PRICING · NO SUBSCRIPTION · NO SEATS · NO RENEWAL

One audit.
One price. Refunds with teeth.

Independent AI engines audit your repository blind. A separate judge, which never audits, reconciles them into one report. Your score is arithmetic over the findings, not anyone's opinion of them. You pay once, per audit. Every finding cites file + code, and false findings are refundable.

ENGINES RUN BLIND · NO CROSS-CONTAMINATIONJUDGE NEVER SCANS · NO CONFLICT OF INTERESTCODE DELETED WITHIN 24H
BASIC
A second opinion before you ship.
$99
PER AUDIT · ONE-TIME
  • 2 independent engines + judge
  • Cross-vendor consensus score
  • Full findings report, file + code cited
  • Shareable report link
  • Repos up to 50k LOC · MVP and vibe-app scale
START BASIC →
DEEP
Maximum reasoning depth. For the code that pays your rent.
$499
PER AUDIT · ONE-TIME
  • 3 engines at full reasoning depth
  • Extended analysis budget per engine
  • Verdict names what blocks production, and what fixing it costs
  • Full findings report, file + code cited
  • Up to 100k LOC · larger repos by arrangement
START DEEP →
EVERY TIER: 14-day money-back guarantee False-finding refund Never billed on a failed run Code deleted within 24 hours We never train on your code

The guarantees, in plain terms

02 · SKIN IN THE GAME
GUARANTEE Nº1

14-Day Money-Back Guarantee

Not satisfied with your audit, for any reason? Tell us within 14 days and we refund the full price. Your request is the decision. No adjudication, no questions.

Request within 14 days of report delivery
One money-back refund per customer
Full refund to your original payment method within 10 business days
FULL POLICY →
GUARANTEE Nº2

The False-Finding Refund

Every finding cites the file and quotes the exact code it came from. If any finding in your report is demonstrably false against the audited commit, the audit is free.

Claim within 30 days with the finding ID + your evidence
Keep the audited commit available so we can verify
Decided in good faith within 10 business days; full fee refunded if confirmed
FULL POLICY →

What we don't guarantee yet.

We don't currently warranty against missed findings, because a promise like that has to be earned with measured precision across thousands of audits, not marketed on day one. We publish the meter. When it crosses the line, the missed-finding warranty ships.

HONESTY IS THE PRODUCT. THE LADDER IS PUBLIC.
FOLLOW THE LADDER →

What you're buying, and what you aren't

03 · SCOPE, PLAINLY

NOT THIS

One model's opinion

We could have shipped a single engine, unreviewed, with nothing behind it when it's wrong. Quicker to build, cheaper to sell. We couldn't have refunded it.

NOT WHAT WE BUILT

VALIDASH

Consensus audit, guaranteed

Multiple frontier engines, run blind, reconciled by a judge with no stake in the findings, then scored by arithmetic you can check yourself. Refund-backed accuracy.

$99 TO $499 · ONE-TIME

NOR THIS

A consulting engagement

We are not senior engineers reading your repository by hand. Validash is automated and point-in-time: you buy a run, not a retainer, and the report names the commit it was run against.

NOT WHAT WE ARE

What a Validash audit is

04 · THE MECHANISM

STEP 01

Engines run blind

Independent frontier models each audit your repo in isolation. None sees another's work.

STEP 02

The judge never scans

A separate model, barred from auditing, weighs the engine reports and reconciles them into one findings list. It does not choose your number: the score is arithmetic over the findings, published in full on your report. No grading of its own homework.

STEP 03

Findings cite receipts

Every finding pins the file it refers to and quotes the code it flags, and your Report names the audited commit it was run against. Claims you can check are claims we can stand behind.

STEP 04

Then the code is gone

Extracted payloads auto-delete within 24 hours. What stays is your report, including the fragments each finding quotes as evidence. We never train on your code, and every provider we send it to is on API terms that bar training on inputs.

Fair questions

05 · FAQ
Will you find every vulnerability in my code?+
No. No analysis, human or machine, catches everything, and a clean report is not proof your code is secure. We would rather print that on our own pricing page than put it in a refund email. What we promise instead: independent engines that can't share blind spots by copying each other, a judge with no stake in the verdict, findings precise enough to be checkable, and refunds when we're provably wrong. See the Audit Methodology for exactly what each tier examines.
Why multiple engines instead of one great one?+
Because any single model can be confidently wrong in ways it can't see, ours included. Different models fail differently. When they independently converge on a finding, that's signal; when they diverge, our judge treats it as doubt, not filler. Independence is the product.
What happens to my code?+
It's processed to produce your report, then extracted payloads are automatically deleted within 24 hours. We never use your code to train a model, and the providers we send it to are on business or API terms under which inputs are not used for training. Details in the Privacy Policy.
Is this a penetration test or a certification?+
No. It's an automated, point-in-time, AI-assisted code analysis: a scored second opinion with receipts, not a pentest, compliance attestation, or professional certification. It's built to be shared (investors, acquirers, clients), but third parties reading your report rely on it at their own judgment.
What if the audit fails midway?+
Then you aren't charged. Your audit token isn't consumed unless every engine and the judge complete. That's not one of the guarantees; that's just how billing should work.