Security operations · Pentest management · Compliance

Your automated security engineer.

CheckAI tells developers what to fix, why it matters and how to fix it. Source tools establish the detections. CheckAI preserves those facts, correlates them, adds contextual business priority, and guides the work to done.

  • Permanent free tier
  • No payment method required
  • No sales call to see a price

What it does

The outcome is not “you have 103 findings”

It is: these are the few things to fix now, here is why, here is how, the work has been created, the fixes will be verified, and the compliance evidence will be updated.

Collect

Public checks and authorized private telemetry from read-only connectors.

Normalize

Findings from different tools deduplicated into one consistent shape.

Correlate

Assets and their relationships mapped, so related findings travel together.

Prioritize

Contextual business priority, held separately from source severity.

Guide

Developer-ready remediation guidance, written for whoever does the fix.

Track

Remediation work created and moved through an explicit status lifecycle.

Verify

Fixes confirmed from later evidence or telemetry, not from a checkbox.

Keep evidence current

Compliance assessments update as the organization’s state changes.

Who it is for

Cloud-native companies without a dedicated security team

Roughly 20–100 people, running on AWS, GitHub, containers and public web applications. The security work is real and the obligations are real, but nobody in the building does it full time.

CheckAI is built to be the function you do not have — not a dashboard that hands you a backlog and calls it visibility.

What CheckAI is not

  • Not another raw vulnerability scanner.
  • Not a cheap clone of a large cloud-security platform.
  • Not an autopilot — connectors are read-only and CheckAI applies no automatic remediation.

Modules

One free platform, three modules you buy separately

Every organization gets the common platform free. The three paid modules are independently purchasable and organization-wide — no paid module requires another, and authorized shared data is reused between active modules rather than duplicated.

Security Operations

USD 189 / month

or USD 1,890 per year, prepaid

  • Multiple verified domains with queued scanning
  • DNS, TLS, HTTP headers, email security, RDAP and security.txt checks
  • GitHub, AWS and CI connectors
  • Asset and relationship inventory
  • Normalization, deduplication and correlation
  • Contextual priority, separate from source severity
  • Remediation guidance, work tracking and scheduled reassessment

What it does not do. Connectors are read-only: CheckAI does not dismiss provider findings, modify code or cloud resources, rotate secrets, or apply automatic remediation. No active exploitation, authenticated scanning, port scanning, site crawling or proof-of-concept takeover testing.

Penetration Test Management

USD 229 / month

or USD 2,290 per year, prepaid

  • PDF upload with malware scanning and OCR
  • AI extraction into structured findings, with human review before anything imports
  • Source severity and tester wording preserved
  • Contextual priority held separately
  • Status lifecycle and remediation-status reports
  • Controlled access to the source PDF
  • Share an approved final report with an Auditor

Limits. One PDF per upload, maximum 50 MB, 300 pages and 500 imported findings. No batch upload. No report versioning or retest management — retests happen outside CheckAI and you update finding status. AI extraction uses your own provider credentials.

Compliance Automation

USD 629 / month

or USD 6,290 per year, prepaid

  • Exploration of any framework, standard, regulation or customer-defined requirement set
  • Workspaces pinned to an exact version
  • Four independent control dimensions
  • Evidence with immutable revisions and freshness tracking
  • AI-identified potential conflicts, which CheckAI never resolves for you
  • Calculated gaps, actions, and approval producing an immutable snapshot
  • Auditor workspace and compliance reports

Source basis. CheckAI includes built-in content only where it has a lawful basis to redistribute it. For proprietary standards such as ISO 27001 you supply an authoritative copy you are licensed to use, which CheckAI processes privately within your organization. Where no adequate source exists, CheckAI gives clearly labelled exploratory guidance and does not invent official structure or control numbering.

Complete Bundle — USD 919 monthly / USD 9,190 annual

The Bundle grants all three module entitlements through one discounted commercial product. It is not a fourth functional module. Bought separately the three total USD 1,047 monthly or USD 10,470 annually, so the Bundle saves USD 128 monthly or USD 1,280 annually — approximately 12.2%.

One 3-day Complete Bundle trial per organization: no payment method, no automatic conversion, and it starts only by explicit Admin action. Your own AI provider credentials are still required for AI features during the trial.

Free forever

The common platform is free Permanent

Every organization starts on Free and stays there indefinitely, whether or not a trial is ever taken or a module is ever purchased. No payment method is required and it is not a time-limited trial.

Organization and people

Account registration and membership; Admin, Contributor, Viewer and Auditor roles; organization profile; Modules & Billing; basic audit history.

One verified domain

Continuous passive monitoring of one verified root domain and its www hostname, verified by domain email — no DNS record or file upload needed. Automatic scan every seven days, plus one manual rescan per organization every 24 hours.

Discovery and preview

Deterministic framework discovery, AI-provider configuration, and the public scan preview. Results use Pass, Warning, Fail and Unknown — category summaries and counts, never a misleading single security score.

Pricing

Published prices. Organization-wide, never per seat.

