Audits and Checks
The two counted units, what each one covers, what is never counted, and where to see your remaining allowance.
What it is
Umbra counts exactly two things. Everything else your plan includes is uncounted, however often you use it.
- Audit — one complete Deep Audit of one application, including up to ten of the backends it talks to. One scan is one Audit whatever the size of the application: no per-host, per-endpoint or per-finding surcharge.
- Check — one AI verification: pressing Exploit on a finding, or validating that a reported CVE is genuinely exploitable on your service.
Your plan includes a set number of each per month. They reset on your billing date and do not roll over. The app shows the reset date, so waiting for the reset is always a valid option.
What is never counted
Monitoring, discovery, scan cadence, cloud posture, agent runs, reports, PDF exports, translations, integrations and API access. Set whatever scan interval you like — scanning itself is not metered.
Re-testing a finding Umbra already reported to you is free. Confirming your own fix never spends a Check. Charging you to verify a remediation would discourage the exact behaviour the product exists to produce.
If a Deep Audit fails before producing anything, the Audit is returned to your allowance automatically.
Why it works this way
Usage-priced AI security tooling has a well-earned reputation for the surprise five-figure bill. Two counted units, both visible before you act and both capped by the plan, mean the worst case for any month is known when you sign the contract. A pathological target cannot cost you more than one Audit, so the number to plan against is how many applications you want audited — not how hard any one of them turns out to be.
Internally, each run is still bounded by a hard budget ceiling. If a run hits it, it finalises with what it has and the report carries a “partial coverage” note. That ceiling protects the platform; it never changes what you are charged.
Where to see it
- Settings → Usage — Audits and Checks remaining this period, the reset date, and the history of what spent them.
- The audit log records every AI run with the user who fired it, so a noisy team is visible without anyone having to reconcile a bill.
- Running out does not degrade anything you already have; upgrading raises the allowance immediately.
Umbra staff have a separate cross-org cost rollup at /api/admin/costs. The
underlying dollar cost of a run is operator-side only and is not shown in the
workspace.