Baseline
Register, inventory, integrate 1–2 repositories, run report-only, establish false-positive and remediation baselines.
Code Zone production bridge
Your 10 public reviews established a useful baseline: Python findings were surfaced across SQL injection, command injection, path traversal, dynamic execution, hard-coded credentials, and resource handling. The next step is a controlled pilot—not an assumption that a public trial represents complete production coverage.
Immediate value · first 5 business days
Create an account, verify email, and keep the public sample free of sensitive source.
Inventory repositories, languages, risk tiers, owners, and release environments.
Start with 1–2 repositories in report-only mode; compare results with existing scanners.
Define reviewer roles, evidence retention, and explicit pass/review/block thresholds.
Bind hashes, SBOM, provenance, and policy context in CI; gate only after calibration.
Local planning tool
This calculator runs only in your browser and does not submit your inputs. It is planning guidance, not a quote, entitlement promise, certification, or regulatory approval.
Published plan guidance
Prices shown are USD. Exact Code Zone entitlements and workload fit should be confirmed during account or enterprise review.
| Plan | Price | Best for | Identity | Deployment | Representative controls |
|---|---|---|---|---|---|
| Free Trial | Free 14 days or 10 tests |
Teams evaluating AI assurance before procurement. | Single operator access | Shared cloud trial workspace |
|
| Essential | USD $149 per month |
Individual professionals, consultants, early-stage teams, and internal pilots. | Single operator access | Shared SaaS workspace for staging and low-risk internal use |
|
| Professional | USD $599 per month |
AI product teams, regulated startups, consulting firms, and growing enterprises. | Team service identities | Shared SaaS with approved production use cases |
|
| Business / Regulated | USD $1,999 per month |
Banks, insurers, healthcare organizations, public-sector contractors, and regulated enterprises. | Role-based service identities with separation of duties | Shared or dedicated regional SaaS where supported |
|
| Enterprise Assurance | Custom annual contract |
Banks, agencies, defense, and critical infrastructure. | Governed service identity lifecycle | Private, on-prem, or sovereign deployment |
|
Practical default: use Professional for a governed production pilot when its scale and deployment fit. Use Business / Regulated for higher-volume regulated workflows and continuous controls. Scope Enterprise for private/on-premise/sovereign deployment, unsupported languages, or organization-specific rule work. These are scoping triggers—not promises that every requested capability is already available.
CI/CD integration architecture
The current MetaSolve CI client submits hashes, provenance, SBOM, policy context, and verification evidence to the trust API. It does not upload or scan raw repository source. Continue using local scanners in CI, then bind their outcomes to a governed release decision.
Rules and compliance
30–60–90 day rollout
Register, inventory, integrate 1–2 repositories, run report-only, establish false-positive and remediation baselines.
Train developers and reviewers, tune CI thresholds, retain evidence, and block only confirmed critical conditions in pilot repositories.
Expand by risk tier, activate separation of duties, publish executive KPIs, rehearse exception and rollback procedures.
Controlled production pilot
Create a verified account for plan-based access, or scope language, deployment, evidence-retention, and governance requirements with MetaSolve.