MetaSolve

Code Zone production bridge

From bounded evaluation to governed production use.

Your 10 public reviews established a useful baseline: Python findings were surfaced across SQL injection, command injection, path traversal, dynamic execution, hard-coded credentials, and resource handling. The next step is a controlled pilot—not an assumption that a public trial represents complete production coverage.

Immediate value · first 5 business days

Establish identity, scope, and a non-production gate.

  1. 01

    Register

    Create an account, verify email, and keep the public sample free of sensitive source.

  2. 02

    Scope

    Inventory repositories, languages, risk tiers, owners, and release environments.

  3. 03

    Pilot

    Start with 1–2 repositories in report-only mode; compare results with existing scanners.

  4. 04

    Govern

    Define reviewer roles, evidence retention, and explicit pass/review/block thresholds.

  5. 05

    Integrate

    Bind hashes, SBOM, provenance, and policy context in CI; gate only after calibration.

Local planning tool

Get a provisional plan recommendation.

This calculator runs only in your browser and does not submit your inputs. It is planning guidance, not a quote, entitlement promise, certification, or regulatory approval.

Languages in scope

Published plan guidance

Match assurance scope to the operating model.

Prices shown are USD. Exact Code Zone entitlements and workload fit should be confirmed during account or enterprise review.

PlanPriceBest forIdentityDeploymentRepresentative controls
Free Trial Free
14 days or 10 tests
Teams evaluating AI assurance before procurement. Single operator access Shared cloud trial workspace
  • 10 completed AI decision verifications
  • 10 basic trust certificates
  • 100 API calls total
  • One governed project
Essential USD $149
per month
Individual professionals, consultants, early-stage teams, and internal pilots. Single operator access Shared SaaS workspace for staging and low-risk internal use
  • 250 decision verifications/month
  • 250 trust certificates/month
  • 10,000 API calls/month
  • 5 users and 5 projects
Professional USD $599
per month
AI product teams, regulated startups, consulting firms, and growing enterprises. Team service identities Shared SaaS with approved production use cases
  • 2,500 decision verifications/month
  • 2,500 trust certificates/month
  • 250,000 API calls/month
  • 20 users and 25 projects
Business / Regulated USD $1,999
per month
Banks, insurers, healthcare organizations, public-sector contractors, and regulated enterprises. Role-based service identities with separation of duties Shared or dedicated regional SaaS where supported
  • 15,000 decision verifications/month
  • 15,000 certificates/month
  • 2,000,000 API calls/month
  • 75 users and 100 projects
Enterprise Assurance Custom
annual contract
Banks, agencies, defense, and critical infrastructure. Governed service identity lifecycle Private, on-prem, or sovereign deployment
  • Private cloud or on-prem option
  • FedRAMP-level architecture support
  • HIPAA and SOC 2 readiness support
  • 24/7 premium support option

Practical default: use Professional for a governed production pilot when its scale and deployment fit. Use Business / Regulated for higher-volume regulated workflows and continuous controls. Scope Enterprise for private/on-premise/sovereign deployment, unsupported languages, or organization-specific rule work. These are scoping triggers—not promises that every requested capability is already available.

CI/CD integration architecture

Keep code scanning and evidence binding explicit.

The current MetaSolve CI client submits hashes, provenance, SBOM, policy context, and verification evidence to the trust API. It does not upload or scan raw repository source. Continue using local scanners in CI, then bind their outcomes to a governed release decision.

1. Pull requestBuild and test
2. Local scannersCode/SCA/secrets/SBOM
3. MetaSolve APIBind hashes and evidence
4. Release gatePass, review, or block
5. DeployOnly with approved state

Rules and compliance

Calibrate before you block.

  • Baseline the six finding categories already observed, then test safe negative controls.
  • Define risk overlays in CI without claiming self-service analyzer rule authoring.
  • Map each finding to evidence relevant to SOC 2, ISO/IEC 27001, or PCI DSS controls; mappings support assessment and do not confer compliance.
  • Require documented reviewer disposition for accepted risk, exceptions, and release overrides.

30–60–90 day rollout

Move the gate from observe to enforce.

Days 0–30

Baseline

Register, inventory, integrate 1–2 repositories, run report-only, establish false-positive and remediation baselines.

Days 31–60

Pilot

Train developers and reviewers, tune CI thresholds, retain evidence, and block only confirmed critical conditions in pilot repositories.

Days 61–90

Scale

Expand by risk tier, activate separation of duties, publish executive KPIs, rehearse exception and rollback procedures.

Controlled production pilot

Validate one workflow before scaling the control.

Create a verified account for plan-based access, or scope language, deployment, evidence-retention, and governance requirements with MetaSolve.