Seats drift because access is easy to grant and nobody audits it. Then the second meter arrives: CI minutes, build runners, monitor runs and AI assistants are all billed apart from the licence they sit beside.
GitHub, GitLab and Bitbucket all meter build minutes separately from seats. A busy pipeline can exceed the seat bill entirely — and nothing in the platform warns you before the invoice does.
Already decided — What this page decides
Still yours to weigh
Thirty-five products across six jobs. Four are platforms or source control — where the code lives and how it ships. Seven are code quality, security and testing tools — the checks every pull request must pass before it merges, and the functional and load tests a release must pass before it ships. Seven are artifacts and supply chain — the repository every build reads from, and the scanning, blocking and curation of what it holds. Nine are API lifecycle tooling — clients, design, testing, and the gateways API and AI traffic run through. Five are infrastructure, secrets and service mesh, adjacent to the pipeline rather than inside it. Three are AI assistants, licensed separately from the platforms they run in.
Application security appears here as a section, not a route: SAST, dependency and secrets scanning ship inside the SCM platforms and are compared below. Runtime and cloud posture — CNAPP, WAF — are a different purchase entirely and live on the Security and Network Security categories, cross-linked and not repeated here.
The row to get exactly right
The licence unit, and the second meter beside it. GitHub, GitLab, Atlassian and Postman price per user; Terraform meters managed resources; Vault meters clients; JetBrains licenses per named user or a floating pool. Then CI minutes, runners, monitor runs and AI seats are billed apart. Model the total, never the per-seat rate.
Often confused withObservability & APM — proving it works under real traffic →·Databases & Data Tools — the schema change the pipeline ships →·Cloud & Workload Security — CNAPP, the runtime half of scanning →
These are not tiers. A DevOps platform is not source control done better — it is four purchases bundled, and whether that is cheaper depends entirely on how many of the four you would otherwise buy.
SCM vs CI/CD
Where the code lives, or what happens when it changes?
SCM vs DevOps platform
One vendor, or best-of-breed?
IDE licensing vs seat licensing
Who is the licence attached to?
Secrets management vs configuration
A credential, or a setting?
Seven variables move the shortlist.
One platform or best-of-breed
GitLab's case is strongest when you use most of it. Using SCM and CI alone means paying for planning and scanning you do not touch.
CI/CD minutes and runner costs
Metered separately everywhere, and frequently larger than the seat bill. Self-hosted runners trade the meter for machines you operate.
Self-hosted or SaaS
The documented route to India residency for GitHub Enterprise Server and GitLab self-managed. It moves upgrades onto your team.
The licence unit
Named user, concurrent, floating or per-organisation. JetBrains and Atlassian differ sharply from GitHub and GitLab here.
AI assistant bundling
The fastest-moving variable in this category. Generous in the trial, itemised at renewal — model the tier plus the assistant.
Pipeline security scanning
SAST, dependency and secrets scanning are in the platform tiers. Runtime and cloud posture are a different purchase entirely.
Contractors and occasional committers
Every model treats them differently, and this is where seat counts drift furthest from headcount.
Pick the job and the way it has to bill. Products drop out with the reason stated, never silently.
What you need it to do
How it has to run
How it bills
India
India residency is annotated rather than used to eliminate: few vendors here document an Indian SaaS region (JFrog’s status page lists Mumbai and Pune), for most of them self-hosting is the documented route — and a region is still not a written storage commitment.
per user / month for the platform, with GitHub Actions CI metered separately in minutes and security as two add-ons since April 2025 — Secret Protection $19 and Code Security $30 per active committer per month; Enterprise Cloud or Enterprise Server for self-hosting
Teams that want the largest ecosystem, the deepest third-party integration and the hiring advantage of the tool most developers already know.
The catch: Three meters on one platform: seats, Actions minutes and the security add-ons (Secret Protection, Code Security). The minutes line is the one that surprises — a busy monorepo pipeline can exceed the seat bill without anybody noticing until the invoice.
per user / month, published tiers, licensed separately from GitHub Enterprise; code completion, chat and agentic assistance inside the editor and the pull request
Teams where the measurable win is time-to-first-draft on routine code, and where the editors in use are supported.
The catch: A separate line at renewal, however generous the trial was. Seat counts drift upward faster than developer headcount because access is easy to grant and nobody audits it.
per user / month across Free, Premium and Ultimate, with CI minutes metered separately; SCM, CI/CD, security scanning, packages and planning under one licence — Ultimate carries the full scanning set
Estates that want one vendor and one bill across the whole toolchain rather than integrating four products — and self-managed installation where India residency requires it.
The catch: The single-platform case is strongest when you use most of it; teams using SCM and CI alone pay for planning and scanning they do not touch. Self-managed means you own the upgrades, which is a standing job.
per user / month as an addition to a GitLab tier; AI code suggestions, chat, vulnerability explanation and merge-request summaries inside the platform
GitLab estates that want AI assistance without introducing a second vendor's tooling and a second data-handling conversation.
The catch: An add-on rather than an inclusion — the same renewal surprise as Copilot. Capability depends on the underlying GitLab tier, so the comparison is tier-plus-Duo against a rival's equivalent.
per user / month with Pipelines build minutes metered separately; source control that shares identity, permissions and issue linking with Jira
Organisations already standardised on Jira that want source, branches and pull requests linked to the work item without an integration to maintain.
