Pricing
Per-audit pricing, from $50.
A $50 quick scan for a fast first look, or the $200 full audit — the complete pipeline with a working exploit on every critical. Re-runs on a new commit don't re-bill, and your team gets free audits to evaluate first. No subscriptions, no seats, no scoping calls.
A fast first look, or the whole pipeline.
Quick scan
Fast first lookA fast, focused first pass over the core risk checklist — the same earned-verdict validation, at a fraction of the cost. The cheapest way to triage a contract.
- Core checklist coverage
- Access control, external calls, DeFi and ERC-4626 token logic, integrations, centralization, and version issues.
- The same earned verdicts
- Findings run through the same validation — unproven ones stay as needs_manual, never a false-positive dump.
- Findings you can act on
- Severity, exact file:line, and the vulnerable code for each issue.
- Versioned, shareable report
- A report link pinned to the commit, plus PDF export.
Narrower by design — no deep adversarial passes and no fork-exploit proof. Step up to the full audit for those.
Full audit
RecommendedThe complete pipeline — deep adversarial analysis, architecture grounding, and a working exploit for every critical.
- Full report
- Every finding with severity, exact file:line, and the vulnerable code.
- Working exploit for criticals
- Each critical is reproduced on a mainnet fork — proof, not just a write-up.
- Architecture artifacts
- Extracted invariants, assumptions, and design decisions your code relies on.
- Earned verdicts
- A finding is dropped only when the validator can cite the line that defeats it — otherwise it stays in front of you as needs_manual.
- Re-audit on every commit
- Same flat price, diffed against your last scan. No new scoping call.
- Versioned, shareable report
- A report link pinned to the commit, plus PDF export.
One-time payment per audit · Charged in USD at checkout · No card on file
Risk classes covered (full audit)
Reentrancy · oracle and price manipulation · access control and privilege escalation · accounting and invariant drift · unchecked external calls and return values.
No trap. No meter. No surprises.
You commit weekly — so the real question is what the bill looks like on a repo you keep pushing to. Here's exactly how it works.
One charge
What counts as one audit
You're billed once when you start an audit on a commit, and codebase size doesn't change the price — one repo, one commit, one charge: $50 for a quick scan, $200 for a full audit.
Re-runs
Re-audits are the same flat price
−3 critical, −5 high vs previous scan
Push a fix, run again. Each re-audit is its own $200 audit, diffed against the last — no new scoping call, no subscription. Continuous security, billed per run.
Reliability
A failed run isn't a charge for nothing
If an audit fails to complete, you shouldn't pay for nothing. Reach out and we'll make it right — a re-run or a credit, not a charge for a report you never got.
Evaluate first
Teams get free audits to start
A team workspace ships with a configurable allowance of free audits, so the whole team can evaluate Guardix on real repositories before paying. Reach out to provision one.
The rest of what a security buyer asks.
Code privacy
Cloned to audit, not to train
- Not training data
- Your code is cloned only to run the audit. It is not used to train any model.
- Data handling
- Need specifics on retention and access for your organization? Reach out and we'll walk you through it.
Chains supported
EVM Solidity, exploit on a fork
Solidity source analysis on any EVM chain. Exploit proofs for critical findings run on a mainnet fork.
Products & stage
What you can buy today
- Code audit$50 quick scan · $200 full
- Live
- PR reviewRequest access
- Early access
- Release audit$200 per audit
- Beta
Frequently asked questions.
One repository at one commit, run through the full pipeline, is one $200 charge. The size of the codebase doesn't change the price — a 200-line library and a 20,000-line protocol both cost $200.
The quick scan is a fast, focused first pass for $50 — it runs the core risk checklist (access control, external calls, DeFi and ERC-4626, integrations, centralization, version issues) with the same earned-verdict validation. The full audit adds the deep adversarial analysis, architecture and invariant extraction, and a working fork exploit for every critical, for $200. Use the quick scan to triage; run the full audit before you ship.
Each re-audit is a fresh audit at the same flat $200, diffed against your last scan. There's no subscription and no discount tier — just the same price every run. To be clear: re-runs are priced the same, not free.
Prioritized findings with severity, file:line, and the vulnerable code; a working fork exploit for every critical; the extracted invariants, assumptions, and decisions your code depends on; and a versioned, shareable report link plus PDF export.
Earned verdicts. A finding is dropped only when the validator can cite the exact line of code that defeats the attack. If it can't prove the finding either way, it stays as needs_manual in front of you — nothing is silently hidden, and nothing is silently kept.
No. Run it first and on every fix to clear the issues a machine can prove. A manual audit still wins on novel, bespoke attack paths and economic or game-theoretic design — spend that budget where a human is irreplaceable.
Solidity on EVM chains — Ethereum, Arbitrum, Optimism, Base, Polygon, and other EVM networks for source analysis. Exploit proofs for critical findings run on a mainnet fork.
Your code is cloned only to run the audit, and it is not used to train any model. For specifics on data handling and retention for your organization, reach out and we'll walk you through it.
Most complete in 1–3 hours depending on codebase size and complexity, with live progress throughout the run.
Yes. A team workspace ships with a configurable allowance of free audits, so the whole team can evaluate Guardix on real repositories before paying. Reach out to provision one and set the allowance.
A one-time, per-audit charge in USD via Stripe at checkout. No subscription, no card kept on file, no hidden fees. If an audit fails to complete, reach out — we'll make it right rather than charge you for nothing.
Still weighing it against a manual engagement? Run Guardix first and on every fix, then spend the human budget on novel attack paths. Read the full comparison →
Run your first audit.
Connect a GitHub repository, pick a commit, and get a full validated report in hours — $200, flat. Teams get a free-audit allowance to evaluate.