This is the one route here that meters per seat — and the seat count you are quoted is rarely the seat count you end up paying for.

Seats drift because access is easy to grant and nobody audits it. Then the second meter arrives: CI minutes, build runners, monitor runs and AI assistants are all billed apart from the licence they sit beside.

GitHub, GitLab and Bitbucket all meter build minutes separately from seats. A busy pipeline can exceed the seat bill entirely — and nothing in the platform warns you before the invoice does.

Already decided — What this page decides

One platform or a toolchainGitLab's whole pitch against GitHub plus best-of-breed
What the second meter costsCI minutes, runners and AI assistants, all billed apart from seats
Whether self-hosting is requiredthe documented route to India residency for most of these

Still yours to weigh

CI cost more than seats last monthpipeline discipline, not a new vendor
A renewal counts developers who leftaudit seats against commit activity
Repository data cannot leave Indiaself-hosted GitLab or GitHub Enterprise Server
What this covers

Source, pipeline, APIs and secrets — four bills, not one.

Thirteen products across four jobs. Four are platforms or source control — where the code lives and how it ships. Four are API lifecycle tooling. Three are infrastructure and secrets, adjacent to the pipeline rather than inside it. And two are AI assistants, licensed separately from the platforms they run in.

Application security appears here as a section, not a route: SAST, dependency and secrets scanning ship inside the SCM platforms and are compared below. Runtime and cloud posture — CNAPP, WAF — are a different purchase entirely and live on the Security and Network Security categories, cross-linked and not repeated here.

The row to get exactly right

The licence unit, and the second meter beside it. GitHub, GitLab, Atlassian and Postman price per user; Terraform meters managed resources; Vault meters clients; JetBrains licenses per named user or a floating pool. Then CI minutes, runners, monitor runs and AI seats are billed apart. Model the total, never the per-seat rate.

Often confused withObservability & APM — proving it works under real traffic·Databases & Data Tools — the schema change the pipeline ships·Cloud & Workload Security — CNAPP, the runtime half of scanning

All three DevOps guides

Boundary — the terms this buyer confuses

Four terms, resolved

These are not tiers. A DevOps platform is not source control done better — it is four purchases bundled, and whether that is cheaper depends entirely on how many of the four you would otherwise buy.

SCM vs CI/CD

Where the code lives, or what happens when it changes?

SCM vs DevOps platform

One vendor, or best-of-breed?

IDE licensing vs seat licensing

Who is the licence attached to?

Secrets management vs configuration

A credential, or a setting?

The practical consequence: price the whole toolchain, not the seat. Every product here has a second meter, and the second meter is where the forecast breaks.
The decision variables

Six things decide this purchase. The feature grid is none of them.

Seven variables move the shortlist.

01

One platform or best-of-breed

GitLab's case is strongest when you use most of it. Using SCM and CI alone means paying for planning and scanning you do not touch.

02

CI/CD minutes and runner costs

Metered separately everywhere, and frequently larger than the seat bill. Self-hosted runners trade the meter for machines you operate.

03

Self-hosted or SaaS

The documented route to India residency for GitHub Enterprise Server and GitLab self-managed. It moves upgrades onto your team.

04

The licence unit

Named user, concurrent, floating or per-organisation. JetBrains and Atlassian differ sharply from GitHub and GitLab here.

05

AI assistant bundling

The fastest-moving variable in this category. Generous in the trial, itemised at renewal — model the tier plus the assistant.

06

Pipeline security scanning

SAST, dependency and secrets scanning are in the platform tiers. Runtime and cloud posture are a different purchase entirely.

07

Contractors and occasional committers

Every model treats them differently, and this is where seat counts drift furthest from headcount.

The narrowing instrument · the reasoning is the product

Narrow 13 products to your shortlist

Pick the job and the way it has to bill. Products drop out with the reason stated, never silently.

What you need it to do

How it has to run

How it bills

India

India residency is annotated rather than used to eliminate: no vendor here documents an Indian SaaS region, and for most of them self-hosting is the documented route.

Still in13/ 13
GitHub
PricePer seat + minutes

per user / month for the platform, with GitHub Actions CI metered separately in minutes and Advanced Security licensed as an addition; Enterprise Cloud or Enterprise Server for self-hosting

Teams that want the largest ecosystem, the deepest third-party integration and the hiring advantage of the tool most developers already know.

The catch: Three meters on one platform: seats, Actions minutes and Advanced Security. The minutes line is the one that surprises — a busy monorepo pipeline can exceed the seat bill without anybody noticing until the invoice.

Largest ecosystemMinutes metered apartAdvanced Security is extra
Open the intel page
GitHub
PricePer seat, published

per user / month, published tiers, licensed separately from GitHub Enterprise; code completion, chat and agentic assistance inside the editor and the pull request

Teams where the measurable win is time-to-first-draft on routine code, and where the editors in use are supported.

The catch: A separate line at renewal, however generous the trial was. Seat counts drift upward faster than developer headcount because access is easy to grant and nobody audits it.