The catch: A smaller ecosystem than GitHub or GitLab, and the strongest case assumes Jira. Atlassian pricing steps at user-count thresholds, so crossing one costs more than the extra seats suggest.
per user / month across Free, Standard, Premium and Enterprise, published; issue tracking and planning for software teams, linked to the branch and the deployment
Engineering organisations that need the work item, the branch and the release connected — the planning half of the toolchain rather than the code half.
The catch: Planning, not source control or CI. Pricing steps at user-count thresholds and the jump is the thing to model — crossing 100 users is not a linear increase.
since March 2026: Free for one user, Solo $9/month and Team $19 per user/month billed annually, Enterprise on quote; the client most API developers already have open — requests, environments, collections and history
Any team building or consuming APIs, which is nearly all of them — this is usually already in use before it is ever purchased.
The catch: Since March 2026 the Free plan is one user and cannot create a team, so any shared collection means a paid seat. Shadow usage on personal free accounts is common and worth auditing.
within the Postman plans (Team $19 per user/month billed annually; Enterprise on quote); schema-first API design with OpenAPI, mocking and documentation generated from the contract rather than written after it
Teams where the API contract needs agreeing before implementation — typically where a separate team consumes it.
The catch: Design-first is a working practice more than a product: without the discipline, the tool produces schemas nobody updates. Value depends on adoption, not licences.
within the Postman plans, with monitoring requests capped per plan (1,000 a month on Free, 10,000 on paid plans); automated API tests that run in CI and on a schedule against live environments
Teams whose integration failures are found by customers rather than by the pipeline.
The catch: Scheduled monitors draw on a per-plan allowance of monitoring requests — a second limit beside seats. It tests the API, not the user journey through the interface.
in the Enterprise plan, quoted by Postman sales; API standards enforcement, secret detection in collections, and visibility of every API the organisation has published
Organisations with more APIs than anyone can list, and no consistent standard across teams.
The catch: Governance is only as real as the enforcement: rules that warn rather than block are ignored within a quarter. Enterprise-tier only.
HCP Terraform free up to 500 managed resources, then priced per managed resource per month (Essentials from $0.10); Terraform Enterprise self-hosted on quote — infrastructure as code with state management, policy and a run history
Teams whose infrastructure changes should be reviewed, versioned and repeatable rather than clicked in a console.
The catch: The per-managed-resource meter means the bill tracks infrastructure sprawl, not team size — a resource nobody uses still counts. IBM-owned since 2025, which some estates weigh in a multi-year commitment.
quoted on active clients for HCP Vault Dedicated or Vault Enterprise; centralised secrets with dynamic credentials, rotation and an audit trail — the machine-identity half of the toolchain
Estates where credentials currently live in CI variables and configuration files, and somebody has finally asked who can read them.
The catch: Client-based metering is hard to forecast, because a client is any application or workload that authenticates. Vault is also an operational commitment: it becomes a critical dependency the day you adopt it.
Community Edition free (BUSL-1.1); self-managed Consul Enterprise on quote — the managed HCP Consul Dedicated reached end of life on 12 Nov 2025; service discovery, health checking and service-mesh networking with mutual TLS between services
Estates running many services across environments where discovery and service-to-service encryption are the operational gap.
The catch: A service mesh is a serious architectural commitment with its own failure modes, and many estates adopt one before they need it. There is no HashiCorp-managed option now, so you run it yourself. If service count is modest, native platform networking is usually enough.
per month list for SaaS Pro with 25 GB of storage plus transfer, then $1.25 falling to $0.75 per GB; Enterprise X from $950 a month with 125 GB; self-managed Pro X from $27,000 a year for one server. A limited-time $50-a-month Pro offer shows no end date — budget on the list price
Teams whose builds pull from npm, Maven, PyPI or Docker Hub and break when those do — one private repository for 60+ package types, containers and AI models, SaaS or self-managed.
The catch: SaaS Pro has no Xray scanning; that starts at Enterprise X. Consumption counts transfer as well as storage, so CI pulling the same images all day spends the allowance. JFrog lists Mumbai and Pune regions; the storage commitment is a contract question.
included from SaaS Enterprise X (from $950 a month) and self-managed Pro X (from $27,000 a year) — not in SaaS Pro; scans the artifacts Artifactory already stores for CVEs, licences, malicious packages, containers and ML models, with an SBOM per build
Teams already on Artifactory who need to say which builds carry a vulnerable or unlicensed component, including in containers and binaries that source scanning never sees.
The catch: It scans only what flows through Artifactory, so it is the wrong buy without the repository. Pricing Pro plus a separate scanner against Enterprise X is the honest comparison. The storage commitment for the Mumbai and Pune regions is a contract question.
quote-only add-on on Enterprise X and Enterprise+, licensed per contributing developer — 50 developers included on Enterprise X, 200 on Enterprise+; adds contextual analysis (is the CVE reachable), secrets, SAST and IaC scanning to Xray
AppSec teams with a CVE backlog too long to fix in order, who need the findings that are actually reachable in their code ranked first.
