Keep every repo smelling fresh.
Patch one repo. Patch them all.
You bring your own Claude key. We never see your code, your credentials, or your cloud. Pricing scales with the size of your portfolio — not with how often you ship.
How it works.
One scenario, end-to-end. From the developer who merged the upgrade to the audit row your compliance team can hand to legal.
- 01
A clean upgrade lands.
A developer merges a NuGet bump, a framework migration, or a custom refactor on one repo. Your CI pipeline runs `stc analyze` after the unit tests. STC records what changed — never the source.
a3f91e chore(deps): bump MediatR 10 → 11 main - 02
STC checks every related repo.
Without ever seeing your source, STC compares the change against every other repo your team has connected. It picks out the matches, ignores the rest, and respects the ones you've intentionally pinned.
- ✓
billing-api - ✓
orders-svc - ✓
fulfillment-worker - ✓
notifications-api - ✓
reporting-svc - ✓
auth-gateway - —
legacy-monolith
- ✓
- 03
Six other projects use the same package.
Your dashboard surfaces the propagation as one row, with the affected repos counted. Approve once and STC kicks off the work — or queue it for a quiet Friday.
Pending propagations 6MediatR 10 → 11Propagate → - 04
Pull requests open themselves.
STC drafts the equivalent change for every matching repo. Branch, diff, summary, migration notes — wired up exactly the way your team would have written them. Your reviewers review, your team merges.
billing-apichore(deps): bump MediatR 11.0 · +24 −18orders-svcchore(deps): bump MediatR 11.0 · +24 −18fulfillment-workerchore(deps): bump MediatR 11.0 · +31 −22+ 3 more - 05
An audit trail you can hand to legal.
Every detection, every PR, every approval — timestamped, signed, exportable. SBOM-friendly logging built for the EU Cyber Resilience Act's 24-hour reporting window and vulnerability-handling requirements.
2026-04-28 14:32MediatR 10 → 11 detectedbilling-api2026-04-28 14:34Propagation queued6 targets2026-04-28 14:51PRs opened & signed6 / 6
Pay for the projects you manage. Not the work we do.
Fair pricing, by design.
Backports stay unlimited on every tier. Capacity is what you pay for — and there's a generous free tier for small portfolios.
Try STC on a small portfolio. Bring your own Claude key.
- ✓Bring your own Claude API key
- ✓Unlimited backports
- ✓1 team member
- ✓Community support
- ✓Audit log retained 30 days
For one team running a handful of services.
- ✓Everything in Free
- ✓Up to 5 team members
- ✓Email support
- ✓Audit log retained 1 year
- ✓Published upgrade paths
For an engineering org maintaining a real portfolio.
- ✓Everything in Starter
- ✓Up to 25 team members
- ✓Role-based access control
- ✓Bulk backport operations
- ✓Slack & webhook integrations
- ✓Priority email support
For organisations standardising across many products.
- ✓Everything in Team
- ✓Unlimited team members
- ✓Single sign-on (SAML / OIDC)
- ✓SCIM provisioning
- ✓Custom detection rules
- ✓Dedicated onboarding
On-premise, regulated industries, or bespoke contractual terms.
- ✓Everything in Business
- ✓On-premise runner
- ✓Air-gapped operation
- ✓CRA-aligned vulnerability handling
- ✓Custom SLAs & contractual terms
- ✓Dedicated success manager
Add-ons.
Optional packages, priced separately. Add when you need them, drop when you don't.
Everything regulated teams ask for in procurement, gathered into one signed package.
- ✓Security overview & CAIQ on request
- ✓Signed Data Processing Addendum
- ✓Audit log retained 3 years
- ✓Quarterly process review
Available on Business and Custom
Add capacity to any paid tier without re-papering the contract.
- ✓Stacks with your tier's included capacity
- ✓Pro-rated when you add it mid-cycle
- ✓Same backport & integration limits
- ✓Cancel any time
Available on Starter, Team, and Business
Questions, answered honestly.
Pricing is the place where vague answers cost real trust. Here are the questions we get most often.