Token Economics: Scanning 101

The Token Ledger.
Run the math on your stack.

Every default is sourced. Every input is yours to change. Toggle between CFO dollars and CTO capacity, swap models live, and download a brief that survives the ride home from the meeting.

Cost calculator Ā· Phoenix Purple

What does unoptimized AI scanning cost you?

A conservative model of your monthly spend. Every default is sourced, every input is yours to change.

Set up your environment
MTok
Ɨ
%
min
$/hr
%
Frontier model (baseline)
Your business case
Reclaimed per month $14.3K $172.1K annualized, at list prices Model spend saved + FP triage hours reclaimed, priced at your loaded rate — not a fixed share of either bar.
Conservative defaults: FP rate 64–82% → 65% Ā· triage 10–30 min → 12 min Ā· tokenizer 1.0–1.35Ɨ on baseline only.
 
āˆ’85%
$7.6K $1.1K
Model spend
 
āˆ’80%
$9.9K $2.0K
FP triage
Today Phoenix
Token Seismograph

Where your current scans leak spend, estimated from repository shape, not your code. Sample profile: Single repo, heavy vendored deps.

Leak index46%of scanned tokens never needed
Est. waste / month$3.5Kat your current model's list price
Vendored deps
22%
Generated code
10%
Duplicated context
9%
Unreachable paths
5%
Model Arbitrage Sandbox

What swapping the frontier model does to this exact scan. Baseline spend swings with the rate card; graph-native spend barely moves.

 
āˆ’85%
$7.6K $1.1K
Opus 4.8
Today Phoenix
Phoenix Blue Ā· CTI + Supply Chain Firewall

Seat-based pricing, pooled tokens, BYOK or Enterprise anchor

Configure your plan
MTok
Price band
Your cost breakdown
At your inputs$63.0Kper year Ā· $5.3K/mo on Pro
Seats$5.3K/mo$105/user Ɨ 50 devs
Overage$0/mo0 MTok above the 250 MTok pool
Crossover40 devswhere Pro yearly = Enterprise base
Choose your plan
Firewall Basicselected
$20–40
/ user / mo
No LLM tokensat current mode: $30 Ā· $1,500/mo

CVE-only gating, no LLM

  • CVSS / EPSS / KEV severity blocking
  • Proxy + CI/CD gates
  • No LLM analyst, no MCP
Select
Standardselected
$25–40
/ user / mo
1M tokens / userat current mode: $33 Ā· $1,625/mo

Heuristics + basic CVE gating

  • Stage 1 heuristic engine (77 rules, 7 categories)
  • Local proxy + CI/CD gates
  • Basic safe-alternative recommendations
Select
Proselected
$90–120
/ user / mo
5M tokens / userat current mode: $105 Ā· $5,250/mo

LLM Analyst + MCP coding agents

  • Stage 2 LLM Analyst (context, IOCs, MITRE map)
  • MCP for Claude Code / Cursor / Windsurf
  • EPSS thresholds, CISA KEV blocking
  • Workflow governance, Slack/Teams routing
  • SBOM checks at deploy
Select
Maxselected
$200–250
/ user / mo
15M tokens / userat current mode: $225 Ā· $11,250/mo

Adversarial Judge + unlimited evaluate

  • Stage 3 Adversarial Judge (dual-LLM validation)
  • Zero-day defenses, obfuscated payload eval
  • Unlimited evaluate API rate
  • Access to top-tier models for Analyst / Judge
  • Shadow mode for safe rollout
Select
Enterpriserecommended
$50K
/ year base Ā· unlimited seats
20M tokens / mo org poolall-in at current usage: $54.8K/yr

SSO, SCIM, RBAC. 99.9% SLA. CRA / NIS2 / DORA audit retention. Overage at vendor + 2% or 100% BYOK.

