Seats drift because access is easy to grant and nobody audits it. Then the second meter arrives: CI minutes, build runners, monitor runs and AI assistants are all billed apart from the licence they sit beside.
GitHub, GitLab and Bitbucket all meter build minutes separately from seats. A busy pipeline can exceed the seat bill entirely — and nothing in the platform warns you before the invoice does.
Already decided — What this page decides
Still yours to weigh
Thirteen products across four jobs. Four are platforms or source control — where the code lives and how it ships. Four are API lifecycle tooling. Three are infrastructure and secrets, adjacent to the pipeline rather than inside it. And two are AI assistants, licensed separately from the platforms they run in.
Application security appears here as a section, not a route: SAST, dependency and secrets scanning ship inside the SCM platforms and are compared below. Runtime and cloud posture — CNAPP, WAF — are a different purchase entirely and live on the Security and Network Security categories, cross-linked and not repeated here.
The row to get exactly right
The licence unit, and the second meter beside it. GitHub, GitLab, Atlassian and Postman price per user; Terraform meters managed resources; Vault meters clients; JetBrains licenses per named user or a floating pool. Then CI minutes, runners, monitor runs and AI seats are billed apart. Model the total, never the per-seat rate.
Often confused withObservability & APM — proving it works under real traffic →·Databases & Data Tools — the schema change the pipeline ships →·Cloud & Workload Security — CNAPP, the runtime half of scanning →
These are not tiers. A DevOps platform is not source control done better — it is four purchases bundled, and whether that is cheaper depends entirely on how many of the four you would otherwise buy.
SCM vs CI/CD
Where the code lives, or what happens when it changes?
SCM vs DevOps platform
One vendor, or best-of-breed?
IDE licensing vs seat licensing
Who is the licence attached to?
Secrets management vs configuration
A credential, or a setting?
Seven variables move the shortlist.
One platform or best-of-breed
GitLab's case is strongest when you use most of it. Using SCM and CI alone means paying for planning and scanning you do not touch.
CI/CD minutes and runner costs
Metered separately everywhere, and frequently larger than the seat bill. Self-hosted runners trade the meter for machines you operate.
Self-hosted or SaaS
The documented route to India residency for GitHub Enterprise Server and GitLab self-managed. It moves upgrades onto your team.
The licence unit
Named user, concurrent, floating or per-organisation. JetBrains and Atlassian differ sharply from GitHub and GitLab here.
AI assistant bundling
The fastest-moving variable in this category. Generous in the trial, itemised at renewal — model the tier plus the assistant.
Pipeline security scanning
SAST, dependency and secrets scanning are in the platform tiers. Runtime and cloud posture are a different purchase entirely.
Contractors and occasional committers
Every model treats them differently, and this is where seat counts drift furthest from headcount.
Pick the job and the way it has to bill. Products drop out with the reason stated, never silently.
What you need it to do
How it has to run
How it bills
India
India residency is annotated rather than used to eliminate: no vendor here documents an Indian SaaS region, and for most of them self-hosting is the documented route.
per user / month for the platform, with GitHub Actions CI metered separately in minutes and Advanced Security licensed as an addition; Enterprise Cloud or Enterprise Server for self-hosting
Teams that want the largest ecosystem, the deepest third-party integration and the hiring advantage of the tool most developers already know.
The catch: Three meters on one platform: seats, Actions minutes and Advanced Security. The minutes line is the one that surprises — a busy monorepo pipeline can exceed the seat bill without anybody noticing until the invoice.
per user / month, published tiers, licensed separately from GitHub Enterprise; code completion, chat and agentic assistance inside the editor and the pull request
Teams where the measurable win is time-to-first-draft on routine code, and where the editors in use are supported.
The catch: A separate line at renewal, however generous the trial was. Seat counts drift upward faster than developer headcount because access is easy to grant and nobody audits it.
per user / month across Free, Premium and Ultimate, with CI minutes metered separately; SCM, CI/CD, security scanning, packages and planning under one licence — Ultimate carries the full scanning set
Estates that want one vendor and one bill across the whole toolchain rather than integrating four products — and self-managed installation where India residency requires it.
The catch: The single-platform case is strongest when you use most of it; teams using SCM and CI alone pay for planning and scanning they do not touch. Self-managed means you own the upgrades, which is a standing job.
per user / month as an addition to a GitLab tier; AI code suggestions, chat, vulnerability explanation and merge-request summaries inside the platform
GitLab estates that want AI assistance without introducing a second vendor's tooling and a second data-handling conversation.