The catch: An add-on to an add-on: it needs Xray, which needs Enterprise X. Count contributing developers, not everyone with access, before the quote. No published price.
quote-only add-on on Enterprise X and Enterprise+ (and in both security bundles); blocks risky open-source packages, AI models and extensions at the moment they are requested and offers a compliant version, now with Package Traffic Controller for Zscaler, Netskope and Cloudflare
Organisations where a malicious or non-compliant package has already reached a developer laptop or a build, and scanning afterwards is no longer enough.
The catch: It controls what passes through Artifactory; direct downloads that bypass it need Package Traffic Controller and a network control. Start policies in dry-run, or developers are blocked on day one.
per instance, per year, by lines of code — Developer, Enterprise and Data Center editions; Sonar no longer publishes the prices, and third-party figures are old list prices. Dependency scanning is Advanced Security, a separate subscription
Teams that want a quality gate on every pull request and whose code cannot leave their own infrastructure — the self-managed route, on infrastructure you control.
The catch: Priced by lines of code, so generated code and monorepos push you up a band. Enterprise adds the legacy languages (COBOL, PL/I, APEX) and AI CodeFix; check your languages before choosing Developer.
a month on Team for up to 100k lines of code (read 30 Sep 2026), up to 1.9M lines; free up to 50k lines and 5 members; Enterprise custom. Wired into GitHub, GitLab, Bitbucket Cloud and Azure DevOps
Teams that want the same quality gate without running a server, and whose code may be stored in the EU or US.
The catch: Data is stored in the EU or US only — chosen at sign-up and fixed — so it cannot meet an India storage requirement; that is SonarQube Server. The US region needs Enterprise.
additional subscription on SonarQube Server Enterprise and SonarQube Cloud Enterprise; adds dependency scanning with malicious-package detection, licence policy and SBOM export, plus taint analysis through libraries
AppSec teams already running SonarQube who want dependency risk and SBOMs in the same pull-request check rather than a second tool.
The catch: Sonar’s pricing page and documentation disagree on whether Cloud Team includes it — get the answer in writing. No published price.
per user per month billed annually on Core ($40 on Pro), up to 50 users; Enterprise is priced per pull request and adds SSO and connections to self-hosted Git servers (Gitar itself runs hosted). AI code review on GitHub, GitLab, Bitbucket and Azure DevOps; a Sonar company since May 2026
Teams where pull requests wait for human review, who want an AI reviewer that comments on and fixes changes before a person looks.
The catch: AI review reads intent in a diff; it does not replace rule-based analysis of the whole codebase. Processing defaults to the US; EU, Singapore, Australia and Japan instances are in beta for Enterprise — not India.
a year for Pro Cloud plus consumption above 25 GB ($1.10/GB/month to 1,000 GB); Pro Self-Hosted $7,500 a year with 50K components included; the free Community Edition is self-hosted and capped at 40,000 components
Teams that want one cache for every package their builds pull, from the company that runs Maven Central — free to start, with a published Pro price.
The catch: Community Edition pauses new components past 40,000 or 100,000 requests a day. Sonatype’s docs list Mumbai and Hyderabad storage regions for the cloud; confirm yours in writing.
a year for Firewall Pro — npm, Maven, PyPI and NuGet, for repositories other than Nexus, internet-connected only; the self-hosted Repository Firewall (15+ formats, air-gapped, container protection) is quoted
Estates where a malicious package has reached a build, and blocking at the proxy matters more than scanning afterwards.
The catch: Firewall Pro is not for Nexus or air-gapped estates — those need the quoted self-hosted edition. Cloud storage regions are not documented.
a year for Pro (5,000 credits); a free tier with 500 credits; Enterprise by quote with the governance, policy and SBOM scope formerly sold as Lifecycle and SBOM Manager — which new customers can no longer buy
Teams whose AI coding assistants choose package versions, and security teams that need SCA, policy and SBOMs from one product.
The catch: Credits are not defined publicly, so model usage in a trial. Cloud storage regions are not documented.
a month per serverless control plane on Konnect Plus; hybrid $200 and Dedicated Cloud Gateways $500 per control plane plus $0.15/GB; 1M API requests included, then $200 a month per extra million (max 10M); Enterprise and the fully self-hosted Gateway Enterprise are quoted
Teams running APIs across clouds and their own clusters who want one control plane for gateways, portals and the API catalogue, with a published price to start.
The catch: Kong Gateway’s open-source line stopped at 3.9.x. Konnect’s India geo keeps control-plane data in-geo, but Kong does not name the city or cloud region, and authentication, billing and usage are shared across geos.
a month per model proxied on Konnect Plus, up to five models; the AI enterprise plugins are an add-on on Plus and included on Enterprise, which is quoted
Teams putting LLM, MCP and agent calls behind the same rate limits, PII controls and cost reporting as their APIs.
The catch: AI Gateway 2.0 (September 2026) replaced the plugin model; the V1 AI plugins become opt-in from Gateway 3.18. Plus caps at five models.
per user / month for Pro, $45 for Enterprise; Essentials is free; an open-source desktop client for REST, GraphQL, gRPC, WebSocket and MCP, with local, Git or end-to-end-encrypted cloud storage
Developers who want an API client that can keep collections local or in Git rather than in a vendor cloud.
