Simple, Transparent Pricing

The Right Plan for Every Team

Start free with 12 core analyzers — no account required. Upgrade to Pro for AI Copilot, Attack Graph, Exploit PoC, Solana support, and branded HTML/SARIF reports. 2 machine activations per license.

Cloud App is Live — Purchase and activate your Pro license directly at app.counterscarp.io
Buy Pro License →
Open Source
Free
$0 / forever
12 core analyzers. No account required. MIT licensed. Install with pip install counterscarp-engine --upgrade

  • Heuristic Scanner — 23 EVM rules
  • Slither (Trail of Bits)
  • Aderyn (Cyfrin Rust)
  • Medusa — coverage-guided fuzzing
  • Foundry — invariant testing
  • Mythril — symbolic execution
  • Supply Chain (OSV.dev)
  • Threat Intel (Code4rena, Immunefi)
  • Liar Detector (NatSpec analysis)
  • Access Matrix
  • Upgrade Diff (UUPS/proxy)
  • CI/CD Pipeline Generator
  • Markdown report
  • JSON output
  • MIT — commercial use allowed
  • Self-hosted, no data sent
  • Air-gap compatible
Enterprise
Enterprise
Custom
Custom activations · Custom terms
For audit firms, protocol teams, and organizations that need custom deployment, SLAs, white-label reports, and dedicated support.
Contact Sales

Custom activations · Custom billing · SLA included


  • On-premise / air-gapped deployment
  • Custom analyzer development
  • White-label report branding
  • Custom vulnerability pattern library
  • Dedicated knowledge base training
  • Local LLM integration
  • Data residency options
  • SSO / SAML integration
  • Audit log & access controls
  • NDA available
  • Dedicated support engineer
  • SLA guarantee (4h response)
  • Onboarding & training sessions
  • Custom integration assistance
Use Cases

Who Uses Which Plan

Solo Developers

Building a DeFi protocol or NFT contract? Run a full audit before deployment. Free CLI, no account needed.

CLI (Free)

Protocol Teams

Continuous monitoring, PR scanning, and team-wide visibility into your security posture. Web UI and integrations.

Cloud App (Soon)

Security Researchers

Use Counterscarp as your first-pass tool on Code4rena and Immunefi contests. CLI is free, fast, and comprehensive.

CLI (Free)

Audit Firms

White-label reports, custom analyzer rules, on-premise deployment, and dedicated support for client engagements.

Enterprise
Full Breakdown

Feature Comparison

Feature CLI (Free) Cloud App Enterprise
Core Analysis
All 21 analyzers
EVM (Solidity) support
Solana / Anchor support
Medusa fuzzing
Mythril symbolic execution
Slither + Aderyn integration
Custom analyzer patterns
Output & Reporting
Interactive HTML report
D3.js attack graph
Markdown report
SARIF output
White-label branding
Shared report permalinksSoon
AI Features
AI Audit Copilot (RAG)
Exploit PoC generator
CI/CD pipeline generator
Custom knowledge base
Platform & Collaboration
Web UI (no install)Soon
Team workspacesSoon
Scheduled scansSoon
REST APISoon
GitHub App integrationSoon
On-premise deployment
Air-gapped installation
Support
Community (GitHub Issues)
Email supportSoon
Dedicated support engineer
SLA guarantee
Common Questions

Frequently Asked Questions

Yes. The CLI is MIT licensed and will remain free forever. There are no usage limits, no rate limits, no telemetry, and no account required. You can use it commercially, fork it, and build products on top of it without restriction.
The CLI runs entirely locally. Your contract code never leaves your machine. The AI Copilot can optionally query external LLM APIs (configurable in counterscarp-audit.toml), but this is opt-in and you control which endpoint is used. For air-gapped environments, AI features can be disabled or pointed at a local LLM.
Yes — the Cloud App is live at app.counterscarp.io. Run audits from your browser with no local install required. Purchase and activate your Pro license directly from the app. Pro unlocks all 21 analyzers including AI Copilot, Attack Graph, and Exploit PoC Generator.
Absolutely. The MIT license explicitly permits commercial use. Audit firms, independent security researchers, and protocol teams use Counterscarp as part of paid engagements. The generated reports are yours to use, share, and include in client deliverables without restriction.
The AI Audit Copilot requires an OpenAI or compatible LLM API key for natural language remediation guidance. You provide your own key — Counterscarp never stores or proxies your API credentials. The RAG knowledge base similarity search works fully offline without any API key.
No — and we're honest about that. Counterscarp dramatically reduces the time and cost of security analysis and catches a wide range of vulnerability classes automatically. But complex business logic bugs, economic attack vectors, and novel exploit patterns still benefit from human expert review. We recommend using Counterscarp as a first pass before a manual audit, and as continuous monitoring after deployment.
Absolutely. The CI/CD Generator feature creates ready-to-use pipeline configurations for GitHub Actions, GitLab CI, and CircleCI. You can configure severity thresholds to automatically block PRs that introduce critical vulnerabilities. SARIF output integrates natively with GitHub Code Scanning.
Get Started

Start Auditing For Free

Install the CLI in one command. No account. No credit card. No limits. Just security.

Install CLI Free See Live Demo Talk to Sales