ROI calculator
A back-of-envelope number for your security review
Three inputs, three outputs, no telemetry. The arithmetic is shown; adjust the inputs to match your stack.
Your team
What changes (annual estimates)
Supply-chain incidents prevented
0.8/ year
Assumes 0.6 incidents per 100 developers per year (our conservative estimate), scaled by Chainsaw's install-path coverage.
Time saved on dependency review
1,300hours / year
25 min per developer per week, 40% cut once policy refuses on the install path. Adjust if your review cadence is different.
Cache-hit CI savings
$691/ year
7,200 CI minutes saved per month at $0.008/min (GitHub-hosted Linux range), 30% cache-hit baseline, counting a quarter of each cached build's minutes as saved.
These are estimates from public benchmarks, not contractual claims. Want a number tuned to your stack?
Book a 30-min walkthroughAssumptions and source notes
- Incidents per 100 developers per year: 0.6 is our own conservative assumption, not a published figure. Sonatype's State of the Software Supply Chain reports (2022-2024) track hundreds of thousands of malicious packages a year; real exposure varies by ecosystem and dependency fan-out.
- Chainsaw install-path coverage: 85%. Reflects coverage of npm, pip, Maven, Docker, NuGet, Cargo, Go, and 9 more ecosystems — not 100%, because adversary novelty always carries residual risk.
- Review-time saved: 25 min per developer per week reading SCA reports, 40% cut after install-path enforcement. Both numbers are tuneable above; tweak inputs to match your team.
- Cache savings: 30% cache-hit rate, a quarter of a cached build's minutes counted as saved, $0.008/min CI-runtime estimate. Self-hosted runners and air-gapped deployments will diverge.
- No telemetry leaves your browser — every number is computed client-side from the inputs above.
Where the numbers come from
Source notes
The calculator is a model, not a measurement. Argue with any row.
| Assumption | Value used | Basis |
|---|---|---|
| Incident frequency | 0.6 incidents per 100 developers per year, scaled by install-path coverage of 16 ecosystems | Conservative assumption; Sonatype SSSC reports (2022-2024) track hundreds of thousands of malicious packages a year |
| Install-path coverage | 85% of incidents in scope | Engineering assumption |
| Dependency-review time | 25 minutes per developer per week; install-path enforcement removes the cause of ~40% of those tickets | Engineering-time assumption |
| CI cost savings | 30% cache-hit rate on the 25% of build time spent installing dependencies, $0.008/min CI runtime | GitHub-hosted-Linux range; self-hosted runners diverge |
| Install share of build time | 25% of each CI minute is dependency install | Engineering assumption |
A back-of-envelope estimate only: no contractual SLA, refund formula or price negotiation tool.
Want a real number, not an estimate?
30 minutes, your CI metrics, our cost model
Bring last quarter's CI build count and SCA ticket volume; leave with a refined number for your security review.