The catch: Cloud Sync is stored in GCP US Central, end-to-end encrypted; keep collections in Local Vault or your own Git if they must stay in India.
quoted, licensed by data plane proxies; an enterprise service mesh on the CNCF Kuma project for Kubernetes and VMs across zones; without a licence it runs 10 proxies for 30 days
Platform teams that need mutual TLS and traffic policy across Kubernetes and VMs in more than one zone.
The catch: No public price. Self-managed, so data stays where you run it; Konnect Mesh Manager follows the Konnect geo.
quote-only: self-hosted SAST, DAST and SCA licences are quoted, and Fortify on Demand is bought as prepaid Assessment Units valid 12 months with no rollover (a year of static scans on one app is 4 AUs); Fortify SCA has a free tier
AppSec teams that want static, dynamic and composition testing from one vendor — SAST across 44+ languages and 350+ frameworks — run on their own servers or as a service with an expert review included.
The catch: No public price for SAST, DAST or an Assessment Unit, and Remediation Aviator costs 1 AU per app on top. Fortify on Demand lists the Americas, Europe, Australia and Singapore, not India — self-host it to keep code here.
by virtual user — permanent, time-limited or 24-hour Virtual User Flex Days — with protocols sold in bundles; every paid edition is quoted and Core SaaS is usage-based; a free Community licence runs 50 virtual users
Teams that must prove an application holds its peak before release — web, API, SAP, Oracle E-Business and 180+ protocols in all — on their own servers or from Core’s cloud load generators.
The catch: Load testing, not a pull-request check; VuGen scripts run only on OpenText engines, though JMeter and Gatling scripts stay portable, and Core names no hosting region. OpenText classes its DevOps testing line as non-core and is divesting non-core units — ask about the roadmap.
seat licences tied to one Windows machine, or concurrent licences drawn from an AutoPass server pool, both quoted; the AI tier and the Aviator add-on are licensed on top; every download carries a 30-day trial seat
QA teams automating regression tests across web, desktop, mobile, SAP, Salesforce, Citrix and 3270/5250 mainframe screens — 200+ technologies by OpenText’s count — in VBScript or Python.
The catch: Tests are built on Windows and lean on its own object repositories, so scripts do not move easily; the SaaS edition lists no India region. OpenText classes its DevOps testing line as non-core and is divesting non-core units — ask about the roadmap.

quoted; gateway licences work across appliance, VM and container form factors; version 11.2 (Nov 2025) with a web Policy Manager and post-quantum key exchange; 11.1 support extended to Oct 2027
Enterprises securing APIs in front of on-premises and legacy back ends, including ESB and SOA services.
The catch: Quote-only, and its SaaS developer portal region is not published; the gateway is self-hosted rather than a managed cloud service.

subscription quoted by Red Hat, Standard (business hours) or Premium (24x7) support; self-managed, managed application in your cloud, or Red Hat-managed service; AAP 2.6
Ops teams standardising configuration, patching and network automation across Linux, Windows and network gear, and teams already holding Red Hat subscriptions.
The catch: Agentless and push-based: strong for configuration and day-2 change, weaker than Terraform for provisioning state (IBM owns both); no list price, so ask what the quote counts.

billed on model tokens in AI credits inside a Snowflake account (rates per model in Snowflake’s consumption table); a standalone CoCo CLI subscription exists, price not published
Data engineers working in Snowflake, dbt or Airflow who want an agent that already knows their schemas, roles and governance policies.
The catch: Token-metered, so cost tracks how heavily people use it rather than headcount, and it is built for data work rather than general application code. Model choice changes the bill by an order of magnitude.

NGINX Plus Standard on AWS Marketplace is $0.50 an hour in software fees after a 30-day trial (Developer $0.14); NGINX One otherwise quoted, bundling NGINX Plus, F5 WAF for NGINX, the Ingress Controller, Gateway Fabric and the SaaS NGINX One Console
Teams that already run NGINX and want a supported load balancer, reverse proxy and API gateway with a WAF and one console across VMs and Kubernetes.
The catch: Outside the marketplace there is no public price. The WAF was renamed from NGINX App Protect, so older quotes and docs use the old name, and NGINX had an exploited flaw in May 2026 (CVE-2026-42945, fixed in NGINX Plus after R36 / OSS 1.30.1).
one platformRules out Atlassian Bitbucket, Postman API Client, Postman API Design, Postman API Testing, Postman Governance, HashiCorp Terraform, HashiCorp Vault, HashiCorp Consul, JFrog Artifactory, JFrog Xray, JFrog Advanced Security, JFrog Curation, SonarQube Server, SonarQube Cloud, SonarQube Advanced Security, Gitar, Sonatype Nexus Repository, Sonatype Repository Firewall, Sonatype Guide, Kong Konnect, Kong AI Gateway, Kong Insomnia, Kong Mesh, OpenText Fortify (SAST · DAST · SCA · Fortify on Demand), OpenText Performance Engineering (formerly LoadRunner: Professional · Enterprise · Core), OpenText Functional Testing (formerly UFT One), Layer7 API Gateway (Broadcom), Red Hat Ansible Automation Platform and F5 NGINX One (NGINX Plus) — one layer of the toolchain, not the whole platform. That leaves GitHub Enterprise, GitHub Copilot, GitLab DevSecOps Platform, GitLab Duo, Atlassian Jira and Snowflake CoCo (formerly Cortex Code).
