Harvey / PricingTransparent pricing

No "book a call to hear the price."

Publishing prices is deliberate — most boutique auditors hide them behind a call. Pricing scales with your codebase size, so a weekend project and an enterprise monorepo never pay the same.

FREE SCAN
$0
  • Source-only, no credentials
  • Static findings + a ten-module coverage ledger
  • Same-day, yours to keep
Run the free scan
CONNECTED AUDIT
$500 / from · by size
  • All ten modules, reviewed with real verdicts
  • Live database: RLS, Supabase advisors
  • PII protection verified in production
  • Read-only access — nothing stood up
Start with a free scan
FULL AUDIT
$1,000 / from · by size
  • Everything in the Connected audit
  • We stand up your stack and attack it live
  • Cross-tenant access & auth flaws proven
  • Mutation-tested tests + investor-ready summary
Start with a free scan
Codebase size · measured automaticallyFree scanConnectedFull audit
Small · under 10k lines$0$500$1,000
Medium · 10k–50k lines$0$1,500$3,000
Large · 50k–150k lines$0$3,500$7,000
Enterprise · 150k+ / monorepo / regulated$0CustomCustom

We measure your codebase size during the free scan and quote from it — generated and vendored code doesn't count. Launch pricing; for context, source-only "vibe-code" audits run $1,500–$5,000 and a traditional pentest $4,000–$12,000 regardless of app size.

Add-on

Findings to tickets. We file every finding as an issue in your tracker — GitHub, Jira, Linear, GitLab, or Azure DevOps — deduped against your last audit, so your team fixes from their own board.

Add-on

Investor-ready summary. A buyer-facing document for fundraise or acquisition diligence — non-technical to read, defensible under technical scrutiny. Available on the Full tier.

Included

Re-audit credit. When you ship the fixes, we re-verify the critical findings once at no extra charge, if requested within 30 days of the original audit. Additional re-audits within that window are a paid add-on at 50% of the original audit price. The repeat-customer diff automates it, so it's cheap for us and high-trust for you.

Included

Machine-readable exports. Ask and your findings also ship as SARIF — the format GitHub code scanning and security tooling ingest — plus a CycloneDX software bill of materials of your dependencies, the artifact enterprise buyers ask for. The coverage ledger travels inside the SARIF, so a module that didn't run can't disappear into "no results."

Free indicates · the audit proves

What each tier can and can't tell you.

The escalation is by access: Free reads your source, Connected adds your live database, Full stands up and attacks a running copy. Each rung is a clean superset of the one before.

What you actually getFree scan$0Connectedfrom $500Full auditfrom $1,000
Reads your source
Findings from every module source alone can run
Coverage ledger: all ten modules, status and reason
False positives triaged out
Fixes named, not just flagged
Reads your production database
Live database + Supabase advisors
PII protection verified in production
Stands up & attacks your app
Cross-tenant access proven on a live stack
Points out tests that pass even when the code is broken
Auth, endpoint & service-seam attacks
Pricing questions

Straight answers.

How is my codebase size measured?

Automatically, during the free scan — lines of application code, with generated and vendored code excluded (our dead-code and duplication modules already detect it). The free scan doubles as an instant, transparent quote for the paid tiers.

What if I decline database access on a paid tier?

The database-dependent checks record "not run — no access" in the coverage ledger, on-brand, and the rest of the audit still runs. You're never charged for a check we couldn't perform.

Is the small-tier Full audit a real pentest?

It's a genuine audit of a small app, and the Full tier does run a live pen-test on a copy of your stack. We keep the language honest: a small MVP is scoped-small, so it sits alongside the $1,500–$5,000 source-review audits rather than a formal enterprise pentest — the difference being that those are source-only, and this one actually runs. If you need a compliance letter, we'll point you to a pentest firm for that specifically.

Are these prices final?

These are launch anchors. Exact price points are being validated against real engagements; the grid is the honest starting point, not a placeholder for a bigger number revealed on a call.

Start free

The free scan is also your quote.

Source-only, no credentials — and it measures your size to quote the paid tiers.