The catch: An add-on rather than an inclusion — the same renewal surprise as Copilot. Capability depends on the underlying GitLab tier, so the comparison is tier-plus-Duo against a rival's equivalent.
per user / month with Pipelines build minutes metered separately; source control that shares identity, permissions and issue linking with Jira
Organisations already standardised on Jira that want source, branches and pull requests linked to the work item without an integration to maintain.
The catch: A smaller ecosystem than GitHub or GitLab, and the strongest case assumes Jira. Atlassian pricing steps at user-count thresholds, so crossing one costs more than the extra seats suggest.
per user / month across Free, Standard, Premium and Enterprise, published; issue tracking and planning for software teams, linked to the branch and the deployment
Engineering organisations that need the work item, the branch and the release connected — the planning half of the toolchain rather than the code half.
The catch: Planning, not source control or CI. Pricing steps at user-count thresholds and the jump is the thing to model — crossing 100 users is not a linear increase.
per user / month with a free tier; the client most API developers already have open — requests, environments, collections and history
Any team building or consuming APIs, which is nearly all of them — this is usually already in use before it is ever purchased.
The catch: The free tier is genuinely capable, so the paid case is collaboration and governance rather than the client itself. Shadow usage on free accounts is common and worth auditing.
within the per-user Postman tiers; schema-first API design with OpenAPI, mocking and documentation generated from the contract rather than written after it
Teams where the API contract needs agreeing before implementation — typically where a separate team consumes it.
The catch: Design-first is a working practice more than a product: without the discipline, the tool produces schemas nobody updates. Value depends on adoption, not licences.
within the per-user tiers, with monitor runs metered separately; automated API tests that run in CI and on a schedule against live environments
Teams whose integration failures are found by customers rather than by the pipeline.
The catch: Scheduled monitor runs are a separate meter from seats — small, but a second meter nonetheless. It tests the API, not the user journey through the interface.
in the Enterprise per-user tiers; API standards enforcement, secret detection in collections, and visibility of every API the organisation has published
Organisations with more APIs than anyone can list, and no consistent standard across teams.
The catch: Governance is only as real as the enforcement: rules that warn rather than block are ignored within a quarter. Enterprise-tier only.
HCP Terraform priced per managed resource per month with a free tier; Terraform Enterprise self-hosted on quote — infrastructure as code with state management, policy and a run history
Teams whose infrastructure changes should be reviewed, versioned and repeatable rather than clicked in a console.
The catch: The per-managed-resource meter means the bill tracks infrastructure sprawl, not team size — a resource nobody uses still counts. IBM-owned since 2025, which some estates weigh in a multi-year commitment.
quoted on active clients for HCP Vault or Vault Enterprise; centralised secrets with dynamic credentials, rotation and an audit trail — the machine-identity half of the toolchain
Estates where credentials currently live in CI variables and configuration files, and somebody has finally asked who can read them.
The catch: Client-based metering is hard to forecast, because a client is any application or workload that authenticates. Vault is also an operational commitment: it becomes a critical dependency the day you adopt it.
quoted per service instance; service discovery, health checking and service-mesh networking with mutual TLS between services
Estates running many services across environments where discovery and service-to-service encryption are the operational gap.
The catch: A service mesh is a serious architectural commitment with its own failure modes, and many estates adopt one before they need it. If service count is modest, native platform networking is usually enough.
one platformRules out Atlassian Bitbucket, Postman API Client, Postman API Design, Postman API Testing, Postman Governance, HashiCorp Terraform, HashiCorp Vault and HashiCorp Consul — one layer of the toolchain, not the whole platform. That leaves GitHub Enterprise, GitHub Copilot, GitLab DevSecOps Platform, GitLab Duo and Atlassian Jira.
pipeline scanningRules out GitHub Copilot, GitLab Duo, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing, HashiCorp Terraform and HashiCorp Consul — no pipeline security scanning; Atlassian Bitbucket, Postman Governance and HashiCorp Vault — one scanning type only, not the SAST + dependency + secrets set. That leaves GitHub Enterprise and GitLab DevSecOps Platform.
