foretop

Pricing

Free to run. Paid only when one repository becomes ten.

Every scanner is open source, unlimited, and needs no account. The hosted hub exists for the point where scan results need to be shared, compared and owned by a team rather than read once in a terminal.

Open-source scanners

Free

Apache-2.0 · unlimited repositories

  • Unlimited repositories
  • Terminal, Markdown, JSON and SARIF output
  • GitHub Action and pull-request annotations
  • Runs locally without an account

Foretop Hub Free

Free

Sign in with GitHub — no card, no sales call, no waitlist

Shared history, policy, ownership and evidence when one repository becomes ten.

  • 3 repositories, then 10 on Team
  • 30 days of finding detail, then 365 days on Team
  • 20 scans per repository each day, then 200 on Team
  • Shared policies and baselines
  • Ownership, escalation and expiring suppressions
  • Dated evidence exports

Foretop Hub Team

€39 /month incl. tax

For teams tracking drift across up to 10 repositories

  • 10 repositories
  • 365 days of finding detail
  • 200 scans per repository each day
  • Shared ownership and review
  • Repository history and comparisons
  • Policies and expiring suppressions
  • Dated evidence exports

Prices include tax. Paddle is our merchant of record and calculates, collects and remits the applicable VAT or sales tax out of the price shown, so the amount you see is the amount you are charged. Cancel from the billing portal at any time; cancellation takes effect at the end of the paid period.

What each tier keeps

Foretop prices retained history, not repository count — history is what actually costs money to store, and it is the thing a team misses when it is gone. Run history is kept for the life of your organisation on every tier; what expires is the finding-level detail behind it.

Comparison of the open-source scanners, Hub Free and Hub Team
 Open-source scanners Hub FreeHub Team
PriceFree, Apache-2.0Free €39/month or €390/year incl. tax
RepositoriesUnlimited 310
Finding detail keptNothing is stored 30 days 365 days
Scans per repository each dayUnlimited 20 200
Run historyLocal filesKept for the life of the organisation Kept for the life of the organisation
AccountNone neededGitHub sign-inGitHub sign-in
Shared policies, ownership, exportsLocal filesYesYes

Expired finding detail is removed according to your plan's retention window and detailed-run limits; run history and the trend line remain. Ending a subscription does not delete run history.

Questions people actually ask

Is the free tier a trial?

No. The scanners are Apache-2.0 and stay free permanently, with no repository limit and no account. They are the evaluation path, which is why there is no time-limited trial of the hosted service.

What does the hosted hub add?

History across runs, shared policies and baselines, ownership routing, expiring suppressions with named owners, and dated evidence exports. A single repository read once in a terminal does not need any of that; forty repositories and a team do.

What happens when I stop paying?

Existing history and evidence stay visible and exportable; new scans and new repository connections pause. Nothing is deleted because a payment failed or a subscription ended. See the refund policy.

Why is history the thing you charge for?

Because it is the thing that costs money to keep. An unscanned repository is free to store; a busy one writing megabytes per run is not. Pricing the cost honestly is why the free tier can stay genuinely useful rather than being crippled on purpose.

How do I subscribe?

Sign in to the hub, open billing settings, and choose monthly or annual. Payment is handled in Paddle's own secure overlay; Foretop never sees your card.

When does Team access begin?

After Paddle confirms the subscription. If confirmation is delayed the hub shows a pending state rather than claiming access you do not have yet — you can leave the page, and it updates by itself once the confirmation arrives.

Can I cancel myself?

Yes, from the billing portal, without contacting anyone. Cancellation takes effect at the end of the paid period, and access continues to that date.

What happens after cancellation?

The organisation returns to Free limits. Run history is not deleted; finding-level detail follows the Free retention window of 30 days. See the refund policy for the 14-day first-payment rule.

Who charges me?

Paddle, as merchant of record and authorised reseller. They issue the invoice and handle VAT and sales tax for your location. Prices include tax. Paddle is our merchant of record and calculates, collects and remits the applicable VAT or sales tax out of the price shown, so the amount you see is the amount you are charged.

I need more than 10 repositories, or self-hosting.

Tell us about your setup.