GuardAPI

USD · billed monthly via Stripe

A merge gate, not a scan quota.

14-day trial on one repository. Then Team or Scale. Runs are unlimited because the engine uses your GitHub minutes, not ours.

Trial

$0

  • 14 days
  • 1 repository
  • Unlimited PR runs in your CI
  • Same fail rule as paid plans
Start trial

Team

$199/mo

  • 3 repositories
  • SARIF + job failure on proven leak
  • Dashboard evidence (redacted)

Scale

$499/mo

  • Unlimited repositories
  • Written evidence pack for access-control audits (export of verdicts, not a SOC 2 Type II certification)
  • Priority onboarding

You must be signed in. Stripe Checkout applies a 14-day trial on paid plans in code. No annual SKU, no seat licenses, no scan credits.

If you are comparing this to something else

Why not AuthzTrace / overstep / AuthProbe?

Those OSS runners prove the algorithm is not a secret. They need a contract or matrix you maintain, and they do not give you a 14-day dashboard. Use them if you want to own the YAML forever. Use GuardAPI if you want OpenAPI pairing, a conservative fail rule, SARIF, and evidence without writing the matrix. Fair comparison: GuardAPI vs OSS authorization testers.

Why not APIsec / StackHawk / Escape?

They cover more than GET BOLA and they cost more (APIsec Standard is published at $690/mo per 100 endpoints; Escape Enterprise starts at $50k/yr on AWS Marketplace as of 2026). If you need GraphQL DAST, agentic pentest, or runtime discovery, buy them. GuardAPI is one check.

We already have RLS / Snyk / a pentest on the calendar

RLS does not prove the HTTP handler. Snyk does not log in as two tenants. A yearly pentest finds last quarter’s IDOR. This gate runs on the PR that introduced GET /invoices/{id}.

Unit tests with two users

Keep them. They miss routes that are in OpenAPI but not in the test suite. This Action walks the spec graph (capped at 40 pairs) every PR.