pipeline scanningRules out GitHub Copilot, GitLab Duo, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing, HashiCorp Terraform, HashiCorp Consul, JFrog Artifactory, Gitar, Sonatype Nexus Repository, Kong Konnect, Kong AI Gateway, Kong Insomnia, Kong Mesh, OpenText Performance Engineering (formerly LoadRunner: Professional · Enterprise · Core), OpenText Functional Testing (formerly UFT One), Layer7 API Gateway (Broadcom), Red Hat Ansible Automation Platform, Snowflake CoCo (formerly Cortex Code) and F5 NGINX One (NGINX Plus) — no pipeline security scanning; Atlassian Bitbucket, Postman Governance, HashiCorp Vault, JFrog Xray, JFrog Curation, Sonatype Repository Firewall and Sonatype Guide — one scanning type only, not the SAST + dependency + secrets set. That leaves GitHub Enterprise, GitLab DevSecOps Platform, JFrog Advanced Security, SonarQube Server, SonarQube Cloud, SonarQube Advanced Security and OpenText Fortify (SAST · DAST · SCA · Fortify on Demand).
API toolingRules out GitHub Enterprise, GitHub Copilot, GitLab DevSecOps Platform, GitLab Duo, Atlassian Bitbucket, Atlassian Jira, HashiCorp Terraform, HashiCorp Vault, HashiCorp Consul, JFrog Artifactory, JFrog Xray, JFrog Advanced Security, JFrog Curation, SonarQube Server, SonarQube Cloud, SonarQube Advanced Security, Gitar, Sonatype Nexus Repository, Sonatype Repository Firewall, Sonatype Guide, Kong Mesh, OpenText Fortify (SAST · DAST · SCA · Fortify on Demand), OpenText Performance Engineering (formerly LoadRunner: Professional · Enterprise · Core), OpenText Functional Testing (formerly UFT One), Red Hat Ansible Automation Platform and Snowflake CoCo (formerly Cortex Code) — not API-lifecycle tooling. That leaves Postman API Client, Postman API Design, Postman API Testing, Postman Governance, Kong Konnect, Kong AI Gateway, Kong Insomnia, Layer7 API Gateway (Broadcom) and F5 NGINX One (NGINX Plus).
infrastructure and secretsRules out GitHub Enterprise, GitHub Copilot, GitLab DevSecOps Platform, GitLab Duo, Atlassian Bitbucket, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing, Postman Governance, JFrog Artifactory, JFrog Xray, JFrog Advanced Security, JFrog Curation, SonarQube Server, SonarQube Cloud, SonarQube Advanced Security, Gitar, Sonatype Nexus Repository, Sonatype Repository Firewall, Sonatype Guide, Kong Konnect, Kong AI Gateway, Kong Insomnia, OpenText Fortify (SAST · DAST · SCA · Fortify on Demand), OpenText Performance Engineering (formerly LoadRunner: Professional · Enterprise · Core), OpenText Functional Testing (formerly UFT One), Layer7 API Gateway (Broadcom), Snowflake CoCo (formerly Cortex Code) and F5 NGINX One (NGINX Plus) — not infrastructure or secrets tooling. That leaves HashiCorp Terraform, HashiCorp Vault, HashiCorp Consul, Kong Mesh and Red Hat Ansible Automation Platform.
artifact managementRules out GitHub Enterprise, GitHub Copilot, GitLab DevSecOps Platform, GitLab Duo, Atlassian Bitbucket, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing, Postman Governance, HashiCorp Terraform, HashiCorp Vault, HashiCorp Consul, SonarQube Server, SonarQube Cloud, SonarQube Advanced Security, Gitar, Kong Konnect, Kong AI Gateway, Kong Insomnia, Kong Mesh, OpenText Fortify (SAST · DAST · SCA · Fortify on Demand), OpenText Performance Engineering (formerly LoadRunner: Professional · Enterprise · Core), OpenText Functional Testing (formerly UFT One), Layer7 API Gateway (Broadcom), Red Hat Ansible Automation Platform, Snowflake CoCo (formerly Cortex Code) and F5 NGINX One (NGINX Plus) — not artifact management or supply-chain control. That leaves JFrog Artifactory, JFrog Xray, JFrog Advanced Security, JFrog Curation, Sonatype Nexus Repository, Sonatype Repository Firewall and Sonatype Guide.
code quality checksRules out GitHub Enterprise, GitHub Copilot, GitLab DevSecOps Platform, GitLab Duo, Atlassian Bitbucket, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing, Postman Governance, HashiCorp Terraform, HashiCorp Vault, HashiCorp Consul, JFrog Artifactory, JFrog Xray, JFrog Advanced Security, JFrog Curation, Sonatype Nexus Repository, Sonatype Repository Firewall, Sonatype Guide, Kong Konnect, Kong AI Gateway, Kong Insomnia, Kong Mesh, Layer7 API Gateway (Broadcom), Red Hat Ansible Automation Platform, Snowflake CoCo (formerly Cortex Code) and F5 NGINX One (NGINX Plus) — not a code quality, security or testing tool. That leaves SonarQube Server, SonarQube Cloud, SonarQube Advanced Security, Gitar, OpenText Fortify (SAST · DAST · SCA · Fortify on Demand), OpenText Performance Engineering (formerly LoadRunner: Professional · Enterprise · Core) and OpenText Functional Testing (formerly UFT One).
