WYSTAN.AI
Get started
WYSTAN.AI
How it worksLive scanDocsPricingGet started
pricing

Pay for repos,
not developers.

Unlimited developers on every tier — you pay for the repositories we keep mapped, never for seats. One price per org, whether you're 8 engineers or 50. We run your first scan for you.

Free
$0/ forever

Open source, and trying it out

  • 1 public / open-source repo · ~150K LOC
  • Unlimited developers
  • 1 full scan / mo · unlimited incremental
  • 50 PR impact comments / mo
  • Hosted MCP for Cursor / Claude Code / Cline
Start free
Pro
$99/ org / mo

Teams of ~8–50 engineers

  • 2 repos included · +$25 / repo / mo
  • Unlimited developers (never per-seat)
  • 30 full re-scans / mo · unlimited incremental
  • 2,000 PR impact comments / mo
  • Weekly Slack digest + drift report
  • Sentry + PostHog overlay
Founding 20 · 40% off for 12 months → $59/moStart free
Scale
$299/ org / mo

Several products, bigger monorepos

  • 10 repos included · +$19 / repo / mo
  • ~5M LOC fair use
  • 150 full re-scans / mo
  • 10,000 PR impact comments / mo
  • Everything in Pro
  • Priority support
Founding · 40% off for 12 months → $179/moStart free

Repos are the unit you buy; codebase size (LOC) is a fair-use fence, not a meter; developers are never counted. Incremental scans re-map only what a push or PR changed — unlimited everywhere. Full re-scans rebuild the whole map (first scan, on-demand rescans, and the weekly calibration on paid tiers) and draw from your monthly cap.

Bigger, or need it in your own VPC? Self-hosting and SSO are on the roadmap — tell us what you need and we'll tell you honestly whether we're there yet: hello@wystan.ai

On the roadmapPrivate mode · Customer-Managed Keys · self-hosting · SSO

Private mode encrypts feature names and file paths too, so our servers see only opaque IDs and counts. Customer-Managed Keys put every decryption under a key you can revoke. Self-hosting runs engine, dashboard and MCP inside your VPC. We publish these when they ship, not before — tell us which one you need and we'll say where it is.

Tell us what you need
one-time audits · separate from the subscription

Need a verdict, not a subscription?

Same engine, plus human judgment. We run the scan, verify every finding by hand against your repo, and deliver a report you can act on — or hand to a board or an investor. The Codebase Audit is fully credited toward any plan, so it doubles as a paid trial.

Feature-Map Snapshot
$499one-time

See your codebase mapped

  • 1 repo · up to ~150K LOC
  • Automated report: features, flows, bus factor, hotspots, coverage
  • PDF + 30 days of dashboard access
  • 24h turnaround
Order a snapshot
Codebase Audit
$1,900one-time

New CTO, refactor quarter, handover

  • Up to 3 repos · ~1M LOC
  • Every finding verified by a human
  • Prioritized top-10 risk register
  • 60-min walkthrough call
  • 48–72h turnaround
  • 100% credited toward any plan within 60 days
Credits toward your subscriptionBook an audit
Due-Diligence Screen
From $5,500one-time

Investors & acquirers — the first pass before full tech DD

  • Any size · multi-repo
  • Written third-party report, under NDA
  • Bus-factor & key-person risk assessment
  • Q&A session with your investment team
  • ~5 business days
Contact us
what's inside the audit

Metrics nobody else measures per feature.

Your scan already tracks bug-fix ratio, health and hotspots. Audits add the layer an EM or architect actually decides with — people, process and risk, derived from git history and joined to your features. Every number ships with its confidence band and the commits behind it. How every metric is computed →

AI ERA · CTO · board
AI-Authorship Share
What share of each feature's lines is agent-committed — line-weighted, read from git trailers (or your git-ai notes). An honest lower bound, labelled as one.
Where AI code is working for you, and where it's rotting — per product feature, not per repo.
AI ERA · EM
AI vs Human Rework
Lines rewritten within 28 days of landing — code that didn't stick — split by AI and human authorship.
One real audit: AI lines reworked 2.9× more than human lines.
PROCESS · EM
Review Hygiene
Self-merged PRs, zero-review merges, sub-minute rubber-stamp approvals, time-to-review, reviewer concentration — per feature.
The leading indicator your bug-fix ratio lags by a quarter.
DEFECTS · Architect
Defect Origins (SZZ)
Every bug-fix traced back through blame to the commit that introduced the defect: who introduces bugs, where, and how long they live.
Fixes land in the handler; bugs are born in the shared validator. Now you see both.
KNOWLEDGE · EM · investor
Orphaned Code %
The share of each feature's lines whose last author no longer commits — knowledge that already left the building.
Sharper than bus factor: not "few people know this" — nobody active does.
ARCHITECTURE · Architect
Boundary Erosion
Feature pairs that increasingly change together, quarter over quarter, with the exact files where the boundary leaks.
Modularity as a trend, not a feeling — and proof when refactoring works.
DD · Investor · acquirer
SBOM → Features
Full transitive dependency tree, license classes and known CVEs — joined to the features that actually import them.
Not a flat npm-audit dump: "this CVE is reachable from Checkout and Billing."
TESTS · EM · QA
Journey-Level Coverage
Which user journeys are exercised by e2e tests, which by integration only, and which are untested — read directly from the routes your specs visit.
Coverage in product language: "63 journeys: 9 e2e, 21 integration-only, 33 bare."
REALITY · EM · PM
Risk × Usage
Real user journeys mined from your analytics, ranked by traffic and overlaid on every risk metric above.
"Your #2 most-used journey runs through your #1 defect hotspot."
what's included

Compare the tiers.

