PRICING · NO SUBSCRIPTION · NO SEATS · NO RENEWAL

One audit.
One price. Refunds with teeth.

Independent AI engines audit your repository blind. A separate judge, which never audits, scores the consensus. You pay once, per audit. Every finding cites file + line, and false findings are refundable.

ENGINES RUN BLIND · NO CROSS-CONTAMINATIONJUDGE NEVER SCANS · NO CONFLICT OF INTERESTCODE DELETED WITHIN 24H
BASIC
A second opinion before you ship.
$99
PER AUDIT · ONE-TIME
  • 2 independent engines + judge
  • Cross-vendor consensus score
  • Full findings report, file + line cited
  • Shareable report link
  • Repos up to 50k LOC · MVP and vibe-app scale
START BASIC →
DEEP
Maximum reasoning depth. For the code that pays your rent.
$499
PER AUDIT · ONE-TIME
  • 3 engines at full reasoning depth
  • Extended analysis budget per engine
  • Judge synthesis with severity ranking
  • Full findings report, file + line cited
  • Priority processing
  • Up to 100k LOC · larger repos by arrangement
START DEEP →
EVERY TIER: 14-day money-back guarantee False-finding refund Never billed on a failed run Code deleted within 24 hours Your code trains no one's model

The guarantees, in plain terms

02 · SKIN IN THE GAME
GUARANTEE Nº1

14-Day Money-Back Guarantee

Not satisfied with your audit, for any reason? Tell us within 14 days and we refund the full price. Your request is the decision. No adjudication, no questions.

Request within 14 days of report delivery
One money-back refund per customer; promo credits refund as credits
Full refund to your original payment method within 10 business days
FULL POLICY →
GUARANTEE Nº2

The False-Finding Refund

Every finding cites the exact file and line. If any finding in your report is demonstrably false against the audited commit, the audit is free.

Claim within 30 days with the finding ID + your evidence
Keep the audited commit available so we can verify
Decided in good faith within 10 business days; full fee refunded if confirmed
FULL POLICY →

We looked for another automated code-audit product that refunds its own false positives. We could not find one.

What we don't guarantee yet.

We don't currently warranty against missed findings, because a promise like that has to be earned with measured precision across thousands of audits, not marketed on day one. We publish the meter. When it crosses the line, the missed-finding warranty ships.

HONESTY IS THE PRODUCT. THE LADDER IS PUBLIC.
FOLLOW THE LADDER →

Where this sits

03 · THE HONEST COMPARISON

BELOW US

Automated scanners

Single-model checkers and vibe scanners. Fast, cheap, noisy: one model's opinion, with no accountability for what it gets wrong.

$5 TO $29

VALIDASH

Consensus audit, guaranteed

Multiple frontier engines from competing vendors, run blind, scored by a judge with no stake in the findings. Refund-backed accuracy. Report in under an hour.

$99 TO $499 · ONE-TIME

ABOVE US

Human audit firms

Senior engineers reading your code. Deep, contextual, slow: weeks of calendar time and quotes that start north of a grand.

$1,500 TO $15,000+

What a Validash audit is

04 · THE MECHANISM

STEP 01

Engines run blind

Independent frontier models from competing vendors each audit your repo in isolation. None sees another's work.

STEP 02

The judge never scans

A separate model, barred from auditing, weighs the reports, discounts outliers, and scores the consensus. No grading of its own homework.

STEP 03

Findings cite receipts

Every finding pins file, line, and the audited commit SHA. Claims you can check are claims we can stand behind.

STEP 04

Then the code is gone

Extracted payloads auto-delete within 24 hours. Your report stays; your source doesn't. Nothing trains anyone's model.

Fair questions

05 · FAQ
Will you find every vulnerability in my code?+
No, and nobody honest will tell you otherwise. No analysis, human or machine, catches everything, and a clean report is not proof your code is secure. What we promise instead: independent engines that can't share blind spots by copying each other, a judge with no stake in the verdict, findings precise enough to be checkable, and refunds when we're provably wrong. See the Audit Methodology for exactly what each tier examines.
Why multiple engines instead of one great one?+
Because single models are confidently wrong in ways they can't see. Engines from different vendors fail differently. When they independently converge on a finding, that's signal; when they diverge, our judge treats it as doubt, not filler. Independence is the product.
What happens to my code?+
It's processed to produce your report, then extracted payloads are automatically deleted within 24 hours. Your code is never used to train any model (ours or our providers'), and our model providers are contractually barred from training on API inputs. Details in the Privacy Policy.
Is this a penetration test or a certification?+
No. It's an automated, point-in-time, AI-assisted code analysis: a scored second opinion with receipts, not a pentest, compliance attestation, or professional certification. It's built to be shared (investors, acquirers, clients), but third parties reading your report rely on it at their own judgment.
What if the audit fails midway?+
Then you aren't charged. Your audit token isn't consumed unless every engine and the judge complete. That's not one of the guarantees; that's just how billing should work.