Skip to main content

Pricing

Per project

Standard plans are $29/mo or $299/yr per shipped product, with no per-user fees or minimum. Eligible public GitHub projects can publish an attestation page for $0.

SourceTrust · Pricing

Per project

$25/mo per product$29/moSave $49/yr

$299 billed yearly, 14% less than paying monthly ($348).

Start for free
  • Unlimited users across your organization
  • Branded attestation page with review gates
  • Repo auto-sync & publish-drift checks

Public

Open source

$0

Connect a public repository through the SourceTrust GitHub App and publish its attestation page without a card or a trial clock.

Start with a public repo
  • Public GitHub repository connected through the GitHub App
  • The attestation page is free to publish
  • Fair use applies.

The page links to the repository and carries SourceTrust attribution

Try before you pay

Create, import, and review for free

Review for free

Create projects, import dependencies, and review licenses for as long as you need.

Pay when you publish

A standard project starts billing on its first publish or export download.

Reuse your capacity

Archive a project to free the slot. Published snapshots stay live.

The billing unit

What counts as a project?

One project is one shipped product, with its own inventory, license page and exports. Its frontend, backend, API and workers can span multiple repositories in the same record.

  • SPA, backend, and API from the same codebase
  • Mobile app in the App Store or Play Store
  • CLI, SDK, or embedded firmware bundle

What's included

Everything in each project

01

Ingest

  • Import from repo auto-sync or SBOMs and lockfiles (CycloneDX SBOM, npm (package-lock.json), pnpm (pnpm-lock.yaml), Yarn (yarn.lock), Bun (bun.lock), and more)
  • Two watched branches per project (Published + Testing)
  • Flag missing license text and obligation gaps before publish

Optional add-ons

On top of any project. Same monthly or yearly choice as your plan.

  • Extra watched branch

    Beyond Published + Testing, per project

    $5/mo

    $50/yr

  • Custom domain

    One hostname for every attestation page in your org. Non-refundable once provisioned.

    $49/mo

    $499/yr

  • Security monitoring

    Daily OSV advisory scans, vendor-only, org-wide

    $200/mo

    $2000/yr

You control what's exposed
  • Password-protect any page; invisible bot protection keeps scrapers out
  • Keep attestation pages out of search engines with per-page indexing controls
  • Security findings stay vendor-only. They never appear on your public page
How attestation pages stay yours

FAQ

Questions

Can we start with one product?

Yes. There is no minimum. Start with the product under the most scrutiny, then add lines as your portfolio grows.

Do you charge per user?

No. SourceTrust includes unlimited users in your organization.

Can we use our own domain?

Yes. The add-on is $49/mo or $499/yr per organization, one fee for every compliance page in the org. Non-refundable once provisioned. See our refund policy for details.

Is this the same as publishing a vulnerability SBOM?

No. A compliance page shows license posture, confirmed licenses, full license text, and attribution duties procurement reviewers check. A raw SBOM lists component versions and is often treated as sensitive security data. SourceTrust publishes what buyers ask for in license diligence, not an attack-surface map.

When am I charged?

Creating projects, importing dependencies, and reviewing licenses is free. A standard project counts toward your subscription on first publish or first export download. Eligible public GitHub projects can publish their attestation page for $0. Archive a paid project to free the slot.

What are watched branches?

Each connected project watches two branches by default, on GitHub, GitLab, or Azure DevOps: Published (feeds the buyer attestation page) and Testing (internal review). Extra slots beyond the two included are available as a per-project add-on.

Do you scan our projects for public vulnerabilities?

Only if you add security monitoring ($200/mo or $2000/yr per organization). It scans your dependencies for known advisories and alerts your team privately. Findings are vendor-only and never appear on the public attestation page.

Can we switch between monthly and yearly?

Yes. Change billing period from your account settings.

Do you offer invoicing or annual contracts?

Yes, for multiple products or procurement requirements. Email hello@sourcetrust.dev.

Which public GitHub projects can publish for free?

Connect a public GitHub repository through the SourceTrust GitHub App. You can publish its attestation page for $0, with no card or trial clock. Fair use applies. The page links back to the repository and carries SourceTrust attribution.

Estimate your exact total

Answer a few questions about what you ship; we'll estimate paid project capacity and add-ons, monthly or yearly. Eligible public GitHub projects are handled separately.

Find your price

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.