Pricing · Expert

The valuation that arrives already speaking your reviewer’s language

There are decisions where the number is not read, it is attacked. Someone on the other side of the table is paid to find the assumption that does not hold, and they will not do it in your terms. They will do it in SOC 2, in OWASP ASVS, in the control language their function already answers to.

Expert is the tier that meets them there. You choose the compliance and analysis frameworks the valuation is expressed against, and the report arrives already mapped to them. Everything the deterministic engine produces, it produces with its work shown, so each figure can be retraced rather than accepted.

  • from £1,999
    Per assessment
  • < 20 min
    Turnaround
  • ASVS · SOC 2
    Selectable frameworks

What you are actually buying

The work you do not have to do.

A valuation that is not expressed against your reviewer’s framework is a valuation somebody has to translate. That somebody is usually you, or an analyst on your team, at the worst possible moment: mid-diligence, against a clock, mapping findings to control objectives by hand in a spreadsheet nobody will ever trust.

Expert removes that step. Select the frameworks before the analysis runs and the report comes out already speaking that language: SOC 2 or OWASP ASVS. What arrives is not evidence you have to interpret. It is evidence your audience can read on the first pass.

The audit trail

Every figure comes with its work shown.

Expert includes a full audit trail. The valuation is recorded factor by factor: the baseline effort established by the measured size and shape of your codebase, every adjustment applied to it, the bounded judgements on system design, domain, integration and security surface, and the scenario multipliers. Every figure traces back to either a measured metric or a signal clamped to what those metrics justify. There is no step in the chain that reads “our engine determined”.

This is what separates a valuation from an estimate. An estimate is what someone believes. A valuation is what an independent party can show you, factor by factor, and defend.

audit_trail.sample.log
sample
  • 13:42:08sealed
    ingest.repository
    acme/api-monorepo @ 1c8e2f9
    0xa8f4…b210
  • 13:42:11verified
    measure.static
    1,284 files · 1.2M LOC
    0x7b21…cf90
  • 13:48:53verified
    read.ai_bounded
    prompts v3.2 · seed 4711
    0x4e02…1d8a
  • 13:51:27deterministic
    compute.valuation
    production_readiness=87
    0x9c61…7f33
  • 13:51:30signed
    sign.certificate
    codeego_cert.pdf
    0x12d9…0aef
  • 13:51:32admissible
    seal.archive
    dossier · long-term vault
    0xd7e4…84c1
6 / 6 events · cryptographic chain intactTrusted Third Party · sealed

Calibration

Rigour is credited, not averaged away.

Because Expert works from hard evidence rather than inference, it can give your codebase credit where credit is due. Strong Test Coverage, low complexity, continuous integration and clear Documentation lift the Production Readiness Score through calibrated floors, instead of being diluted into an average.

The consequence matters commercially: engineering discipline that you paid for over years finally shows up in the number, in a form the buyer can verify.

Formal review

Built for formal review.

Expert unlocks the parts of the platform designed for scrutiny.

You select the compliance and analysis frameworks the valuation is expressed against, so the report speaks in the standards your audience already uses rather than in ours. You receive a deterministic maintenance cost estimate derived from your actual infrastructure, not from a sector benchmark. Encrypted inference is included at no extra cost, so the code is analysed under stronger confidentiality guarantees, which matters when the codebase under review is not yours to expose.

And qualified custody is included, not sold separately: an Evidence Certificate issued by a Trusted Third Party, with a verifiable time stamp and an auditable chain of custody. What Expert gives you is the control over when to apply it. You decide, on each analysis, whether it gets sealed.

That control is the point. Sealing creates a permanent, dated record. On an exploratory run against a target you have not bid on yet, or an internal look at your own estate, you may not want one. On the valuation that goes into the data room, you do. Deciding what becomes evidence, and what stays a working document, is your call rather than a consequence of which product you bought.

The frameworks

The standards you can select.

Two different things are being chosen here, and they are worth keeping apart. The compliance frameworks decide what the finished report is expressed against: pick the one your reviewer already works to. The scoring frameworks are the reference models behind each technical dimension, so you can see what the score is measured against rather than take the number on trust.

Compliance · what the report is expressed against

  • OWASP Application Security Verification Standardv5.0.0
  • SOC 2: Trust Services Criteriav2017-tsc

Scoring · what each dimension is measured against

  • Diátaxisv2023Documentation

    Diátaxis documentation framework: tutorials, how-to guides, reference and explanation.