self-hostingRules out GitHub Copilot, Atlassian Bitbucket, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing, Postman Governance, SonarQube Cloud, Gitar, Sonatype Guide, Kong Insomnia and Snowflake CoCo (formerly Cortex Code) — SaaS only, so India residency cannot be met by deployment choice. That leaves GitHub Enterprise, GitLab DevSecOps Platform, GitLab Duo, HashiCorp Terraform, HashiCorp Vault, HashiCorp Consul, JFrog Artifactory, JFrog Xray, JFrog Advanced Security, JFrog Curation, SonarQube Server, SonarQube Advanced Security, Sonatype Nexus Repository, Sonatype Repository Firewall, Kong Konnect, Kong AI Gateway, Kong Mesh, OpenText Fortify (SAST · DAST · SCA · Fortify on Demand), OpenText Performance Engineering (formerly LoadRunner: Professional · Enterprise · Core), OpenText Functional Testing (formerly UFT One), Layer7 API Gateway (Broadcom), Red Hat Ansible Automation Platform and F5 NGINX One (NGINX Plus).
AI assistanceRules out Atlassian Bitbucket, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing, Postman Governance, HashiCorp Terraform, HashiCorp Vault, HashiCorp Consul, JFrog Artifactory, JFrog Xray, JFrog Advanced Security, JFrog Curation, SonarQube Advanced Security, Sonatype Nexus Repository, Sonatype Repository Firewall, Kong Konnect, Kong AI Gateway, Kong Insomnia, Kong Mesh, Layer7 API Gateway (Broadcom) and F5 NGINX One (NGINX Plus) — no AI assistant documented for this product. That leaves GitHub Enterprise, GitHub Copilot, GitLab DevSecOps Platform, GitLab Duo, SonarQube Server, SonarQube Cloud, Gitar, Sonatype Guide, OpenText Fortify (SAST · DAST · SCA · Fortify on Demand), OpenText Performance Engineering (formerly LoadRunner: Professional · Enterprise · Core), OpenText Functional Testing (formerly UFT One), Red Hat Ansible Automation Platform and Snowflake CoCo (formerly Cortex Code).
per-seat pricingRules out HashiCorp Terraform, JFrog Artifactory, JFrog Xray, SonarQube Cloud, Sonatype Nexus Repository, Kong Konnect, Kong AI Gateway, Snowflake CoCo (formerly Cortex Code) and F5 NGINX One (NGINX Plus) — consumption-metered: the bill tracks resources, not people; HashiCorp Vault, HashiCorp Consul, JFrog Advanced Security, JFrog Curation, SonarQube Server, SonarQube Advanced Security, Kong Mesh, OpenText Fortify (SAST · DAST · SCA · Fortify on Demand), OpenText Performance Engineering (formerly LoadRunner: Professional · Enterprise · Core), OpenText Functional Testing (formerly UFT One), Layer7 API Gateway (Broadcom) and Red Hat Ansible Automation Platform — quote-only, and metered on clients or services rather than seats. That leaves GitHub Enterprise, GitHub Copilot, GitLab DevSecOps Platform, GitLab Duo, Atlassian Bitbucket, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing, Postman Governance, Gitar, Sonatype Repository Firewall, Sonatype Guide and Kong Insomnia.
no metered minutesRules out GitHub Enterprise, GitLab DevSecOps Platform and Atlassian Bitbucket — CI minutes are metered separately and routinely exceed the seat bill. That leaves GitHub Copilot, GitLab Duo, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing, Postman Governance, HashiCorp Terraform, HashiCorp Vault, HashiCorp Consul, JFrog Artifactory, JFrog Xray, JFrog Advanced Security, JFrog Curation, SonarQube Server, SonarQube Cloud, SonarQube Advanced Security, Gitar, Sonatype Nexus Repository, Sonatype Repository Firewall, Sonatype Guide, Kong Konnect, Kong AI Gateway, Kong Insomnia, Kong Mesh, OpenText Fortify (SAST · DAST · SCA · Fortify on Demand), OpenText Performance Engineering (formerly LoadRunner: Professional · Enterprise · Core), OpenText Functional Testing (formerly UFT One), Layer7 API Gateway (Broadcom), Red Hat Ansible Automation Platform, Snowflake CoCo (formerly Cortex Code) and F5 NGINX One (NGINX Plus).
