Pricing · Expert
The valuation that arrives already speaking your reviewer’s language
There are decisions where the number is not read, it is attacked. Someone on the other side of the table is paid to find the assumption that does not hold, and they will not do it in your terms. They will do it in SOC 2, in OWASP ASVS, in the control language their function already answers to.
Expert is the tier that meets them there. You choose the compliance and analysis frameworks the valuation is expressed against, and the report arrives already mapped to them. Everything the deterministic engine produces, it produces with its work shown, so each figure can be retraced rather than accepted.
- from £1,999Per assessment
- < 20 minTurnaround
- ASVS · SOC 2Selectable frameworks
- from £1,999Per assessment
- < 20 minTurnaround
- ASVS · SOC 2Selectable frameworks
What you are actually buying
The work you do not have to do.
A valuation that is not expressed against your reviewer’s framework is a valuation somebody has to translate. That somebody is usually you, or an analyst on your team, at the worst possible moment: mid-diligence, against a clock, mapping findings to control objectives by hand in a spreadsheet nobody will ever trust.
Expert removes that step. Select the frameworks before the analysis runs and the report comes out already speaking that language: SOC 2 or OWASP ASVS. What arrives is not evidence you have to interpret. It is evidence your audience can read on the first pass.
The audit trail
Every figure comes with its work shown.
Expert includes a full audit trail. The valuation is recorded factor by factor: the baseline effort established by the measured size and shape of your codebase, every adjustment applied to it, the bounded judgements on system design, domain, integration and security surface, and the scenario multipliers. Every figure traces back to either a measured metric or a signal clamped to what those metrics justify. There is no step in the chain that reads “our engine determined”.
This is what separates a valuation from an estimate. An estimate is what someone believes. A valuation is what an independent party can show you, factor by factor, and defend.
| Time | Action | Target | Hash | State |
|---|---|---|---|---|
| 13:42:08 | ingest.repository | acme/api-monorepo @ 1c8e2f9 | 0xa8f4…b210 | sealed |
| 13:42:11 | measure.static | 1,284 files · 1.2M LOC | 0x7b21…cf90 | verified |
| 13:48:53 | read.ai_bounded | prompts v3.2 · seed 4711 | 0x4e02…1d8a | verified |
| 13:51:27 | compute.valuation | production_readiness=87 | 0x9c61…7f33 | deterministic |
| 13:51:30 | sign.certificate | codeego_cert.pdf | 0x12d9…0aef | signed |
| 13:51:32 | seal.archive | dossier · long-term vault | 0xd7e4…84c1 | admissible |
- 13:42:08sealedingest.repositoryacme/api-monorepo @ 1c8e2f90xa8f4…b210
- 13:42:11verifiedmeasure.static1,284 files · 1.2M LOC0x7b21…cf90
- 13:48:53verifiedread.ai_boundedprompts v3.2 · seed 47110x4e02…1d8a
- 13:51:27deterministiccompute.valuationproduction_readiness=870x9c61…7f33
- 13:51:30signedsign.certificatecodeego_cert.pdf0x12d9…0aef
- 13:51:32admissibleseal.archivedossier · long-term vault0xd7e4…84c1
Calibration
Rigour is credited, not averaged away.
Because Expert works from hard evidence rather than inference, it can give your codebase credit where credit is due. Strong Test Coverage, low complexity, continuous integration and clear Documentation lift the Production Readiness Score through calibrated floors, instead of being diluted into an average.
The consequence matters commercially: engineering discipline that you paid for over years finally shows up in the number, in a form the buyer can verify.
Formal review
Built for formal review.
Expert unlocks the parts of the platform designed for scrutiny.
You select the compliance and analysis frameworks the valuation is expressed against, so the report speaks in the standards your audience already uses rather than in ours. You receive a deterministic maintenance cost estimate derived from your actual infrastructure, not from a sector benchmark. Encrypted inference is included at no extra cost, so the code is analysed under stronger confidentiality guarantees, which matters when the codebase under review is not yours to expose.
And qualified custody is included, not sold separately: an Evidence Certificate issued by a Trusted Third Party, with a verifiable time stamp and an auditable chain of custody. What Expert gives you is the control over when to apply it. You decide, on each analysis, whether it gets sealed.
That control is the point. Sealing creates a permanent, dated record. On an exploratory run against a target you have not bid on yet, or an internal look at your own estate, you may not want one. On the valuation that goes into the data room, you do. Deciding what becomes evidence, and what stays a working document, is your call rather than a consequence of which product you bought.
The frameworks
The standards you can select.
