# Certification & pricing

> Free public-interest inspection for high-value open-source repositories; paid certification for private and niche repositories. Payment never changes a result.


The economics of inspect.software follow one rule: **inspection of software
the public depends on is free, and depth and privacy are paid for.** Revenue
from paid services funds the free public record.

<div class="md-callout"><span class="md-callout-icon">◇</span><div><b>A higher result is never for sale.</b> Payment buys analysis, privacy, frequency, and reporting — the methodology and the outcome are identical on every tier. See <a href="/wiki/signals-not-warranties">signals, not warranties</a>.</div></div>

## Free — the public record

Repositories of high public value are inspected free of charge:

- Full health report against the complete
  [versioned methodology](/methodology), published in the
  [public record](/#record).
- An embeddable [GitHub badge](/badges) reflecting the current standing.
- Re-inspection when a new scan is submitted or scheduled by an operator.

Eligibility is assessed automatically at submission against documented
public-interest thresholds (adoption, ecosystem presence, activity). Any
GitHub account may submit a public repository for consideration.

## Paid — certification and depth

Repositories outside the free thresholds, and organizations needing more
than the public record offers:

| Service | For | What it provides |
| ------- | --- | ---------------- |
| **On-demand certification** | Maintainers of niche public repositories | Full inspection and badge now, without waiting for free coverage; paid from an account balance directly at submission. Credits are purchased on the account profile, or granted by a code |
| **Developer program** | Maintainers inspecting their own work regularly | A subscription covering inspections of repositories the account owns or maintains, however niche — in place of per-inspection credits |
| **Private repository audit** | Organizations with closed source | Planned service; currently arranged only through a separate engagement |
| **Continuous monitoring** | Engineering and security teams | Scheduled re-inspection with alerts on regressions — band drops, security posture changes, bus-factor decline |
| **Deep security review** | Security-conscious organizations | Expanded supply-chain and static-analysis coverage beyond the standard posture signals |
| **Enterprise reporting** | Procurement, platform, and compliance teams | Portfolio views across dependencies and exportable, compliance-ready reporting |
| **API access** | Platforms and developer tools | Programmatic access to published results and metrics |

On-demand certification and the developer program are available today; current
prices are shown on the [account profile](/profile), and payment is handled by
Stripe. The remaining services are being introduced in stages; terms are
documented per engagement. Enquiries:
[mail@inspect.software](mailto:mail@inspect.software).

## What payment can never do

- Change a formula, weight, threshold, or published value.
- Remove or suppress an unfavorable published result.
- Buy placement or ranking in the public record.

Where a paid scan narrows the methodology (an agreed
[scan configuration](/wiki/scan-configuration)), the report itself documents
exactly what was measured and what was excluded.

## Why free coverage is sustainable

Free inspection is bounded to genuinely popular, high-public-value software
— the packages whose health is systemic. The reasoning is documented openly
in the [about](/about) page's principles.