published pricingRules out HashiCorp Vault, HashiCorp Consul, JFrog Advanced Security, JFrog Curation, SonarQube Server, SonarQube Advanced Security, Kong Mesh, OpenText Fortify (SAST · DAST · SCA · Fortify on Demand), OpenText Performance Engineering (formerly LoadRunner: Professional · Enterprise · Core), OpenText Functional Testing (formerly UFT One), Layer7 API Gateway (Broadcom) and Red Hat Ansible Automation Platform — quote-only. That leaves GitHub Enterprise, GitHub Copilot, GitLab DevSecOps Platform, GitLab Duo, Atlassian Bitbucket, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing, Postman Governance, HashiCorp Terraform, JFrog Artifactory, JFrog Xray, SonarQube Cloud, Gitar, Sonatype Nexus Repository, Sonatype Repository Firewall, Sonatype Guide, Kong Konnect, Kong AI Gateway, Kong Insomnia, Snowflake CoCo (formerly Cortex Code) and F5 NGINX One (NGINX Plus).
an Indian regionRules nothing out on published terms. It flags GitHub Enterprise — No Indian SaaS region is documented, GitHub Copilot — No Indian region is documented and there is no self-hosted option, GitLab DevSecOps Platform — No Indian SaaS region is documented, GitLab Duo — No Indian SaaS region is documented, Atlassian Bitbucket — No Indian region is documented and there is no self-hosted option, Atlassian Jira — No Indian region is documented and there is no self-hosted option, Postman API Client — No Indian region is documented and there is no self-hosted option, Postman API Design — No Indian region is documented and there is no self-hosted option, Postman API Testing — No Indian region is documented and there is no self-hosted option, Postman Governance — No Indian region is documented and there is no self-hosted option, HashiCorp Terraform — No Indian SaaS region is documented, HashiCorp Vault — No Indian SaaS region is documented, HashiCorp Consul — No Indian SaaS region is documented, SonarQube Server — No Indian SaaS region is documented, SonarQube Cloud — No Indian region is documented and there is no self-hosted option, SonarQube Advanced Security — No Indian SaaS region is documented, Gitar — No Indian region is documented and there is no self-hosted option, Sonatype Repository Firewall — No Indian SaaS region is documented, Sonatype Guide — No Indian region is documented and there is no self-hosted option, Kong Insomnia — No Indian region is documented and there is no self-hosted option, Kong Mesh — No Indian SaaS region is documented, OpenText Fortify (SAST · DAST · SCA · Fortify on Demand) — No Indian SaaS region is documented, OpenText Performance Engineering (formerly LoadRunner: Professional · Enterprise · Core) — No Indian SaaS region is documented, OpenText Functional Testing (formerly UFT One) — No Indian SaaS region is documented, Layer7 API Gateway (Broadcom) — No Indian SaaS region is documented, Red Hat Ansible Automation Platform — No Indian SaaS region is documented, Snowflake CoCo (formerly Cortex Code) — No Indian region is documented and there is no self-hosted option and F5 NGINX One (NGINX Plus) — No Indian SaaS region is documented — marked on the cards, not removed.
The minutes are the surprise, not the seatsGitHub Actions, GitLab CI and Bitbucket Pipelines all meter build minutes separately from the seat licence. A busy monorepo with a matrix build can exceed its seat bill without anybody noticing until the invoice — and the fix is pipeline discipline, not a different vendor.
Seat counts drift upward, quietlyAccess is easy to grant and nobody audits it. Contractors, occasional committers and people who left the team last quarter all count. Audit against actual commit activity before every renewal; it is the cheapest saving in this route.
AI assistants are bundled in the trial, itemised at renewalCopilot and GitLab Duo are both separate licences however the pilot was framed. Model the platform tier PLUS the assistant when comparing vendors, because that is the number you will pay in year two.
JetBrains is carried but not ranked hereTechBag sells JetBrains licences and it belongs in this route. There are no intel pages yet, so it is named and not ranked rather than silently omitted. Its licence unit differs materially from everything carded here — per named user or a floating pool, which changes the maths for teams with part-time or shift-based developers.
If one of these is your sentence, the shortlist is short.
Why: SCM, CI, packages, scanning and planning under one licence and one renewal conversation.
The trade-off: You pay for the whole platform whether or not you use the whole platform. Price it against what you would otherwise buy.
Why: Self-hosting is the documented residency route — no vendor here publishes an Indian SaaS region.
The trade-off: Somebody owns upgrades, backups and availability. That role is the real cost, and it is usually unassigned at signature.
Why: Both support self-hosted runners, which trades the per-minute meter for machines you already pay for.
The trade-off: Self-hosted runners are infrastructure you now maintain and secure — and a compromised runner is a supply-chain problem.
Why: Shared identity, permissions and issue linking with no integration to build or maintain.
The trade-off: Smaller ecosystem than GitHub or GitLab, and Atlassian pricing steps hard at user-count thresholds.
Why: An inventory of every published API plus enforceable standards across teams.
The trade-off: Enterprise tier, and governance that warns rather than blocks is ignored within a quarter.
Why: Centralised secrets with dynamic credentials, rotation and an audit trail of who read what.
The trade-off: Client-based metering is hard to forecast, and Vault becomes critical infrastructure the day you adopt it.
Why: Infrastructure as code with state, policy and a reviewable run history.
The trade-off: Per managed resource, so the bill tracks infrastructure sprawl rather than team size — unused resources still count.
Why: A private repository caches every package and image the build pulls, so builds keep working when npm or Docker Hub does not.
The trade-off: Consumption bills storage plus transfer above an allowance; measure a month of real pulls before choosing a tier.
