Four plans, billed per active repo.
Start free — no card required
Free for the first repo. No card to start.
Connect GitHub, get a draft PR within five minutes. Upgrade only when you're ready — one repo stays free forever.
1 active repo · continuous dependency watch · draft PRs
All tiers ship with SOC 2 / NIS2 / CRA evidence-ready audit trails, the same triage loop, and the same test-gated auto-merge guardrails. Higher plans widen what the agent handles autonomously — and how fast it commits a fix. Bivouac produces the evidence; the certifications are your team's.
1 active repo · no card required
- Continuous dependency watchGitHub repo + lockfile scan against public advisory feeds every five minutes.
- Manual patch PRsAgent opens a draft PR with the chosen SemVer bump and rationale. You review and merge on your terms — no auto-merge scope on Free.
- Standard SLAGoal times from disclosure to fix-attempted, broken down by severity.
Up to 5 active repos
- Continuous dependency watchGitHub repo + lockfile scan against public advisory feeds every five minutes.
- Forward-fix patch PRsAgent opens a draft PR with the chosen SemVer bump, rationale, and pre-pinned references.
- Test-suite gateProject test suite runs on a clean checkout. Red blocks the merge — every widening of the auto-merge scope is opt-in per repo.
- Standard SLAGoal times from disclosure to fix-attempted, broken down by severity. Pages the on-call rotation on contested decisions.
Up to 25 active repos · private advisory feeds
- Continuous dependency watchGitHub repo + lockfile scan against public AND private advisory feeds every five minutes.
- Autonomous patch-and-mergeAgent opens, tests, and merges the patch PR unattended for surfaces your policy pack classifies as routine.Autonomous patch
- Downgrade-as-fixOn a regression or breaking upstream cut, the agent may downgrade or pin instead of forward-fixing — chosen locally, tested, and merged without paging the on-call.Downgrade-as-fix
- Multi-repo policy packsShared guardrails and severity rules across every repo in the org, surfaced in the audit log for evidence.
- Compress SLAGoal times drop on critical severity. Pages only on contested license or security-sensitive surfaces.
SLA add-ons
Unlimited repos · dedicated routing
- Continuous dependency watchPrivate feeds, supply-chain provenance scoring, and registry-level disclosures before your scanner catches up.
- Autonomous patch-and-mergeWidened auto-merge scope with per-repo overrides, captured in the audit log for evidence.Autonomous patch
- Downgrade-as-fixForward fix, downgrade, or pin — chosen by Bivouac on your policy. Regression-class fixes go straight to merge.Downgrade-as-fix
- Multi-repo policy packsOrg-wide guardrails, severity rules, and on-call routing rules. Every widening is opt-in and recorded.
- SBOM provenanceExportable attestation logs aligned with SOC 2, NIS2, and EU Cyber Resilience Act evidence requests — to support your SOC 2, NIS2, and EU CRA evidence workflows, not a Bivouac certification.
SLA add-ons
Usage-based add-ons
SLA add-ons
Pair any tier with an SLA upgrade. Each add-on bills on its own usage curve — pricing finalised once customer contracts are in flight.
SLA add-on
SLA add-on
SLA add-on
Billing, caps, and cycle mechanics
Six questions a buyer should be able to answer before they upgrade.
Plain-language answers about plan changes, what each tier actually unlocks, the monthly cycle, what counts as an active repo, what happens past the cap, and how refunds and downgrades are credited. If something’s missing, ping us — we read every message.