Two different things are being chosen here, and they are worth keeping apart. The compliance frameworks decide what the finished report is expressed against: pick the one your reviewer already works to. The scoring frameworks are the reference models behind each technical dimension, so you can see what the score is measured against rather than take the number on trust.
Compliance · what the report is expressed against
- OWASP Application Security Verification Standardv5.0.0
- SOC 2: Trust Services Criteriav2017-tsc
Scoring · what each dimension is measured against
- Diátaxisv2023Documentation
Diátaxis documentation framework: tutorials, how-to guides, reference and explanation.
- ISO/IEC 25010v2011Code quality
ISO/IEC 25010 product-quality model: Maintainability characteristic.
- OpenTelemetryv1.0Observability
OpenTelemetry observability model: logs, metrics, traces and operational readiness.
- OWASP ASVSv4.0.3Security
Application Security Verification Standard: verification-requirement-driven security assessment.
- OWASP SCVSv1.0Dependencies
OWASP Software Component Verification Standard: dependency and supply-chain verification.
- OWASP Top 10v2021Security
OWASP Top 10 (2021) web application security risks.
Working to a standard that is not on this list? Expert includes the option to request it, so the report can still be expressed against the framework your reviewer already uses.
Fit
When to choose Expert.
Funding rounds where the technical diligence is real. Mergers and acquisitions, on either side of the table. Vendor delivery disputes. Any situation where the valuation becomes legal or financial evidence, and where the cost of the number being wrong is measured in millions rather than in hundreds.
Best for: mergers and acquisitions, funding rounds, and any decision where the valuation becomes evidence.
Included.
All features in Pro, plus:
In the report
- Full Certified Software Valuation: Production Readiness Score, seven technical dimensions, Technical and Economic Valuation
- Selectable compliance and analysis frameworks
- Deterministic maintenance cost estimate derived from your infrastructure
How the figure is built
- Fully deterministic valuation methodology, reproducible on demand
- Detailed audit trail behind every figure
- Evidence-based score calibration that credits real engineering rigour
Safeguards
- Encrypted inference included at no extra cost
- Qualified custody included: Evidence Certificate sealed by a Trusted Third Party, applied at your discretion on each analysis
- Challenge any factor: accepted challenges re-run the analysis at no cost, with both versions kept
The commercials
- Results in under 20 minutes
- One-off payment, no subscription
from £1,999, one-off payment
Frequently asked questions.
No. Every Codeego analysis is reproducible, on every tier: the metrics come from purpose-built tools, and the AI layer runs at temperature zero with a fixed seed, its judgements clamped to ranges the hard metrics justify. Reproducibility is not something we sell back to you at a higher price.
Two compliance frameworks, which decide what the finished report is expressed against: OWASP Application Security Verification Standard and SOC 2: Trust Services Criteria.
Behind the score sit six reference models, one or more per technical dimension: Diátaxis, ISO/IEC 25010, OpenTelemetry, OWASP ASVS, OWASP SCVS and OWASP Top 10.
Note that the only ISO in the list is ISO/IEC 25010, the product-quality model used to score code quality. It is not a compliance framework and it is not ISO 27001.
An inventory of the infrastructure your codebase actually runs (compute, databases, queues, storage, specialised workloads), converted into a monthly operating cost range by a deterministic schedule. Not a sector benchmark, and not a percentage of the rebuild figure.
Pro seals the valuation. Expert changes how it is produced. They are two different axes, not two rungs.
Pro is Starter with qualified custody switched on: a certified, sealed figure, proportionate for light due diligence. Expert adds the frameworks: you choose the standards the valuation is expressed against, and the report arrives already mapped to them, with an audit trail behind every figure and custody included, applied at your discretion.
Choose Pro when the report needs to be trusted. Choose Expert when somebody is going to check it against a standard.
Yes, at no extra cost. Expert includes everything in Pro, the Evidence Certificate among it.
What Expert adds is control over when it is applied. On each analysis you decide whether the report is sealed. Sealing creates a permanent, independently verifiable record, which is exactly what you want on the valuation that goes into a data room, and not always what you want on an exploratory run against a target you have not bid on. The choice is yours per analysis, not per purchase.
Because of what it saves, not because of what it adds.
Pro gives you a certified figure. Expert gives you that figure already expressed against the framework your reviewer works to, with every number retraceable to the evidence behind it. The alternative is not “buy Pro and lose something”. The alternative is buying Pro and then having someone on your team do the mapping by hand, mid-diligence, against a clock. Measure the price against that afternoon, not against the other tier.
No, and it is worth being exact about this rather than comfortable.
The analysis runs on remote infrastructure. Your code is sent there. What encrypted inference changes is that it is processed under encryption and inside hardware-isolated environments, so nobody can read what you sent at any point.