Pricing
Credit-based pricing for every workload, across every plan
SAST, full attestations and Live Monitoring all draw from the same credit balance. Buy a fixed monthly plan for a lower rate, or top up as you go.
- No card required
- 1-hour turnaround on your first scan
- Public registry trust badge included
Plans
Monthly plans
Commit to a monthly bundle and your price per credit drops. Every bundle works the same way — only the volume and the rate change.
Partner
Custom volume, custom terms. For platforms reselling TrustYourAgent or fleets beyond Enterprise scale.
Need more mid-cycle? Top up at any time at your plan's rate. No plan yet? Buy credits as you go at €1.00/credit, the same rate as Starter.
Credits
What determines your credit cost
Every attestation is priced the same way: a baseline for your codebase size, a multiplier for complexity, and a surcharge per compliance standard in scope.
We don't quote attestations in euros. Every scan costs credits, calculated from your codebase size, complexity and compliance scope. What a credit is worth in euros depends only on which plan you're on, above.
See details: how credits are calculated
1. Codebase size (baseline)
Applies to SAST and full attestations. Live Monitoring runs as a continuous credit draw, not a one-off baseline.
| Profile | LOC range | Monthly baseline (credits) | Rationale |
|---|---|---|---|
| Micro | < 5K | 300 | Single-function agent; minimal state; few paths |
| Small | 5K–50K | 1,500 | Standard agent; moderate dependencies; typical test coverage |
| Large | 50K–500K | 3,000 | Enterprise agent; heavy dependencies; comprehensive evidence |
| Massive | 500K+ | 5,000+ | Multi-service orchestration; deep chain; regulatory-grade |
2. Complexity multiplier
Based on dependency count, chain depth and how many standards apply.
| Tier | Characteristics | Multiplier | Example |
|---|---|---|---|
| Low | 1–3 dependencies; simple chain; 1–2 standards | 1.0× | Standalone micro-service; no external APIs |
| Medium | 5–10 dependencies; branching chain; 3–4 standards | 1.5× | Standard SaaS agent; payment processor + rate limiter + logging |
| High | 15+ dependencies; deep chain; 4+ standards; regulatory evidence | 2.0× | FCA-regulated fintech; insurance underwriting; healthcare |
Example: a large codebase (3,000 baseline) at high complexity (2.0×) consumes 6,000 credits for that attestation.
3. Standards and regulatory surcharge
Added per compliance standard beyond the 1–2 covered in your baseline.
| Standard / requirement | Additional credits | Notes |
|---|---|---|
| ISO 27001 (InfoSec) | +500 | Baseline covers 1–2 standards; additional = +500 each |
| PCI-DSS (Payment) | +500 | — |
| GDPR (Data Protection) | +500 | — |
| EU AI Act (High-Risk) | +1,000 | Heavier compliance evidence burden |
| SOC 2 Type II | +500 | — |
| Custom regulatory (e.g. NIST AI RMF) | +500–1,000 | Depends on scope |
Example: a high-complexity agent (6,000 baseline) + 4 standards (2,000 surcharge) = 8,000 credits for that attestation.
Coverage
What each scan type includes
Every plan draws from the same feature set. What you get depends on the scan type you run, not which plan you're on.
| Capability | SAST onlyCode | Full attestationCode + runtime | Live MonitoringContinuous |
|---|---|---|---|
| Testing coverage | |||
| Static code analysis (source + dependencies) | Included | Included | Not included |
| Dynamic / adversarial testing against your live API | Not included | Included | Not included |
| Tested against TrustYourAgent's full 23-vector risk library | Code vectors only | Included | Not included |
| Evidence & reporting | |||
| Full trust report (HTML + PDF) | Included | Included | Not included |
| Structured findings JSON + line-level remediation pointers | Included | Included | Not included |
| Trust score, risk score and confidence grade (A–E) | Included | Included | Not included |
| Machine-readable Trust Mark + public verification URL | Included | Included | Not included |
| Behavioural graph | Included | Included | Not included |
| Data lineage | Included | Included | Not included |
| Regulatory coverage analysis | Included | Included | Not included |
| Compliance conformity assessment | Included | Included | Not included |
| Evidence packs | Included | Included | Not included |
| Integration with GRC systems | Included | Included | Not included |
| Signed Behavioural Provenance Manifest (SHA-256) | Not included | Included | Not included |
| CI/CD gate result + PR annotations | Included | Included | Not included |
| Deployment state (SAFE / GATED / BLOCKED) | Not included | Included | Not included |
| Regulated-tier evidence: EU AI Act clause indicators, Annex IV support, audit exposure rating | Not included | Included | Not included |
| Ongoing monitoring | |||
| Behavioural trust detection and decisioning signals | Not included | Not included | Included |
| Continuous compliance posture tracking | Not included | Not included | Included |
| Data lineage drift | Not included | Not included | Included |
| Tool and model drift | Not included | Not included | Included |
| Platform and protocol full agent-chain detection | Not included | Not included | Included |
| Multi-agent / fleet-level risk surfacing | Not included | Not included | Included |
| Alert routing (ServiceNow, JIRA, Archer, Splunk, Datadog) | Not included | Not included | Included |
| 90-day validity window with re-attestation trigger | Included | Included | Continuous |
Regulated-tier evidence ships with a full attestation when your agent is flagged high-risk under the applicable framework.
FAQ
A few things people ask
Start with €10 free
No card required. See your first attestation in under an hour.
