DebtDetect Sign up
Guide

How a workspace goes from sign-up to a report you can keep.

This guide is for someone who has not opened the app yet, and for a teammate who already has. Home is the mark at the top. There is no separate back control.

Open a workspace

Sign up uses GitHub. DebtDetect does not invent a password, and it does not ask you to share a GitHub password with a teammate. Before the workspace opens, you accept the current terms and privacy notice. The person who signs up becomes the owner of a new workspace only when that GitHub account does not already belong to one.

A paid account is one workspace. Signing up again with the same GitHub login opens that workspace. It does not start a second trial and it does not create a second place to put repositories. If the same email already sits on a paid account under a different GitHub login, signup stops. Use the account that pays.

An owner or admin later authorizes the company’s repositories. Signing up does not, by itself, grant DebtDetect the right to clone private code. That authorization is a separate step, and it can be revoked. When it is revoked, later scans stop. The findings and reports already stored stay with the workspace.

Use a repository you own, or one you were explicitly asked to test. A disposable repository is the safest first scan.

Run a scan

Owners and admins choose which authorized repositories consume the private-repository allowance. Starter includes 5, Pro 25, Business 100. Reaching the limit does not delete a repository, a finding, or a report. Deselect one repository, or ask about Business or Enterprise capacity.

Scans share one daily pool for the whole workspace. Starter is 20 a day, Pro is 100, Business is 1,000. Adding a seat does not multiply that pool. An extra seat, at €15 a month, adds a person.

A scan runs on a machine reserved for scanning, separate from the website. The page shows the stage: preparing the workspace, discovering source files, then analysis, then the stored result. A job that stops sending a heartbeat is put back on the queue. You do not need to guess whether it vanished.

On Pro and higher, an owner can set a repository to scan daily or weekly. The schedule waits long enough that it does not fire twice in the same window, it stays inside the daily cap, and it skips when the cap is already full. A failed scheduled scan can message the person on Slack when that person has linked Slack and turned alerts on.

Read a finding

A finding names a rule, a file, and when the evidence includes it, a line. Severity is critical, high, medium, low, or info. The page also shows why the finding matters, what a change would try to do, and a bounded effort in hours. The euro figure next to it is the same estimate, not a quote from a contractor.

On Pro and higher, an owner or admin can assign the finding. The assignment is written on that finding’s timeline, with the person’s name. The same person can dismiss it, and the reason is stored. Resolve and reopen are recorded the same way. Starter can read the current finding. It does not get that timeline.

Some rules are mechanical. For trailing whitespace or a missing final newline, Slack can open a draft pull request that contains that one-line edit. Every other finding stays a labeled plan. The pull request says a person must review it. DebtDetect does not describe that commit as a completed fix.

Test files and copies under legacy-reference can still show a credential-shaped match. They stay on the report so they are not hidden, and they are not priced as production debt. One match is counted per file and rule. The production item is the one that should drive the critical total.

Read a report

A completed scan can be downloaded as a PDF. The header is the repository name, the scan date, the scan time, and a short commit id. Under that are health, debt, the finding count, and the monthly exposure range. An exposure table lists remediation effort, remediation cost, monthly effort, monthly exposure, and annual exposure, each as low, midpoint, and high.

Findings follow, grouped by severity. Each group shows a count, hours, and cost. Each row shows the file, the rule, the category, the hours, the cost, and a short explanation. A scan with nothing recorded says so, instead of inventing a table.

On the site, Reports and the repository page list the same scans. Newest is first. Latest marks the newest completed scan for that repository. An older row still downloads that specific scan. The file name includes the repository and the timestamp, so two downloads do not look like the same file.

A download is the PDF on your computer. It does not send email. A clean scan, with no findings and no monthly cost, is never emailed. If a person asks for an overview of a scan that has findings or a monthly cost, that message is sent from noreply@debtdetect.org to that person’s own address. It is not the full PDF, it is not copied to support, and noreply@debtdetect.org does not accept replies. For help, write to hello@debtdetect.org.

Connect Slack

Each DebtDetect workspace connects one Slack workspace that belongs to that company. Another company does not join the Slack that owns the DebtDetect app, and your company does not have to join anyone else’s. An owner or admin opens Workspace and chooses Connect. Slack asks them to approve the install in their own Slack. DebtDetect returns to the workspace page and shows that Slack’s name. Reconnect replaces the install for this DebtDetect workspace only.

Starter can connect and can receive a direct message when a scan that person started finishes or fails, after they turn on Slack alerts and link their identity. The bot and the Monday digest require Pro or higher. In Slack, /debt-detect or a mention of DebtDetect can list top findings, explain a finding, describe a fix, queue a scan, or ask what changed in the last week. Preparing a fix opens the draft pull request described above, and only when that person’s role and the workspace controls allow it.

Linking is personal. One person linking their Slack user does not connect a second company, and it does not link their teammates. Each person does it for themselves.

Do not paste Slack tokens, client secrets, or signing secrets into DebtDetect, chat, or email. The install stores an encrypted bot token for that company only.

Choose a plan

Starter at €34.51 a month, VAT included, is the scanner: 5 private repositories, 20 scans a day, 3 seats, 90 days of history, ranges, reports, alerts, and a Slack connection. Pro at €117.81, VAT included, adds the year of history, the confidence label, assignment and the timeline, the schedule, the Slack bot, and the narrow pull request. Business at €474.81, VAT included, adds the portfolio, the audit CSV, the controls for who may scan or open a pull request, the quiet window, the 90-day leadership PDF, and support mail that includes the workspace id. Paying yearly is 10% off and still includes VAT: Starter €372.47, Pro €1,272.11, Business €5,127.71. Enterprise is a quote. It is the company login, the removal path, the annual invoice, the security packet, the scan queue, and the audit token. There is no Enterprise price on the homepage.

Starter is €34.51 a month, VAT included (€29 net). Pro is €117.81, VAT included (€99 net). Business is €474.81, VAT included (€399 net). Paying yearly is 10% off the net year, and that price also includes VAT: Starter €372.47, Pro €1,272.11, Business €5,127.71. A saved EU VAT ID uses reverse charge and VAT is €0. The receipt always shows net, VAT, and total.

What not to paste

Feedback belongs in Help inside the app. Describe what you did, what you expected, and whether you were blocked. Do not paste source code, tokens, passwords, customer data, or the contents of a finding that includes a secret. The report already omits matched secret values on purpose.

Support is hello@debtdetect.org. Business and Enterprise receive a reply on business days. Include the workspace id, which Help can place in the subject line, so a reply can find the right account.