against a manual engagement? Run Guardix first and on every fix, then spend the human budget on novel attack paths. Read the full comparison →

Run your first audit.

Connect a GitHub repository, pick a commit, and get a full validated report in hours — $200, flat. Teams get a free-audit allowance to evaluate.