Free tool · No sign-up · No email gate

Build vs. Buy: SAST Assessment

Seven questions about the parts of an internal scanner nobody puts in the estimate.

The quote you were given is for v1. This prices what comes after, then recommends an outcome. Including build, when build is right.

Question 1 Step 1 of 8

What it measures

Seven things that decide this, none of them detection

Getting findings out of an open-source engine is a weekend. Everything below turns findings into a control you can report on.

Q1

Who owns this scanner in year three?

The estimate you were given is for v1. The cost is whoever maintains it after the builder moves teams.

Q2

How many languages are in active production?

Every language is a separate parser, rule set, and accuracy problem.

Q3

Your team says the scanner got more accurate. How do you verify that?

No accuracy claim is checkable without a fixed set of your own code that someone has already labeled.

Q4

You change the model. What happens to the 400 findings your team already dismissed?

This is what separates a scanner from a security program.

Q5

Can you predict next quarter's inference bill within 20%?

Cost scales with commit volume, the one variable your security team doesn't control.

Q6

Where do findings have to appear before developers fix them?

Each surface is a separate integration with its own permissions and rate limits.

Q7

Should the tool find the vulnerability, or close it?

A wrong finding wastes an hour. A wrong fix ships to production.

Outcomes

Three results, and we will tell you not to buy

A tool that only recommends its own vendor is a brochure. An unsupported stack routes to build whatever the score says.

Build

Dedicated owners and a stack your team can support. You get a checklist, not a sales pitch.

Hybrid

Detection is close to a commodity. Deciding which findings are real still is not.

Buy

The modal result, because the gap between getting findings and running a control is a product.

Inference pricing

Model list prices as of September 2026

The calculator runs your PR volume across 9 models. The spread between cheapest and dearest is usually an order of magnitude.

Model Provider Input / 1M Cached input / 1M Output / 1M
GPT-6 Astra OpenAI $10.00 $1.000 $50.00
Claude Fable 5.1 Anthropic $10.00 $0.250 $50.00
Claude Mythos 5.1 Anthropic $10.00 $0.250 $50.00
Claude Opus 5.5 Anthropic $4.00 $0.200 $20.00
GPT-5.6 Sol OpenAI $4.00 $0.400 $20.00
Claude Opus 5 Anthropic $5.00 $0.500 $25.00
GPT-5.6 Terra OpenAI $2.00 $0.200 $12.00
Claude Sonnet 5 Anthropic $2.00 $0.200 $10.00
GPT-5 mini OpenAI $0.25 $0.025 $2.00

Both providers bill cached input at 10% of base. Anthropic charges 1.25x for cache writes, which the calculator doesn't model, so its cached figures run slightly optimistic.

FAQ

Questions about the assessment

Is this just a lead magnet that always says buy?

No. An internal or proprietary stack routes to build whatever the score says, because no vendor covers it. Buy is the most common result because it reflects how most teams answer.

How is the recommendation scored?

Each question carries up to three points of "buy pressure", for a maximum of 20. Low totals point to a build, mid-range to a hybrid split, high to buying. Two conditions override the total: an unsupported internal stack routes to build, and merge gating without refactor-stable fingerprints routes to buy.

Where do the inference cost numbers come from?

Published OpenAI and Anthropic list prices as of September 2026, across 9 models: GPT-6 Astra, Claude Fable 5.1, Claude Mythos 5.1, Claude Opus 5.5, GPT-5.6 Sol, Claude Opus 5, GPT-5.6 Terra, Claude Sonnet 5, GPT-5 mini. Token volumes come from published per-PR review workloads, roughly 8,000 input and 1,000 output for diff-only review. PR volume defaults to 1.7 merged per developer per week. Every input is editable and every assumption is listed under the calculator.

Why does the cost model include a benchmark set?

Because without one, no accuracy claim about your scanner is verifiable, including your own. It is a few hundred findings per language from your own repos, labeled once by a human and re-scored on every change. Most build estimates leave it out.

What happens to my answers?

Everything runs in your browser. Your answers are encoded in the page URL so you can forward the report or reopen it later. Nothing is sent to a server, and there is no email gate.

Can I export the report?

Yes. Download PDF prints the report through a layout built for paper: white background, Corgea branding, sensible page breaks, and the cost assumptions expanded. You can also copy a link that reopens it with the same answers.

If the answer is buy

Corgea finds it, verifies it, and opens the fix

Refactor-proof fingerprints and a fixed line in the budget instead of a per-token bill.

See how Corgea works