All versions
v2.0.0Comté seriesCurrent2026-07-22

zkao 2.0: Pay As You Go, and a New Look

Billing is now pure pay-as-you-go: buy prepaid credits, pay only for what a scan uses, and your credits never expire. No subscriptions. zkao also gets a dark theme, a refreshed look, and redesigned home, repository, and scan pages. Our analysis flows keep getting sharper.

Version 2.0 changes two things at once. Billing is now pure pay-as-you-go: buy prepaid credits, set a budget for each scan, and pay only for what a scan actually uses. And zkao has a new look, including a full dark theme and rebuilt home, repository, and scan pages. Our analysis flows keep getting sharper too.


One simple credit balance

We have replaced subscriptions with a single prepaid credit balance:

  • Buy credits when you need them. Top up with a credit bundle. There is no monthly plan to pick and no billing cycle to track.
  • Your credits never expire. They sit in one balance and are there whenever you want to scan, whether that is today or six months from now.
  • Pay only for what a scan uses. Set a per-scan budget; we never charge above it, and you only pay for the credits the analysis actually consumes. If a scan runs over your cap, we absorb the difference.

Your existing credits carried over

If your project was on a subscription plan, there is nothing you need to do. All of your credits, including any granted by your plan, moved straight onto your new pay-as-you-go balance. Nothing was lost, and they now never expire. You will see this reflected in your billing activity.

Spend controls

Two new controls give you a clear ceiling on what a project can spend:

  • Monthly budget. Cap how many credits a project can spend per calendar month, get alerted as spend approaches the cap, and optionally block new scans once it is reached.
  • Auto top-up. Turn it on and we buy more credits automatically when your available balance drops below a threshold you choose, so scanning keeps running without anyone remembering to top up. You stay in control of the threshold, the amount, and how often it can fire.

A billing page that shows your ceiling

The project billing page now makes your spending ceiling obvious at a glance. Your balance shows what is available versus what running scans have reserved, tiles cover this month's and last month's spend against your monthly budget, and one plain sentence states how many more credits scans can spend before they stop. If auto top-up is on without an enforced monthly budget, the page flags that there is no ceiling on scan spend at all. Every entry in your billing activity now reads in plain language too.

Project admins can also export the ledger as a CSV, straight from the billing activity card. Each row carries the date, what the movement was, the credit amount, the balance after it, and the scan a charge belongs to, so you can keep the record outside the app or reconcile spend in your own spreadsheet.

A dark theme, and a fresh look

zkao now has a full dark theme. Every surface is designed for it rather than recolored: cards, tables, charts, and the severity colors on findings all have their own dark values, so critical and high still read as critical and high. A switcher in the top bar lets you pick light, dark, or follow your system setting, and your choice is remembered as you move around the app. Shared public reports and anything you print always render light, so an export looks the same for everyone you send it to.

The rest of the app was refreshed alongside it. Headings, page titles, and card titles use a distinct typeface, with a monospaced one for code, commit hashes, and finding ids, so a page's structure is easier to scan. The sidebar is cleaner, with simpler nav rows and a clearer indication of where you are. Each project header is now a card with a proper breadcrumb, so from a repository or scan page you can see where it sits and click back up.

Your repositories, ranked by risk

The Repositories page is now a health board instead of a flat table. Each repository gets a card with a verdict at a glance, critical through low, all clear, or never scanned, based on the findings you still have open. The card breaks those findings down by severity and shows the branch, the last scan, how many scans have run, and how many findings you have already resolved. A repository being scanned right now says so live.

Repositories are ordered most urgent first, the header tells you how many need attention, and you can search by name or sort by risk, last scan, or name. A repository that has never been scanned sorts last and offers a direct "Run first scan" action, so it reads as a setup task rather than a risk reading.

A dashboard for every repository

Opening a repository now answers what to do next. A status band at the top tells you whether the current commit is covered by the latest scan, next to your open findings, your criticals, how long it has been since the last scan, and a prominent Run scan button.

