ROI calculator

A back-of-envelope number for your security review

Three inputs, three outputs, no telemetry. The arithmetic is shown; adjust the inputs to match your stack.

Your team

What changes (annual estimates)

Supply-chain incidents prevented

0.8/ year

Assumes 0.6 incidents per 100 developers per year (our conservative estimate), scaled by Chainsaw's install-path coverage.

Time saved on dependency review

1,300hours / year

25 min per developer per week, 40% cut once policy refuses on the install path. Adjust if your review cadence is different.

Cache-hit CI savings

$691/ year

7,200 CI minutes saved per month at $0.008/min (GitHub-hosted Linux range), 30% cache-hit baseline, counting a quarter of each cached build's minutes as saved.

These are estimates from public benchmarks, not contractual claims. Want a number tuned to your stack?

Book a 30-min walkthrough
Assumptions and source notes
  • Incidents per 100 developers per year: 0.6 is our own conservative assumption, not a published figure. Sonatype's State of the Software Supply Chain reports (2022-2024) track hundreds of thousands of malicious packages a year; real exposure varies by ecosystem and dependency fan-out.
  • Chainsaw install-path coverage: 85%. Reflects coverage of npm, pip, Maven, Docker, NuGet, Cargo, Go, and 9 more ecosystems — not 100%, because adversary novelty always carries residual risk.
  • Review-time saved: 25 min per developer per week reading SCA reports, 40% cut after install-path enforcement. Both numbers are tuneable above; tweak inputs to match your team.
  • Cache savings: 30% cache-hit rate, a quarter of a cached build's minutes counted as saved, $0.008/min CI-runtime estimate. Self-hosted runners and air-gapped deployments will diverge.
  • No telemetry leaves your browser — every number is computed client-side from the inputs above.

Where the numbers come from

Source notes

The calculator is a model, not a measurement. Argue with any row.

AssumptionValue usedBasis
Incident frequency0.6 incidents per 100 developers per year, scaled by install-path coverage of 16 ecosystemsConservative assumption; Sonatype SSSC reports (2022-2024) track hundreds of thousands of malicious packages a year
Install-path coverage85% of incidents in scopeEngineering assumption
Dependency-review time25 minutes per developer per week; install-path enforcement removes the cause of ~40% of those ticketsEngineering-time assumption
CI cost savings30% cache-hit rate on the 25% of build time spent installing dependencies, $0.008/min CI runtimeGitHub-hosted-Linux range; self-hosted runners diverge
Install share of build time25% of each CI minute is dependency installEngineering assumption

A back-of-envelope estimate only: no contractual SLA, refund formula or price negotiation tool.

Want a real number, not an estimate?

30 minutes, your CI metrics, our cost model

Bring last quarter's CI build count and SCA ticket volume; leave with a refined number for your security review.