FeatureFreeProScale
Core
Source-available CLI (FSL) + hosted MCP server
Hosted dashboard
Repositories included1210
Extra repos$25 / repo / mo$19 / repo / mo
Private repos
DevelopersUnlimitedUnlimitedUnlimited
Usage
Full re-scans / month (weekly calibration included)130150
PR impact comments / month502,00010,000
Incremental scansUnlimitedUnlimitedUnlimited
Weekly calibration re-scan + drift report
Fair-use codebase size (LOC)~150K~1M~5M
Boost packs (200 / 1,000 / 5,000 extra full scans)
Runtime & delivery
Sentry + PostHog attribution per feature
Slack digests + REST API
PR comments on every pull request
honest positioning

Where Wystan fits.

Not a replacement for your PR reviewer, your error tracker or your static analyser. Wystan lives in a specific slice — the persistent, feature-grained map of your product built from git history, with runtime joined to it. Here's where that slice overlaps with the tools you probably already pay for.

questions

Frequently asked.

Why unlimited developers instead of per-seat?
Developers aren't what cost us money — the code we scan and PR-comment volume are. Invite every engineer, EM, PM and contractor; your bill doesn't move. Per-seat tools punish you for inviting the people who most need visibility.
Is per-repo pricing a good deal compared with per-seat tools?
For a 10-engineer team, $99/month is about $119 per engineer per year — against $240–400/month for per-seat review tools at the same headcount. Below ~5 engineers a per-seat tool can be cheaper; Wystan pays off from roughly 8 engineers up, and the gap widens as you grow, because your bill doesn't.
What is the Founding 20 offer?
The first 20 organizations get 40% off for their first 12 months — Pro at $59/mo, Scale at $179/mo — in exchange for a 30-minute feedback call each month for the first three months and a short quote we may publish. After 12 months, list pricing applies; after 20 orgs, the offer closes.
How is a one-time audit different from a subscription?
Same engine, different deliverable. The subscription is the living map: it re-scans on every push, comments on every PR, and sends weekly drift digests — fully automated. An audit is a point-in-time deep read where a human verifies every finding, writes a prioritized risk register, and walks you through it — a report you can hand to a board or an investor. The Codebase Audit is 100% credited toward any plan within 60 days, so it works as a paid trial, not a fork in the road.
Is there really a free tier?
Yes, with no trial clock. The engine is source-available (FSL-1.1 — free to use and read; each release converts to Apache-2.0 after two years). The hosted Free tier covers one public / open-source repo up to ~150K LOC, with one full scan a month and 50 PR comments — incremental scans stay unlimited. Runtime integrations (Sentry, PostHog, Slack) are Pro and above.
What counts as a scan?
Incremental scans (on push / PR) are unlimited on every tier. Full re-scans (initial, on-demand, and the weekly calibration re-scan on paid tiers) draw from your monthly cap — 1 on Free, 30 on Pro, 150 on Scale. The billing page shows your running usage. Need more in a busy month? Boost packs add 200, 1,000 or 5,000 extra full scans as one-time top-ups — incremental scans are never limited.
What is the weekly calibration re-scan?
Once a week (paid tiers) we re-run a full cold scan of each repo and diff it against last week's anchor. The fresh full scan is the ground truth that corrects any drift the fast incremental scans accumulated, and the diff — features added or removed, coverage and flow shifts — lands in your Slack digest. It draws from the same monthly full-scan cap.
How do monorepos count against the repo limit?
One repository = one slot, monorepos included — a 12-package Turborepo is still one repo. Pro includes 2 repos and Scale 10; extra repos are $25 (Pro) or $19 (Scale) per repo per month. What scales with codebase size is the fair-use LOC cap (~150K Free, ~1M Pro, ~5M Scale). Inside the dashboard each workspace package is still mapped and scored as its own project.
Do you ever store our source code?
Never, on any tier. The scanner processes code in memory only and discards it. We store derived metadata — feature names and metrics are readable today, scan content is encrypted at rest. See the security page for the full data-flow.
Do you offer on-prem or self-hosted deployment?
Not today. Self-hosting (engine, dashboard and MCP inside your VPC), SSO and Customer-Managed Keys are on the roadmap. If you need one of them, email hello@wystan.ai — we'll tell you honestly where we are and what we can do in the meantime.
get started

Start free. Upgrade when you hit a limit, never a timer.