Both billing intervals are shown together. Annual billing charges ten monthly payments for twelve months.

CheckAI list prices in USD. Prices are organization-wide and tax-exclusive where legally permitted; tax is calculated at checkout.
Product Monthly Annual, prepaid
FreeUSD 0USD 0
Security OperationsUSD 189USD 1,890
Penetration Test ManagementUSD 229USD 2,290
Compliance AutomationUSD 629USD 6,290
Complete Bundle — all threeUSD 919USD 9,190
EnterpriseQuotedQuoted

Free

Monthly
USD 0
Annual
USD 0

Security Operations

Monthly
USD 189
Annual
USD 1,890

Penetration Test Management

Monthly
USD 229
Annual
USD 2,290

Compliance Automation

Monthly
USD 629
Annual
USD 6,290

Complete Bundle — all three

Monthly
USD 919
Annual
USD 9,190

Enterprise

Monthly
Quoted
Annual
Quoted

The commercial rules

  • Prices are organization-wide, never per seat.
  • Unlimited organization members. People are never counted.
  • No commercial quota on assessments, pentest uploads or generated reports — technical, concurrency, rate, safety and fair-use controls still apply.
  • List prices cover up to 500 billable assets for Security Operations and the Complete Bundle. Penetration Test Management and Compliance Automation carry no asset threshold.
  • Annual billing is ten monthly payments for twelve months.
  • Prices are tax-exclusive where legally permitted; tax is calculated at checkout.
  • AI provider usage is paid by your organization directly to your provider. CheckAI does not resell it or mark it up.
  • No mandatory setup fee.
  • Best-effort email support is included. See the support terms.
  • Payment is by card through Stripe-hosted checkout.

What counts as a billable asset

A billable asset is a distinct target that generates its own assessment or collection cycle. It is a narrower set than the full inventory CheckAI builds for you — most of what appears in your asset list is never billable.

Counted

  • A verified domain or discovered hostname under active assessment
  • A compute workload — an EC2 instance, an ECS or EKS service, a Lambda function, or an RDS instance
  • A source repository under active assessment
  • A container image under active assessment
  • An identity-provider tenant

Never counted

  • Packages and dependencies — enumerated inside a repository sync
  • Configuration and network objects — security groups, network interfaces, VPCs, IAM policies, KMS keys, CloudTrail and Config metadata, S3 bucket configuration
  • Registries, and logical application or service groupings
  • People and identities of every kind — users, service accounts, cloud roles and API identities

Kubernetes and other ephemeral compute is counted as services or task definitions, never as running pods or instances — so autoscaling never changes your bill. Your current billable count is shown in the product, against the 500 included.

When we quote instead

We quote an organization running more than 500 billable assets, because a larger estate consumes proportionally more scanning and collection. We also quote where you need negotiated contract terms, a data processing addendum beyond our standard route, a support SLA, SSO/SAML, or custom engineering work.

Crossing 500 assets never stops your scans, never removes a capability and never silently excludes an asset from assessment. It starts a conversation, not an outage. Email us about a quote.

Security and trust

What CheckAI actually does with your data and access

Written to survive an enterprise security questionnaire, rather than to sound reassuring.

Data handling

  • Tenant isolation with row-level security and organization-scoped access.
  • Encryption at rest and in transit.
  • Private object storage with short-lived authorized retrieval.
  • Managed PostgreSQL with point-in-time recovery and tested restoration.
  • Background-job isolation.

Access model — connectors are read-only

The GitHub permission set and the AWS least-privilege boundary are documented, including what is deliberately excluded:

  • No secret retrieval or decryption.
  • No S3 object access.
  • No command or session execution.
  • No Lambda invocation.
  • No CloudTrail event bodies.
  • No database access.

AI is bring-your-own-key

Your credentials, your provider account, your data terms with that provider. CheckAI does not resell AI usage or hold provider credit. Credentials are encrypted, never returned to the browser and never logged. The interface identifies the provider and model before sensitive content is transmitted.

Accounts and subprocessors

MFA is mandatory for Admin and Contributor roles. Our subprocessors:

  • AWS
  • Stripe
  • Amazon SES
  • Cloudflare

Retention and deletion are stated in plain customer terms in our legal documents.

What we do not claim

CheckAI holds no security certification and claims none. We do not claim that generated PDFs are PDF/UA conformant, and we do not claim that audit records are immutable or tamper-proof. If a control is not implemented, it is not on this page.

Contact and support

Talk to us

Enterprise quotes, security reports, billing questions, or anything else. We read everything that arrives, and security reports go first. Our support terms set out what we do and do not commit to.

What you can use this for

  • A general question, or an Enterprise quote
  • A security or vulnerability report
  • Billing, refund or cancellation questions
  • A domain ownership dispute
  • A personal-email approval review
  • An MFA recovery request
  • A data-deletion or legal request
  • A feature request

We use this only to reply to you.

Start on Free, with no payment method

Create an organization, verify one domain, and see what CheckAI finds. Add modules when and if they earn it.