  • ISO/IEC 25010v2011Code quality

    ISO/IEC 25010 product-quality model: Maintainability characteristic.

  • OpenTelemetryv1.0Observability

    OpenTelemetry observability model: logs, metrics, traces and operational readiness.

  • OWASP ASVSv4.0.3Security

    Application Security Verification Standard: verification-requirement-driven security assessment.

  • OWASP SCVSv1.0Dependencies

    OWASP Software Component Verification Standard: dependency and supply-chain verification.

  • OWASP Top 10v2021Security

    OWASP Top 10 (2021) web application security risks.

Working to a standard that is not on this list? Expert includes the option to request it, so the report can still be expressed against the framework your reviewer already uses.

Fit

When to choose Expert.

Funding rounds where the technical diligence is real. Mergers and acquisitions, on either side of the table. Vendor delivery disputes. Any situation where the valuation becomes legal or financial evidence, and where the cost of the number being wrong is measured in millions rather than in hundreds.

Best for: mergers and acquisitions, funding rounds, and any decision where the valuation becomes evidence.

Included.

All features in Pro, plus:

In the report

  • Full Certified Software Valuation: Production Readiness Score, seven technical dimensions, Technical and Economic Valuation
  • Selectable compliance and analysis frameworks
  • Deterministic maintenance cost estimate derived from your infrastructure

How the figure is built

  • Fully deterministic valuation methodology, reproducible on demand
  • Detailed audit trail behind every figure
  • Evidence-based score calibration that credits real engineering rigour

Safeguards

  • Encrypted inference included at no extra cost
  • Qualified custody included: Evidence Certificate sealed by a Trusted Third Party, applied at your discretion on each analysis
  • Challenge any factor: accepted challenges re-run the analysis at no cost, with both versions kept

The commercials

  • Results in under 20 minutes
  • One-off payment, no subscription
Start valuation

from £1,999, one-off payment

Frequently asked questions.

No. Every Codeego analysis is reproducible, on every tier: the metrics come from purpose-built tools, and the AI layer runs at temperature zero with a fixed seed, its judgements clamped to ranges the hard metrics justify. Reproducibility is not something we sell back to you at a higher price.

Two compliance frameworks, which decide what the finished report is expressed against: OWASP Application Security Verification Standard and SOC 2: Trust Services Criteria.

Behind the score sit six reference models, one or more per technical dimension: Diátaxis, ISO/IEC 25010, OpenTelemetry, OWASP ASVS, OWASP SCVS and OWASP Top 10.

Note that the only ISO in the list is ISO/IEC 25010, the product-quality model used to score code quality. It is not a compliance framework and it is not ISO 27001.

An inventory of the infrastructure your codebase actually runs (compute, databases, queues, storage, specialised workloads), converted into a monthly operating cost range by a deterministic schedule. Not a sector benchmark, and not a percentage of the rebuild figure.

Pro seals the valuation. Expert changes how it is produced. They are two different axes, not two rungs.

Pro is Starter with qualified custody switched on: a certified, sealed figure, proportionate for light due diligence. Expert adds the frameworks: you choose the standards the valuation is expressed against, and the report arrives already mapped to them, with an audit trail behind every figure and custody included, applied at your discretion.

Choose Pro when the report needs to be trusted. Choose Expert when somebody is going to check it against a standard.

Yes, at no extra cost. Expert includes everything in Pro, the Evidence Certificate among it.

What Expert adds is control over when it is applied. On each analysis you decide whether the report is sealed. Sealing creates a permanent, independently verifiable record, which is exactly what you want on the valuation that goes into a data room, and not always what you want on an exploratory run against a target you have not bid on. The choice is yours per analysis, not per purchase.

Because of what it saves, not because of what it adds.

Pro gives you a certified figure. Expert gives you that figure already expressed against the framework your reviewer works to, with every number retraceable to the evidence behind it. The alternative is not “buy Pro and lose something”. The alternative is buying Pro and then having someone on your team do the mapping by hand, mid-diligence, against a clock. Measure the price against that afternoon, not against the other tier.

No, and it is worth being exact about this rather than comfortable.

The analysis runs on remote infrastructure. Your code is sent there. What encrypted inference changes is that it is processed under encryption and inside hardware-isolated environments, so nobody can read what you sent at any point.