Free security for the people who keep the ecosystem running.
Open-source maintainers secure the code the whole industry depends on, and nonprofits do vital work on tight budgets. Safeguard is free for both — the full platform, including reachability analysis, SBOMs, and Griffin AI autonomous remediation, at no cost.
What's included
Full platform, free
SCA, SBOM/AIBOM, container & IaC scanning, reachability analysis, and autonomous Auto-Fix — no feature gates.
Public repo coverage
Continuously scan your public projects and their dependency trees, with fix PRs opened straight against your repos.
SBOMs for your users
Publish CycloneDX/SPDX SBOMs so downstream consumers and enterprises can trust and adopt your project.
Maintainer-friendly
Low-noise, reachability-prioritized findings — so you spend time maintaining, not triaging false positives.
Nonprofit-ready evidence
Compliance-aligned reports and SBOMs for grant, donor, and audit requirements.
Academy access
Free Safeguard Academy courses and certifications for your contributors and staff.
The program in detail
Maintainers of public, OSS-licensed repositories. Free scanning for public projects, generous limits, a security badge and published SBOM for your repo.
What is included
- Scanning for your public repositories, with generous limits
- Dependency analysis, and an SBOM in CycloneDX or SPDX
- Reachability-based prioritization, so you fix what is actually exploitable
- A security badge for your README and a published SBOM for the repo
- Autonomous fix PRs are limited on this program
Who qualifies
- Public, OSS-licensed repositories only. Private repositories need a paid plan
- We re-check periodically that the repository is still public and maintained
- Not for commercial closed-source work
How we verify
Links your public repository so we can confirm it is OSS-licensed.
Renewal and what comes next
Runs for as long as the repository stays public and maintained, re-checked periodically. Private repositories move to a paid plan, and you keep your history.
Every program starts with the eligibility form. Nothing is granted without it.
Who qualifies
- Maintainers of public open-source projects under an OSI-approved license.
- Registered nonprofits, NGOs, and charities (501(c)(3) or local equivalent).
- Public-good and civic-tech projects run by volunteers.
- Projects and organizations that are not primarily commercial.
How to get started
Apply
Share a link to your public repo(s) or nonprofit registration.
Verification
We confirm the project's license or the organization's nonprofit status.
Activate
Your free license is enabled; connect your repositories in minutes.
Publish trust
Ship SBOMs and a clean security posture your users can rely on.
Frequently asked questions
Which open-source licenses qualify?
Any OSI-approved license (MIT, Apache-2.0, GPL, BSD, MPL, and others). The project must be genuinely public and open source, not source-available or commercial with an OSS veneer.
Is it free forever?
The open-source and nonprofit licenses are free for as long as you remain eligible. If a project becomes a commercial product, we'll help you transition to a standard plan.
Do nonprofits need to be US-based?
No. Registered nonprofits, NGOs, and charities worldwide qualify — 501(c)(3) in the US or the equivalent registration in your country.
Can I scan private repos under this program?
The OSS program covers your public projects. Nonprofits can cover their internal/private repositories used to run the organization. For broader commercial private use, a standard plan applies.
Ready to start?
Apply for a free licenseSelf-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.