Skip to main content

Guide

SAST pricing models, explained

The list price on a vendor's homepage rarely predicts what a SAST tool actually costs a year in. The pricing model — not the headline number — is what determines that. Here are the three models actually in use, a real example of each, and the specific way each one grows a bill that a first quote doesn't show.

Three models, one real example of each

Per-developer / per-seat SaaS

Priced per active contributor per month, billed by the vendor's cloud platform. Snyk Code ($25/dev/mo, Team plan) and Semgrep Pro ($25–60/dev/mo) both work this way.

What grows the bill

Headcount, not usage. A team that doubles from 10 to 20 developers doubles its SAST bill even if scan volume or code size barely changes — the meter is attached to the org chart, not the codebase.

Self-hosted perpetual license

A license tied to lines-of-code analyzed, running on infrastructure the buyer operates. SonarQube Developer Edition starts around $2,500/year for ~100K LOC; Enterprise and Data Center editions scale into the tens or hundreds of thousands for larger codebases.

What grows the bill

Two things outside the license line item: the codebase itself (LOC-tiered pricing means the license cost rises as the product grows, independent of team size), and the infrastructure to run it — a Java runtime and database to operate and patch, not included in the license price.

Enterprise custom quote

No public per-unit price at all — a sales cycle produces a number. Checkmarx One and Veracode both operate this way, with published estimates in the $35,000–$90,000+/year range depending on scale.

What grows the bill

The negotiation itself. Without a public unit price, there is no way to sanity-check a quote against a list price — the number is whatever the sales process produces, which makes budget planning before that first call effectively a guess.

Flat annual license

A fixed yearly fee tied to scan capacity (files, SLOC, rule count) rather than team size. This is how StaticCodeAudit prices — see the full tier breakdown.

What grows the bill

Only crossing into a higher capacity tier — adding developers to an existing team does not change the price, since nothing is metered per seat.

A live example of a pricing model changing under a buyer

GitHub Advanced Security is a useful case study precisely because it changed shape recently: it used to be sold as one bundle, priced per active committer. In 2025 it split into two separate add-ons — GitHub Code Security ($30/committer/mo, the SAST-equivalent feature) and GitHub Secret Protection ($19/committer/mo, a separate product). A quote or comparison table built before that split, still showing a single bundled number, is now describing a product that no longer exists in that form. This is not a criticism of GitHub's pricing — it is the general risk of per-seat SaaS pricing: the vendor can restructure the meter at any time, and last year's comparison may already be wrong.

Current published entry-level pricing

Tool Model Entry-level price
StaticCodeAudit Flat annual license €990/year (Solo)
Snyk Code Per-developer SaaS $25–40/dev/mo
Semgrep Pro Per-developer SaaS $25–60/dev/mo
GitHub Code Security Per-committer SaaS $30/committer/mo
SonarQube (self-hosted) Perpetual, LOC-tiered ~$2,500+/year + infra
Checkmarx One Enterprise custom quote $35,000–90,000+/year
Veracode Enterprise custom quote $50,000+/year

Same data as the full competitor table, verified and corrected where public pricing had changed.

Frequently asked questions

Which pricing model is "best"?

None universally — it depends on what actually grows in an organisation. A stable team on a growing codebase is penalized by per-seat pricing but not by flat-fee or LOC-tiered pricing. A small, fast-growing team is the opposite case. There is no model that is cheaper in every scenario.

Why do enterprise tools avoid publishing prices at all?

Typically because large deals are individually negotiated based on scale, contract length, bundled products and procurement leverage — a single published number would either overstate small-deployment cost or understate large-deployment cost. It is a common practice in the category, not specific to any one vendor.

Does self-hosted always mean cheaper?

Not necessarily — the license fee is only part of the cost. Running the infrastructure (server, database, patching, uptime) has a real operational cost that a SaaS or flat-fee offline binary does not carry, even when the license line item itself looks lower.

How is this different from the pricing table on the pricing page?

The pricing page shows StaticCodeAudit's own tiers and a competitor snapshot. This page explains the pricing models themselves — what structurally makes each one's bill grow — independent of any single vendor.

See where a flat annual license lands for your team

Open the full tier breakdown, or try the live demo report first — no install, no signup.

See pricing tiers Open the live report