API toolingRules out GitHub Enterprise, GitHub Copilot, GitLab DevSecOps Platform, GitLab Duo, Atlassian Bitbucket, Atlassian Jira, HashiCorp Terraform, HashiCorp Vault and HashiCorp Consul — not API-lifecycle tooling. That leaves Postman API Client, Postman API Design, Postman API Testing and Postman Governance.
infrastructure and secretsRules out GitHub Enterprise, GitHub Copilot, GitLab DevSecOps Platform, GitLab Duo, Atlassian Bitbucket, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing and Postman Governance — not infrastructure or secrets tooling. That leaves HashiCorp Terraform, HashiCorp Vault and HashiCorp Consul.
self-hostingRules out GitHub Copilot, Atlassian Bitbucket, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing and Postman Governance — SaaS only, so India residency cannot be met by deployment choice. That leaves GitHub Enterprise, GitLab DevSecOps Platform, GitLab Duo, HashiCorp Terraform, HashiCorp Vault and HashiCorp Consul.
AI assistanceRules out Atlassian Bitbucket, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing, Postman Governance, HashiCorp Terraform, HashiCorp Vault and HashiCorp Consul — no AI assistant documented for this product. That leaves GitHub Enterprise, GitHub Copilot, GitLab DevSecOps Platform and GitLab Duo.
per-seat pricingRules out HashiCorp Terraform — consumption-metered: the bill tracks resources, not people; HashiCorp Vault and HashiCorp Consul — quote-only, and metered on clients or services rather than seats. That leaves GitHub Enterprise, GitHub Copilot, GitLab DevSecOps Platform, GitLab Duo, Atlassian Bitbucket, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing and Postman Governance.
no metered minutesRules out GitHub Enterprise, GitLab DevSecOps Platform and Atlassian Bitbucket — CI minutes are metered separately and routinely exceed the seat bill. That leaves GitHub Copilot, GitLab Duo, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing, Postman Governance, HashiCorp Terraform, HashiCorp Vault and HashiCorp Consul.
published pricingRules out HashiCorp Vault and HashiCorp Consul — quote-only. That leaves GitHub Enterprise, GitHub Copilot, GitLab DevSecOps Platform, GitLab Duo, Atlassian Bitbucket, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing, Postman Governance and HashiCorp Terraform.
an Indian regionRules nothing out on published terms. It flags GitHub Enterprise — No Indian SaaS region is documented, GitHub Copilot — No Indian region is documented and there is no self-hosted option, GitLab DevSecOps Platform — No Indian SaaS region is documented, GitLab Duo — No Indian SaaS region is documented, Atlassian Bitbucket — No Indian region is documented and there is no self-hosted option, Atlassian Jira — No Indian region is documented and there is no self-hosted option, Postman API Client — No Indian region is documented and there is no self-hosted option, Postman API Design — No Indian region is documented and there is no self-hosted option, Postman API Testing — No Indian region is documented and there is no self-hosted option, Postman Governance — No Indian region is documented and there is no self-hosted option, HashiCorp Terraform — No Indian SaaS region is documented, HashiCorp Vault — No Indian SaaS region is documented and HashiCorp Consul — No Indian SaaS region is documented — marked on the cards, not removed.
The minutes are the surprise, not the seatsGitHub Actions, GitLab CI and Bitbucket Pipelines all meter build minutes separately from the seat licence. A busy monorepo with a matrix build can exceed its seat bill without anybody noticing until the invoice — and the fix is pipeline discipline, not a different vendor.
Seat counts drift upward, quietlyAccess is easy to grant and nobody audits it. Contractors, occasional committers and people who left the team last quarter all count. Audit against actual commit activity before every renewal; it is the cheapest saving in this route.
AI assistants are bundled in the trial, itemised at renewalCopilot and GitLab Duo are both separate licences however the pilot was framed. Model the platform tier PLUS the assistant when comparing vendors, because that is the number you will pay in year two.
JetBrains is carried but not ranked hereTechBag sells JetBrains licences and it belongs in this route. There are no intel pages yet, so it is named and not ranked rather than silently omitted. Its licence unit differs materially from everything carded here — per named user or a floating pool, which changes the maths for teams with part-time or shift-based developers.
If one of these is your sentence, the shortlist is short.
Why: SCM, CI, packages, scanning and planning under one licence and one renewal conversation.
The trade-off: You pay for the whole platform whether or not you use the whole platform. Price it against what you would otherwise buy.
Why: Self-hosting is the documented residency route — no vendor here publishes an Indian SaaS region.
The trade-off: Somebody owns upgrades, backups and availability. That role is the real cost, and it is usually unassigned at signature.
Why: Both support self-hosted runners, which trades the per-minute meter for machines you already pay for.
The trade-off: Self-hosted runners are infrastructure you now maintain and secure — and a compromised runner is a supply-chain problem.