Flip saves $8.2K/yr at 50 devs.
Select
Annual cost by tier at 50 devs
Firewall Basic
$28.8K
Standard
$26.7K
Pro
$63.0K
Max
$135.0K
Enterprise
$54.8K
Three-stage detection pipeline
Stage 1
Heuristic Engine not in your tier
77 rules across 7 categories. Install-time + build-time.
Stage 2
LLM Analyst not in your tier
Context, IOCs, MITRE ATT&CK mapping. EPSS + KEV gating.
Stage 3
Adversarial Judge not in your tier
Dual-LLM validation. Zero-day + obfuscated payload defense.
Four enforcement gates
Coding Agent
real-time
MCP (Claude Code, Cursor, Windsurf)
Local Proxy
install-time
npm / pip / cargo install hook
CI / CD
build-time
GitHub Actions / GitLab / Jenkins / Azure
Deployment Policy
deploy-time
SBOM checks, K8s admission, CodePipeline
Live intelligence coverage
341,223CVEs scored with CVSS
343,854CVEs with EPSS probabilities
HourlyData refresh cadence
4 gatesCoding agent → proxy → CI/CD → deploy
What each role does in Blue
CISOStrategic oversight
  1. Dashboard overview
  2. Trending CVEs + analytics
  3. Audit log for compliance
  4. Scoring weight customization
  5. User approvals
  6. Export analytics reports
Security OpsDaily monitoring
  1. 0-day monitoring stats
  2. Favorites + cached analyses
  3. CVE search on new intel
  4. Comments for team
  5. Tune suppression policies
Developer / DevSecOpsIntegration + prevention
  1. Generate API key (fetch tier)
  2. GitHub PAT for private repos
  3. Firewall management rules
  4. Webhook for PR scanning
  5. Malware firewall in CI
  6. Monitor daily LLM budget
Analyst / ResearcherDeep analysis
  1. CVE search
  2. AI analysis (root cause, impact, remediation)
  3. Compare CVSS / EPSS / Phoenix Score
  4. Comment on findings
  5. Save to favorites
  6. Export research data
Phoenix Orange Ā· ASPM foundation

Per-asset license credits. 1 Enterprise license = 15,000 credits.

Tell us about your backlog
CountWeightCredits
RepositoriesGitHub / GitLab / Bitbucket org settings
Ɨ weight
200
Build files / artifactsCount CI/CD pipeline defs (.yml, Jenkinsfile)
Ɨ weight
12.5
Infra VMs / serversCMDB export or cloud-console VM count
Ɨ weight
200
Running containerskubectl get pods --all-namespaces | wc -l
Ɨ weight
150
Container imagesUnique images in ECR / ACR / GCR registries
Ɨ weight
20
Endpoints (IPs)EDR, vuln scanner, or CMDB endpoint export
Ɨ weight
250
Websites (FQDNs)DNS zone file or WAF / CDN domain list
Ɨ weight
100
APIs (FQDNs)API gateway routes or Swagger / OAS specs
Ɨ weight
150
Cloud resourcesAWS Config / Azure Resource Graph / GCP Asset Inventory
Ɨ weight
600
Your remediation math
Total asset entitlement1,682.5 credits1 Enterprise license Ā· headroom 3,317.5 credits
Recommended tierProfessionalGrowing teams
Headroom66%within the Professional allocation
Platform tiers
Freeover cap
1,000
asset credits / license
Get started2 premium users + guests
  • Up to 1,000 assets
  • Community Slack support
  • Dashboard reporting
  • Google SSO + Authenticator
Select
Professionalrecommended
5,000
asset credits / license
Growing teams10 security admins + guests Ā· 300+ users
  • 5,000 asset credits
  • Slack support with SLA + email
  • Cyber Risk Graph
  • SCA + Web / API DAST
  • Threat Intel + Exploitability
  • Automated workflows
Select
Enterpriserecommended
15K+
asset credits / license
Full platform20 admins + SSO + AD Ā· 900+ users
  • 15,000+ asset credits per license
  • Priority Slack + email + CSM
  • Dedicated SaaS hosting + BYOEK
  • Advanced threat intel
  • AI remediation campaigns
  • CAB / EAB invitation (vetted)
Select

CAB / EAB subject to vetting. Cyber threat intel premium feeds may require add-on. Token-based AI credits are an Enterprise add-on.

