# ROI calculator | Chainsaw

> Estimate the supply-chain incidents prevented, dependency-review time saved, and CI cache-hit savings from running Chainsaw on the install path.

Source: https://chain305.com/roi/

---

ROI calculator

# A back-of-envelope number for your security review

Three inputs, three outputs, no telemetry. The arithmetic is shown; adjust the inputs to match your stack.

### Your team

DevelopersAnyone whose CI runs install commands.CI builds per monthAcross every repo, every branch.Average build time (minutes)From "kick off" to "green check."

### What changes (annual estimates)

Supply-chain incidents prevented

0.8/ year

Assumes 0.6 incidents per 100 developers per year (our conservative estimate), scaled by Chainsaw's install-path coverage.

Time saved on dependency review

1,300hours / year

25 min per developer per week, 40% cut once policy refuses on the install path. Adjust if your review cadence is different.

Cache-hit CI savings

$691/ year

7,200 CI minutes saved per month at $0.008/min (GitHub-hosted Linux range), 30% cache-hit baseline, counting a quarter of each cached build's minutes as saved.

These are estimates from public benchmarks, not contractual claims. Want a number tuned to your stack?

[Book a 30-min walkthrough](https://cal.com/chain305/30min)

Assumptions and source notes

-   Incidents per 100 developers per year: 0.6 is our own conservative assumption, not a published figure. Sonatype's State of the Software Supply Chain reports (2022-2024) track hundreds of thousands of malicious packages a year; real exposure varies by ecosystem and dependency fan-out.
-   Chainsaw install-path coverage: 85%. Reflects coverage of npm, pip, Maven, Docker, NuGet, Cargo, Go, and 9 more ecosystems — not 100%, because adversary novelty always carries residual risk.
-   Review-time saved: 25 min per developer per week reading SCA reports, 40% cut after install-path enforcement. Both numbers are tuneable above; tweak inputs to match your team.
-   Cache savings: 30% cache-hit rate, a quarter of a cached build's minutes counted as saved, $0.008/min CI-runtime estimate. Self-hosted runners and air-gapped deployments will diverge.
-   No telemetry leaves your browser — every number is computed client-side from the inputs above.

Where the numbers come from

## Source notes

The calculator is a model, not a measurement. Argue with any row.

Assumption

Value used

Basis

Incident frequency

0.6 incidents per 100 developers per year, scaled by install-path coverage of 16 ecosystems

Conservative assumption; Sonatype SSSC reports (2022-2024) track hundreds of thousands of malicious packages a year

Install-path coverage

85% of incidents in scope

Engineering assumption

Dependency-review time

25 minutes per developer per week; install-path enforcement removes the cause of ~40% of those tickets

Engineering-time assumption

CI cost savings

30% cache-hit rate on the 25% of build time spent installing dependencies, $0.008/min CI runtime

GitHub-hosted-Linux range; self-hosted runners diverge

Install share of build time

25% of each CI minute is dependency install

Engineering assumption

A back-of-envelope estimate only: no contractual SLA, refund formula or price negotiation tool.

Want a real number, not an estimate?

## 30 minutes, your CI metrics, our cost model

Bring last quarter's CI build count and SCA ticket volume; leave with a refined number for your security review.

[Get started](https://chain305.com/chainsaw/signup) [Talk to sales](https://cal.com/chain305/30min)

---

## Long form

The full text behind this page, including detail the page itself leaves out.

ROI calculator

### A back-of-envelope number for your security review

Three inputs, three outputs, no telemetry. Drop in your team size and CI volume, get an estimate of incidents prevented, dependency-review time saved, and cache-hit cost savings. The arithmetic is shown — adjust inputs to match your stack.

##### Your team

DevelopersAnyone whose CI runs install commands.CI builds per monthAcross every repo, every branch.Average build time (minutes)From "kick off" to "green check."

##### What changes (annual estimates)

Supply-chain incidents prevented

0.8/ year

Based on Sonatype State of the Software Supply Chain — ~0.6 incidents per 100 developers per year, scaled by Chainsaw's install-path coverage.

Time saved on dependency review

1,300hours / year

25 min per developer per week, 40% cut once policy refuses on the install path. Adjust if your review cadence is different.

Cache-hit CI savings

$691/ year

7,200 CI minutes saved per month at $0.008/min (GitHub-hosted Linux range), 30% cache-hit baseline.

These are estimates from public benchmarks, not contractual claims. Want a number tuned to your stack?

[Book a 30-min walkthrough](https://cal.com/chain305/30min)

Assumptions and source notes

-   Incidents-per-100-devs-per-year: derived from Sonatype's State of the Software Supply Chain reports (2022-2024); we use a conservative 0.6 baseline. Real rates vary by ecosystem and dependency fan-out.
-   Chainsaw install-path coverage: 85%. Reflects coverage of npm, pip, Maven, Docker, NuGet, Cargo, Go, and 9 more ecosystems — not 100%, because adversary novelty always carries residual risk.
-   Review-time saved: 25 min per developer per week reading SCA reports, 40% cut after install-path enforcement. Both numbers are tuneable above; tweak inputs to match your team.
-   Cache savings: 30% cache-hit rate, $0.008/min CI-runtime estimate. Self-hosted runners and air-gapped deployments will diverge.
-   No telemetry leaves your browser — every number is computed client-side from the inputs above.

Where the numbers come from

#### Source notes

The calculator is a model, not a measurement. Every assumption it bakes in is listed below so you can argue with it.

-   Incident frequency
    
    Sonatype State of the Software Supply Chain reports (2022-2024) tracked hundreds of thousands of malicious packages per year. We use a conservative 0.6 incidents per 100 developers per year baseline, scaled by Chainsaw's install-path coverage of 16 ecosystems.
    
-   Dependency-review time
    
    Average 25 minutes per developer per week reading SCA reports, triaging false positives, and responding to PR-blocking comments. Install-path enforcement removes the upstream cause for ~40% of those tickets.
    
-   CI cost savings
    
    Cached install bytes don't egress from upstream registries on repeat installs. We use a 30% cache-hit rate and a $0.008/min CI-runtime estimate (in the GitHub-hosted-Linux range). Self-hosted runners diverge — adjust the inputs.
    
-   What this isn't
    
    A contractual SLA, a refund formula, or a price negotiation tool. The page is a back-of-envelope estimate so a buyer can sanity-check the order of magnitude before scheduling a 30-minute call.
    

Want a real number, not an estimate?

#### 30 minutes, your CI metrics, our cost model

Bring last quarter's CI build count and SCA ticket volume. We'll plug them in, walk through the assumptions, and give you a refined number you can take into your security review.

[Get started](https://chain305.com/chainsaw/signup) [Talk to sales](https://cal.com/chain305/30min)
