Simple, transparent pricing

Pay for what keeps you safe

Start free with a public URL check. Connect your source code when you are ready for deeper coverage.

Beta

Free

$0forever

Start with a public URL check. No account required.

Check your app
  • 1 public URL check
  • External surface scan (URL only)
  • Plain-English finding summaries
  • Source code connection
  • Ongoing monitoring
  • AI fix suggestions
  • Deep-Dive reports

Deep-Dive

One-timeper scan

AI-powered adversarial review of a specific scan result.

Start with GitHub
  • Everything in Protection
  • Dual-model adversarial challenge
  • Immutable finding provenance
  • Monotonic fail-closed verdict
  • Fix order and priority map
  • Privacy-safe artifact delivery

What each tier includes

FeatureFreeProtectionDeep-Dive
Public URL checks1UnlimitedUnlimited
External surface scan
Source code connection
Three-engine scan (Gitleaks · Semgrep · OSV)
Ongoing branch monitoring
Suggested Patch (AI fix proposals)
Draft PR delivery
Private security reports
Dual-model adversarial challenge
Immutable finding provenance

Frequently asked

Do I need a GitHub account?

For the Free tier, no. For Protection and Deep-Dive, yes — VibeBear connects to GitHub to read your source code and create Draft PRs. You choose exactly which repositories.

What does the URL check cover?

The free public URL check scans what is visible from the outside: HTTP headers, response bodies, robots directives, and common exposure patterns. It is not a source-code audit.

Can I cancel Protection at any time?

Yes. Cancel from your account settings and Protection continues until the end of the billing period. No refunds for partial periods.

What is a Deep-Dive report?

An adversarial AI review of a specific scan result — two models independently challenge the findings, building an immutable evidence chain. One Deep-Dive credit is included per scan.

Is my source code safe?

VibeBear reads source code in memory during a scan and discards it immediately. Secrets are never stored. GitHub access is read-only and scoped to repositories you choose.