Add-ons (Enterprise)
Professional Services (ProServe)6-month light / 3–4 month heavy
  • 2 calls/week, 1–3h/week for first month
  • Configuration support + PYRUS adjustments
  • 4 instructor-led training sessions
  • Translation script creation + support
  • Customized KRI reporting (MTTR, SLA)
  • Rollout support + verification
  • ~24h supported / ~36h guided allocation
Guided / Premium SupportEnterprise add-on, named resources
  • Priority CSM + dedicated TAM
  • Priority email support 12Ɨ5
  • Premium SLA for issues + changes
  • Priority fixes + tracking
  • Customer Advisory Board invitation (vetted)
  • Executive Advisory Board invitation (vetted)
Token-based AI creditsEnterprise add-on
  • Powers Green AI remediation campaigns
  • Powers advanced PS-MPI judge stage
  • Sized per remediation throughput target
Source: Phoenix Core Ā· Licensing & Support Guide (March 2026). 9 asset categories, weighted per type, 1 Enterprise license = 15,000 credits.
Derek

Derek Fisher

Head of product security at a global fintech

Derek Fisher – Head of product security at a global fintech. Speaker, instructor, and author in application security.

Derek is an award winning author of a children’s book series in cybersecurity as well as the author of ā€œThe Application Security Handbook.ā€ He is a university instructor at Temple University where he teaches software development security to undergraduate and graduate students. He is a speaker on topics in the cybersecurity space and has led teams, large and small, at organizations in the healthcare and financial industries. He has built and matured information security teams as well as implemented organizational information security strategies to reduce the organizations risk.

Derek got his start in the hardware engineering space where he learned about designing circuits and building assemblies for commercial and military applications. He later pursued a computer science degree in order to advance a career in software development. This is where Derek was introduced to cybersecurity and soon caught the bug. He found a mentor to help him grow in cybersecurity and then pursued a graduate degree in the subject.

Since then Derek has worked in the product security space as an architect and leader. He has led teams to deliver more secure software in organizations from multiple industries. His focus has been to raise the security awareness of the engineering organization while maintaining a practice of secure code development, delivery, and operations.

In his role, Jeevan handles a range of tasks, from architecting security solutions to collaborating with Engineering Leadership to address security vulnerabilities at scale and embed security into the fabric of the organization.

Jeevan Singh

Jeevan Singh

Founder of Manicode Security

Jeevan Singh is the Director of Security Engineering at Rippling, with a background spanning various Engineering and Security leadership roles over the course of his career. He’s dedicated to the integration of security practices into software development, working to create a security-aware culture within organizations and imparting security best practices to the team.
In his role, Jeevan handles a range of tasks, from architecting security solutions to collaborating with Engineering Leadership to address security vulnerabilities at scale and embed security into the fabric of the organization.

James

James Berthoty

Founder of Latio Tech

James Berthoty has over ten years of experience across product and security domains. He founded Latio Tech to help companies find the right security tools for their needs without vendor bias.

christophe

Christophe Parisel

Senior Cloud Security Architect

Senior Cloud Security Architect

Chris

Chris Romeo

Co-Founder
Security Journey

Chris Romeo is a leading voice and thinker in application security, threat modeling, and security champions and the CEO of Devici and General Partner at Kerr Ventures. Chris hosts the award-winning ā€œApplication Security Podcast,ā€ ā€œThe Security Table,ā€ and ā€œThe Threat Modeling Podcastā€ and is a highly rated industry speaker and trainer, featured at the RSA Conference, the AppSec Village @ DefCon, OWASP Global AppSec, ISC2 Security Congress, InfoSec World and All Day DevOps. Chris founded Security Journey, a security education company, leading to an exit in 2022. Chris was the Chief Security Advocate at Cisco, spreading security knowledge through education and champion programs. Chris has twenty-six years of security experience, holding positions across the gamut, including application security, security engineering, incident response, and various Executive roles. Chris holds the CISSP and CSSLP certifications.

jim

Jim Manico

Founder of Manicode Security

Jim Manico is the founder of Manicode Security, where he trains software developers on secure coding and security engineering. Jim is also the founder of Brakeman Security, Inc. and an investor/advisor for Signal Sciences. He is the author of Iron-Clad Java: Building Secure Web Applications (McGraw-Hill), a frequent speaker on secure software practices, and a member of the JavaOne Rockstar speaker community. Jim is also a volunteer for and former board member of the OWASP foundation.

Join our Mailing list!

Get all the latest news, exclusive deals, and feature updates.

The IKIGAI concept
Protected By
Shield Security PRO