See Your Real Findings Before You Talk to a Single Salesperson
There is a particular kind of friction that kills good security tools before a developer ever gets to see one work. It usually looks like this: a request has to go through procurement, a champion inside the company has to build a business case from a vendor's marketing claims rather than actual results, a security review has to run before anyone touches a real repository, and by the time an engineer finally gets to see their own code scanned, weeks or months have passed and enthusiasm has cooled. The tool that could have proven itself in twenty minutes instead has to prove itself in a slide deck.
Portal's free entry tier exists to remove that friction entirely, for exactly the audience that feels it most: a developer or a small team who wants to know, honestly and immediately, what is sitting in their dependencies.
What you actually get, no strings attached
Signup is free and does not require a sales conversation. Once you are in, you can connect one existing repository from GitHub, GitLab, or Bitbucket, plus one open source repository of your choosing, and run one project scan per month using software composition analysis, SCA. That scope is intentionally narrow. This is not a trial with a countdown clock designed to convert you before you have learned anything; it is a genuinely free, ongoing way to see software composition analysis findings on code that matters to you, one project at a time.
SCA means the scan looks at your full dependency tree, the packages you imported and everything those packages pull in underneath them, and tells you what vulnerabilities are actually present, not just in the libraries you chose directly but in the transitive dependencies most teams never manually audit. For a lot of developers, this is the first time they see the real shape of their dependency risk rather than a guess based on which packages sound risky.
Why this matters more than it looks like it should
Security tooling has a trust problem that is mostly self-inflicted. Every vendor claims their scanner finds more, misses less, and generates fewer false positives than the competition, and there is no way to evaluate that claim except by running the scanner. A free tier that actually works on your own code, rather than a sanitized demo repository chosen to make the product look good, is the fastest way to cut through vendor noise. You are not asked to trust a pitch. You are shown findings on software you already understand, and you can judge for yourself whether they are accurate and useful.
This also changes who gets to start the conversation. Historically, evaluating a supply-chain security platform meant someone in security leadership initiating a procurement process, often based on a category report or a peer recommendation, long before any individual engineer had hands-on experience with the product. Portal's free tier flips that order. An individual contributor, a solo developer, or a two-person startup team can form their own opinion first. By the time a broader security or engineering conversation happens, it can start from evidence rather than assumption: here is what the platform found in our actual code, here is how the reachability analysis narrowed down which findings matter, here is what the interface felt like to use.
A front door, not a demo
It is worth being precise about what this tier is and is not. It is not a stripped-down simulation. The scans are real, the findings are real, and the reachability and prioritization logic that helps cut through vulnerability noise runs the same way it does at higher tiers, just against a narrower slice of your work: one existing repo, one open source repo, one project a month. Think of it as a permanent, low-commitment vantage point rather than a time-boxed trial designed to expire.
For teams that later need broader coverage, deeper scanning modes, or the SAST, DAST, and remediation capabilities that come with the full platform, the free tier is a natural place to start rather than a dead end. The findings you see here transfer directly into a conversation about what a broader deployment would surface across an entire codebase, not just one project.
Bring your own code, and see what is actually there
The best case a security vendor can make for itself is not a slide about detection rates. It is a real scan, on real code, with results a developer can inspect line by line and vulnerability by vulnerability. That is what the free tier is built to offer: no procurement conversation required, no sales call to sit through, just an honest look at what is already living in your dependencies.
If you want to see what your own repository actually contains before anyone tries to sell you anything, sign up at safeguard.sh and connect a repo today. The findings are yours to evaluate on your own terms.