Skip to main content
NEKOD

PRICING

Simple pricing. No credits. No surprises.

One-Time

For solopreneurs trying NEKOD

€35/ one time
  • All Basic controls, plus:
  • Full hard-coded secrets detection
  • Full security vulnerability scan
  • Full dependency vulnerability alerts
  • Deterministic policy controls
  • GDPR compliance monitoring
  • Findings report

Includes:

Unlimited projects and repos

Unlock Recommended or Advanced without Pro

Pro

Most Popular

Made for teams shipping regularly

€129/ monthly
  • All Basic controls, plus:
  • 100 checks per month
  • Priority support
  • Free re-checks after fixing issues
  • Advanced assessments
  • Remediation guidance
  • Plain-language findings and fix guidance

Includes:

Unlimited apps and repos

Run deeper scans with your monthly checks

Enterprise

For growing teams and agency engagements

  • All Pro controls, plus:
  • Multiple users, teams, and portfolio view
  • Custom policies and governance setup
  • Large repos and custom compliance scope
  • Hands-on assessments and remediation support
  • Team training and enablement

Free

Connect GitHub and run your first scan at no cost.

€0/mo

  • Basic security checks included
  • Plain-language findings report
  • No credit card required

Add-ons & partners

Automated scans. Human backup when you need it.

NEKOD hand-off

Share your repo. Our team runs the assessment and walks you through the results.

What's included:

  • Full security and compliance assessment
  • Findings report and production score
  • Human code review on top of automated checks
  • Live debrief with NEKOD
  • Delivered within 3 business days

Expert help

Hands-on support from vetted specialists matched to your situation.

What's included:

  • Cybersecurity and vulnerability review
  • Compliance and privacy (GDPR, policies)
  • Architecture and data review
  • Remediation guidance for launch blockers
  • You implement; expert advises

Work with a partner

Need engineers, not just a scan? Softup builds and ships complete AI solutions.

What's included:

  • Product development and platform extensions
  • MVP to production implementation
  • Launch delivery and production hardening
  • Integrations and deployment support

ROI calculator

See what manual security review costs you, compared to a NEKOD scan.

Product releases per year

Base

1 product releases / year

Manual audit time

16 hrs

16 hrs per release

Issues to find & fix

10 issues

10 issues per release

Hours per issue (manual)

4 hrs

4 hrs per issue

Total value (est.)

9,200

43 hours saved per year

  • Manual audit & fix time56 hrs · €4,200
  • GDPR inaction risk (est.)€5,000
  • Free tier (1 scan included)€0/yr
  • Time with NEKOD (est.)13 hrs

Estimates use €75/hr builder time and typical vibe-coded app patterns. GDPR inaction risk is illustrative (fines can reach €20M or 4% of turnover). Actual outcomes vary. First scan is free.

Good to know

Frequently Asked Questions

NEKOD provides quality assurance for vibe-coded apps. We run a 360° assessment covering security, data, code quality, documentation, access control, and compliance - then deliver a Launch Readiness Score with prioritized findings and a remediation roadmap. For enterprises, we also help set up an AI-driven development governance framework at scale.

We review your app across five categories: data & database security, code quality, documentation, user access, and policies & compliance. You get a detailed Findings Report, a 360° Risk Radar visualization, and a Launch Readiness Score. The Hosted assessment takes about 3 days; the Full-Stack assessment takes about 5 days.

Our assessments check for GDPR readiness, EU AI Act classification, and alignment with ISO 27001. For regulated industries, we also cover DORA (financial services), PCI-DSS (payments), and NIS2. Each assessment includes a compliance map showing where your app stands.

Especially then. MVPs often handle real user data from day one - which means GDPR applies immediately. A pre-launch assessment catches hard-coded API keys, disabled security policies, missing consent flows, and other issues that are cheaper to fix now than after launch.

You view your findings with prioritized auto-fixes and recommendations in real time in our app or report. From there, you can apply the auto-fixes, or engage us to support you with remediation and fix implementation. Scans can be re-run as often as needed.

No. We keep assessment outputs (findings, scores, scope, metadata). The full repo lives on disk only temporarily during a scan.

Yes. You choose "Only select repositories" at install time.

Not during a normal scan. Fix PRs or hands-on remediation are separate, opt-in engagements.

Only your account (and your org, if you're on a team plan). We treat assessment results as confidential.

Primarily EU (Netherlands). Some subprocessors may process in the US with appropriate safeguards. See our Privacy Policy and subprocessors list.

Revoke the NEKOD GitHub App from GitHub, or remove specific repos from the installation.