Health and debt
Health falls as risk and effort rise. Debt rises with the same evidence. Both sit on a 0–100 scale so a repository can be compared with the one next to it.
DebtDetect scans a GitHub repository you are allowed to use, groups the findings by severity, and puts a low-to-high euro range next to the work. The report names the repository and the time of the scan. The same facts stay on the site, so a later scan does not erase the earlier one.
A finished scan is not a score by itself. It is a health figure, a debt figure, a count of findings, and a monthly exposure range. The range is an engineering estimate. It is not cash you have already saved, and it is not a bill.
Health falls as risk and effort rise. Debt rises with the same evidence. Both sit on a 0–100 scale so a repository can be compared with the one next to it.
Monthly and annual exposure show a low, a midpoint, and a high. Pro and higher add a confidence label, so a weak number can be rejected instead of treated as exact.
Every report carries the repository name, the scan date, and the scan time. On the site, Latest marks the newest completed scan. Older scans stay downloadable.
There is no DebtDetect password. A paid GitHub account opens the workspace it already pays for. It does not create a second account.
An owner or admin selects which private repositories use the shared allowance. Hitting the limit does not delete findings. Deselect one, or ask for capacity.
The scan machine is separate from the website. Progress stays on the repository page. A job that stops sending a heartbeat is returned to the queue.
Findings are grouped by severity, with file, rule, hours, and cost. Test files and archived copies stay visible and are not priced as production debt.
Starter can see the finding, the range, and the report. Pro can assign it, dismiss it with a stored reason, and read the timeline. A daily or weekly scan can run inside the cap. Slack can list findings, explain one, and open a draft pull request when the person’s role allows it.
That pull request edits source only for trailing whitespace or a missing final newline. Every other finding stays a labeled plan. A person still reviews the pull request. DebtDetect does not claim it re-ran the analyzer on that commit.
There is not one shared Slack. An owner connects DebtDetect into the company’s workspace. After that, people link their own identity. A scan that person started can message them when it finishes or fails. On Pro and higher, Monday brings a digest of what was added, resolved, and reopened. If a scan reopens an assigned finding, the assignee gets the message.
The price is what you pay. VAT is included. An EU VAT ID removes it, and the receipt shows net, VAT, and total.
A small team that needs the scan, the euro range, and a report.
A lead who needs to trust the number and watch a finding move.
A manager who needs a portfolio, an audit trail, and a control on who may act.
Security and finance have to approve it.
No. Sign up uses your GitHub account. DebtDetect does not create a password for you to reset.
No. The same GitHub account opens the workspace that is already paid. The same email on a paid account cannot be used to create a second one.
On a machine reserved for scanning, separate from the website. Source is cloned for the scan and then removed from that machine. The application runs in Frankfurt.
An estimate of engineering effort and cost-equivalent exposure. The report says so. It is not a promise of cash savings.
Write to hello@debtdetect.org. Business and Enterprise receive a reply on business days. Inside the app, Help puts the workspace id in the subject so a reply finds the right account. Report emails come from noreply@debtdetect.org. That address does not accept replies.