Why: Curation blocks the package at the moment of request; Advanced Security ranks what is already in by whether it is reachable.
The trade-off: Both are quoted Enterprise X add-ons, and Curation only sees traffic that passes through the repository.
Why: A quality gate fails new code that breaks the agreed rules at the pull request, where the fix is a comment rather than a hotfix.
The trade-off: Priced by lines of code, and Cloud stores data in the EU or US — self-host Server if code must stay in India.
Why: An AI reviewer comments on, fixes and validates each pull request before a person looks at it.
The trade-off: It reads the change, not the whole codebase — pair it with static analysis rather than replacing it.
Why: Community Edition pauses new components past 40,000 or 100,000 requests a day since December 2025; Pro removes the cap.
The trade-off: Pro Self-Hosted is $7,500 a year with 50K components included — count your estate before choosing a tier.
Why: An AI gateway applies rate limits, PII redaction and cost reporting to LLM, MCP and agent traffic, on the same platform as the API gateway.
The trade-off: Konnect Plus bills $100 a month per model and stops at five; beyond that, Enterprise is quoted.
Why: Both are per-seat add-ons to their platform; the honest comparison is platform tier plus assistant, not assistant alone.
The trade-off: A separate line at renewal however the trial was framed, and seat counts drift upward faster than headcount.
Application security is a section here, not a route, because the bench is thin and the products are modules of platforms carded elsewhere. Three kinds of scanning ship inside the SCM platforms above:
GitHub carries all three in two add-on licences since April 2025 — Secret Protection and Code Security; GitLab carries the full set at Ultimate; JFrog scans the artifacts rather than the repository, with Xray from Enterprise X and Advanced Security on top; Sonar runs SAST and secrets in the same quality gate, with dependency scanning in Advanced Security. The boundary is the deploy: everything above happens before it. Container and cloud posture scanning happens after, is a different purchase, and lives on Cloud & Workload Security. Web application firewalls are further out still and belong to Firewall & Network Security. Neither is carded here.
On JetBrains. TechBag carries JetBrains licences and they belong in this route. There are no intel pages for them yet, so JetBrains is named and not ranked rather than quietly left out — the treatment this site gives any vendor it names before building its page. What matters commercially is that its licence unit is different from everything carded above: per named user, or a floating pool shared across a team. For an estate with contractors, shift work or part-time developers, a floating pool can be materially cheaper than per-seat SCM licensing, and the two models cannot be compared line-for-line. Ask us for a JetBrains quote alongside any shortlist here.
Ask before signature
This route scales by developers — and by pipeline volume, which is not the same number.
Under 20 developers
Put this in your PoC
Prove the minutes against your real pipeline before paying.
20–100 developers
Put this in your PoC
Audit seats before every renewal. It is the cheapest saving here.
100–500 developers
Put this in your PoC
Model the tier jump, not the per-seat rate.
500+ developers
Put this in your PoC
Name the owner for the self-hosted upgrade path before choosing it.
Where a vendor does not publish list pricing, this page says so rather than implying a figure.
Git is portable. Everything built around it is not.
Repositories and history
Git is distributed by design — a clone is a complete copy
Pipeline definitions
Vendor-specific YAML, rewritten for the new platform
Issues, boards and pull-request history
Exportable via API; the discussion context rarely survives intact
Secrets and IaC state
Vault and Terraform state are portable with planning, catastrophic without it
The practical consequence: the code is never the lock-in. The pipelines, the scanning configuration and the accumulated review history are, and none of them appear in a switching-cost estimate.
Per seat, plus the meters beside it, in USD and INR.
Four checks, in the order most likely to return a yes.
The free tiers here are unusually strong. The paid case is compliance, support and scale rather than capability.
One meter you expect, and several you do not.
TechBag quotes every one of these in INR with GST, and models your actual volumes against each meter rather than comparing rates. Where a vendor publishes no list price, this page says so instead of repeating a third-party figure.
TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale at ≈₹83/$; the tier-matched INR quote is ours.
Metered separately everywhere, and routinely larger than the seat bill on a busy pipeline.
Copilot and Duo are separate licences however generous the trial was.
Upgrades, backups, availability and runner security. A role, not a line item.
Access is easy to grant and nobody audits it. Check against commit activity, not the directory.
Five ways this purchase goes wrong. Four of them are meters nobody modelled.
CI/CD minutes exceeding the seat bill
A matrix build on every push, on a busy monorepo. The fix is pipeline discipline and self-hosted runners, not a different vendor.
Seats counted per repository access rather than per active developer
Contractors, occasional committers and people who left all count. Audit against commit activity before every renewal.
Self-hosted chosen for residency, then nobody owns the upgrades
The residency requirement is met on day one and the platform is three versions behind by year two. Name the owner at signature.
The AI assistant licensed separately at renewal
Bundled generously in the trial, itemised afterwards. Compare platform tier plus assistant, not the tier alone.
Atlassian tier jumps at user-count thresholds
Crossing a threshold is not a linear increase. Model the jump before hiring past it.
Our IT & ITES guide maps CERT-In, DPDP, client contracts and buyers’ demands to the controls an Indian IT services, BPO or SaaS firm needs. This category answers:
Vendor-neutral. No gated content. · Last reviewed