Why: Shared identity, permissions and issue linking with no integration to build or maintain.
The trade-off: Smaller ecosystem than GitHub or GitLab, and Atlassian pricing steps hard at user-count thresholds.
Why: An inventory of every published API plus enforceable standards across teams.
The trade-off: Enterprise tier, and governance that warns rather than blocks is ignored within a quarter.
Why: Centralised secrets with dynamic credentials, rotation and an audit trail of who read what.
The trade-off: Client-based metering is hard to forecast, and Vault becomes critical infrastructure the day you adopt it.
Why: Infrastructure as code with state, policy and a reviewable run history.
The trade-off: Per managed resource, so the bill tracks infrastructure sprawl rather than team size — unused resources still count.
Why: Both are per-seat add-ons to their platform; the honest comparison is platform tier plus assistant, not assistant alone.
The trade-off: A separate line at renewal however the trial was framed, and seat counts drift upward faster than headcount.
Application security is a section here, not a route, because the bench is thin and the products are modules of platforms carded elsewhere. Three kinds of scanning ship inside the SCM platforms above:
GitHub carries all three in Advanced Security (an additional licence); GitLab carries the full set at Ultimate. The boundary is the deploy: everything above happens before it. Container and cloud posture scanning happens after, is a different purchase, and lives on Cloud & Workload Security. Web application firewalls are further out still and belong to Firewall & Network Security. Neither is carded here.
On JetBrains. TechBag carries JetBrains licences and they belong in this route. There are no intel pages for them yet, so JetBrains is named and not ranked rather than quietly left out — the same treatment given to SailPoint, Cato and Zerto elsewhere on this site. What matters commercially is that its licence unit is different from everything carded above: per named user, or a floating pool shared across a team. For an estate with contractors, shift work or part-time developers, a floating pool can be materially cheaper than per-seat SCM licensing, and the two models cannot be compared line-for-line. Ask us for a JetBrains quote alongside any shortlist here.
Ask before signature
This route scales by developers — and by pipeline volume, which is not the same number.
Under 20 developers
Put this in your PoC
Prove the minutes against your real pipeline before paying.
20–100 developers
Put this in your PoC
Audit seats before every renewal. It is the cheapest saving here.
100–500 developers
Put this in your PoC
Model the tier jump, not the per-seat rate.
500+ developers
Put this in your PoC
Name the owner for the self-hosted upgrade path before choosing it.
Where a vendor does not publish list pricing, this page says so rather than implying a figure.
Git is portable. Everything built around it is not.
Repositories and history
Git is distributed by design — a clone is a complete copy
Pipeline definitions
Vendor-specific YAML, rewritten for the new platform
Issues, boards and pull-request history
Exportable via API; the discussion context rarely survives intact
Secrets and IaC state
Vault and Terraform state are portable with planning, catastrophic without it
The practical consequence: the code is never the lock-in. The pipelines, the scanning configuration and the accumulated review history are, and none of them appear in a switching-cost estimate.
Per seat, plus the meters beside it, in USD and INR.
Four checks, in the order most likely to return a yes.
The free tiers here are unusually strong. The paid case is compliance, support and scale rather than capability.
One meter you expect, and several you do not.
TechBag quotes every one of these in INR with GST, and models your actual volumes against each meter rather than comparing rates. Where a vendor publishes no list price, this page says so instead of repeating a third-party figure.
TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale at ≈₹83/$; the tier-matched INR quote is ours.
Metered separately everywhere, and routinely larger than the seat bill on a busy pipeline.
Copilot and Duo are separate licences however generous the trial was.
Upgrades, backups, availability and runner security. A role, not a line item.
Access is easy to grant and nobody audits it. Check against commit activity, not the directory.
Five ways this purchase goes wrong. Four of them are meters nobody modelled.
CI/CD minutes exceeding the seat bill
A matrix build on every push, on a busy monorepo. The fix is pipeline discipline and self-hosted runners, not a different vendor.
Seats counted per repository access rather than per active developer
Contractors, occasional committers and people who left all count. Audit against commit activity before every renewal.
Self-hosted chosen for residency, then nobody owns the upgrades
The residency requirement is met on day one and the platform is three versions behind by year two. Name the owner at signature.
The AI assistant licensed separately at renewal
Bundled generously in the trial, itemised afterwards. Compare platform tier plus assistant, not the tier alone.
Atlassian tier jumps at user-count thresholds
Crossing a threshold is not a linear increase. Model the jump before hiring past it.
Vendor-neutral. No gated content. · Last reviewed