Below it, a triage table lists findings with Open, All, and Resolved tabs, showing severity, location, resolution state, and whether a finding has been confirmed. Two compact meters roll up the repository's severity mix and where its findings sit in the triage lifecycle, with every count linking straight into the Findings tab. Scan history sits underneath. A side rail keeps the questions scans have raised, your repository guidance, automations, and recent activity on the repository's findings within reach.

The "needs review" badge now counts every finding nobody has triaged yet, so a real backlog no longer stays hidden. And if the latest scan ran on an older version of zkao, the page says so.

A home page that leads with what needs you

Signing in now opens on the work rather than a summary. A "Needs attention" queue ranks what is waiting on you: unreviewed critical and high findings, scans that failed, projects that have run out of credits, and questions a scan has raised about your code. Every row names the project and repository it belongs to and carries the action that deals with it.

Underneath, your projects are listed with their open findings broken down by severity, the credits available to each one, and whether it is up to date, due a scan, or scanning right now. A side column keeps the findings that have been open longest, the scans in flight, and recent activity from across every project you belong to. A new Activity page holds the full cross-project history, paged, for when the recent list is not enough.

Watch a scan as it runs

A running scan now shows how far along it is everywhere it appears: your home page, the project dashboard, the repository scan lists, and the scan page itself. The bar is weighted by how much of the work each phase represents, so it no longer jumps from a quarter to nearly finished the moment a short phase ends.

The scan page adds what the scan is working on at that moment, how many credits it has spent against its budget, and a cancel button beside them. There is deliberately no time estimate: how long a scan takes depends on the repository and the guidance it was given, so any figure in minutes would be a guess dressed up as a fact. Scan progress is available through the API too.

A rebuilt scan page

A scan now reads as two columns: the findings on the left, what the scan did on the right.

The findings list groups by where each finding stands, confirmed first, then anything awaiting triage, then whatever was skipped, with severity, status, and a comment count on every row. Filters for severity, and for hiding discarded or recurring findings, sit directly above it.

The right column leads with how the scan finished: how many of its findings were new since the last scan of that repository, and how much of the audit scope it actually read. Below that, each phase sits on a timeline with its duration, what it found, whether its result was reused from an earlier scan, and the files it opened, with a count of how many times each was accessed. The guidance the scan ran with is there as well, so you can see what it was told before reading what it found.

Sharper analysis

Our analysis flows keep improving at the part that matters most: staying on the code worth auditing and confirming real issues instead of noise. Flows including snarksentinel, gestalt, and cryptopsy got better at working through a large codebase in a deliberate order and building a clearer map of it before digging in, so a fresh scan can surface issues earlier passes missed, even on code we have already looked at.

Other changes

  • Cancelling a scan takes effect immediately, including in the first seconds after launch. A cancel that arrived while a scan was still getting set up could previously be missed, letting analysis already under way run to completion and spend credits after you had stopped it.
  • Credits a scan is holding are now always returned to your available balance when it ends, including after an unusual failure or cancellation. Any reservation left hanging is repaired automatically, you are charged exactly what a normal run would have charged, and a settlement never takes your balance below zero.
  • Adding a repository now accepts a GitHub URL pasted straight from your address bar. Anything after a "?" or "#", such as GitHub's own tab links or tracking parameters, is ignored instead of being read as part of the repository name, which used to fail with a misleading message about zkao not having access.
  • Members with the viewer role now see a repository's coverage status and latest commit instead of a message saying they do not have access, and a temporary problem reaching GitHub no longer reads as an access denial.
  • The repository sub-tabs carry badges for unresolved findings and in-flight scans, so you can see outstanding work without opening each tab.
  • Credit top-ups now start at 10,000 credits, and the same minimum applies to auto top-up.
  • The project dashboard's recent scans are now a compact rail showing the repository path, the commit scanned, and the guidance each scan ran with.
  • How much of a repository a scan read is now measured against the scope the scan set out to audit, rather than against every file in the repository, so the figure reflects the work that was actually planned.