Pricing
The Index is free. Always.
Every score, every capability, the whole methodology — free forever. More than 300 of the things we measure are abandoned or deprecated right now. Pro tells you which of them are yours, and what to use instead.
Every finding, in full. You will never learn from us that a risk exists only after paying.
- Every security finding — how many advisories and at what severity, whether it runs a script at install time, what it can reach on your machine
- The full Index — every tashan score and expertise grade, filed by job function
doctoraudits the config you already have, on your machine, no account- Agent endpoints and badges — no key, no quota
no account · no key · no quota
Free tells you something is wrong. Pro tells you what it is and what to do about it.
- The advisory itself — which CVE or GHSA, its severity, the affected range, and the version that fixes it. Not "2 known advisories".
- What the install script actually runs — the exact command, before you run it.
- The replacement, named. Not "this is deprecated" — switch to this one, it scores 65 and is still maintained.
- Every score since we started measuring. trend needs ~30 days · clock restarted 30 Jul
cancel any time in your account · 7-day refund
Questions
What am I paying for today?
Named replacements for anything dead in your config, and the full score history. Trend needs about a month of data before it means anything and we restarted that clock on 30 July when the score was recalibrated — we'd rather say so than let you find out.
Why isn't this free like everything else?
Because it's the one thing that can't be re-derived from today's public data. Every score on the Index is a snapshot anyone could recompute; the series only exists because we recorded it, every day, and a day we miss is gone for good — for us too. That's what $6 buys, and it's worth more every month it runs.
How do I use the key?
tashan activate <key> once per machine, then
tashan doctor as usual — it is stored in ~/.config/tashan/key, so there is no
export to remember and nothing to re-do in a new terminal. Same key on every machine you use. The key is in your
account. Nothing about your
config is uploaded — the CLI reads your local files and asks us only about capability names.
Full details on support.
Do I get an account?
Yes — your account shows your
plan, renewal date, the machines you have activated, your licence key and your invoices. Run
tashan account and it opens already signed in; there is no password to make. Pro also shows
up in your terminal, where doctor prints Pro · licence active on
every run.
How many machines?
Activate each one with the same key — tashan activate <key>
registers it under its hostname, so your account lists exactly what
is active. tashan activate --forget hands a slot back from the machine itself.
Do you sell the capabilities?
No. We sell nothing we measure, host nothing, and take no cut of anything. Every other index in this field either sells the listings, hosts the servers, or earns when you run them — so a low verdict costs them money. It costs us nothing, which is the only reason our verdict is worth reading (see About).
Team or company use?
The data API is live and free — see for hosts. Org-wide auditing of your own internal skills and servers is not built yet; tell us what you need and it shapes what gets built.