Token Policy
Token pricing follows measured scan effort, not button clicks.
Every paid plan includes a monthly token pool. Tokens are debited only after a scan or analysis action completes, using the actual workload produced by that activity. Smaller assets cost less, while large repositories, broad cloud inventory sweeps, and deep database scans consume more because they require more processing, API work, and persistence.
What consumes tokens
Source code scans are weighted by files scanned, bytes processed, and connector API calls. Database scans are weighted by sampled objects and pages read. Cloud inventory is weighted by service checks, regions, and discovered assets. Endpoint telemetry and deeper asset actions follow the same measured-work principle.
When tokens are debited
We do not charge in advance. The ledger is updated only after the scan completes, so the debit reflects the real size of the repository, table, inventory pass, or endpoint action that was actually performed.
Visibility and top-ups
Each workspace gets a shared organizational token balance with full token history. Every debit records the initiating user, scan surface, target, metadata, token amount, and resulting balance. Additional token top-ups can be purchased when the monthly pool runs low.