Separate licencePublished per seatSeat drift is real
Open the intel page
GitLab
PricePer seat + minutes

per user / month across Free, Premium and Ultimate, with CI minutes metered separately; SCM, CI/CD, security scanning, packages and planning under one licence — Ultimate carries the full scanning set

Estates that want one vendor and one bill across the whole toolchain rather than integrating four products — and self-managed installation where India residency requires it.

The catch: The single-platform case is strongest when you use most of it; teams using SCM and CI alone pay for planning and scanning they do not touch. Self-managed means you own the upgrades, which is a standing job.

One platform, one billSelf-managed availablePay for the whole platform
Open the intel page
GitLab
PricePer seat add-on

per user / month as an addition to a GitLab tier; AI code suggestions, chat, vulnerability explanation and merge-request summaries inside the platform

GitLab estates that want AI assistance without introducing a second vendor's tooling and a second data-handling conversation.

The catch: An add-on rather than an inclusion — the same renewal surprise as Copilot. Capability depends on the underlying GitLab tier, so the comparison is tier-plus-Duo against a rival's equivalent.

Add-on to a tierStays inside GitLabTier-dependent
Open the intel page
Atlassian
PricePer user + minutes

per user / month with Pipelines build minutes metered separately; source control that shares identity, permissions and issue linking with Jira

Organisations already standardised on Jira that want source, branches and pull requests linked to the work item without an integration to maintain.

The catch: A smaller ecosystem than GitHub or GitLab, and the strongest case assumes Jira. Atlassian pricing steps at user-count thresholds, so crossing one costs more than the extra seats suggest.

Jira-nativeTier jumps at thresholdsSmaller ecosystem
Open the intel page
Atlassian
PricePer user, published

per user / month across Free, Standard, Premium and Enterprise, published; issue tracking and planning for software teams, linked to the branch and the deployment

Engineering organisations that need the work item, the branch and the release connected — the planning half of the toolchain rather than the code half.

The catch: Planning, not source control or CI. Pricing steps at user-count thresholds and the jump is the thing to model — crossing 100 users is not a linear increase.

Planning, not SCMPublished per userThreshold jumps
Open the intel page
Postman
PricePer user, published

per user / month with a free tier; the client most API developers already have open — requests, environments, collections and history

Any team building or consuming APIs, which is nearly all of them — this is usually already in use before it is ever purchased.

The catch: The free tier is genuinely capable, so the paid case is collaboration and governance rather than the client itself. Shadow usage on free accounts is common and worth auditing.

Already in useFree tier is capableAudit shadow usage
Open the intel page
Postman
PriceIn the Postman tiers

within the per-user Postman tiers; schema-first API design with OpenAPI, mocking and documentation generated from the contract rather than written after it

Teams where the API contract needs agreeing before implementation — typically where a separate team consumes it.

The catch: Design-first is a working practice more than a product: without the discipline, the tool produces schemas nobody updates. Value depends on adoption, not licences.

Contract-firstNeeds the disciplineIn the tiers
Open the intel page
Postman
PriceIn the Postman tiers

within the per-user tiers, with monitor runs metered separately; automated API tests that run in CI and on a schedule against live environments

Teams whose integration failures are found by customers rather than by the pipeline.

The catch: Scheduled monitor runs are a separate meter from seats — small, but a second meter nonetheless. It tests the API, not the user journey through the interface.

Runs in CIMonitors metered apartAPI-scoped
Open the intel page
Postman
PriceEnterprise tiers

in the Enterprise per-user tiers; API standards enforcement, secret detection in collections, and visibility of every API the organisation has published

Organisations with more APIs than anyone can list, and no consistent standard across teams.

The catch: Governance is only as real as the enforcement: rules that warn rather than block are ignored within a quarter. Enterprise-tier only.

API inventoryEnterprise tierEnforcement or theatre
Open the intel page
HashiCorp
PricePer managed resource

HCP Terraform priced per managed resource per month with a free tier; Terraform Enterprise self-hosted on quote — infrastructure as code with state management, policy and a run history

Teams whose infrastructure changes should be reviewed, versioned and repeatable rather than clicked in a console.

The catch: The per-managed-resource meter means the bill tracks infrastructure sprawl, not team size — a resource nobody uses still counts. IBM-owned since 2025, which some estates weigh in a multi-year commitment.

Per managed resourceSprawl moves the billIBM-owned
Open the intel page
HashiCorp
PriceQuote (per client)

quoted on active clients for HCP Vault or Vault Enterprise; centralised secrets with dynamic credentials, rotation and an audit trail — the machine-identity half of the toolchain

Estates where credentials currently live in CI variables and configuration files, and somebody has finally asked who can read them.

The catch: Client-based metering is hard to forecast, because a client is any application or workload that authenticates. Vault is also an operational commitment: it becomes a critical dependency the day you adopt it.

Dynamic secretsClient-meteredBecomes critical infrastructure
Open the intel page
HashiCorp
PriceQuote (per service)

quoted per service instance; service discovery, health checking and service-mesh networking with mutual TLS between services

Estates running many services across environments where discovery and service-to-service encryption are the operational gap.

The catch: A service mesh is a serious architectural commitment with its own failure modes, and many estates adopt one before they need it. If service count is modest, native platform networking is usually enough.

Service meshArchitectural commitmentOften adopted too early
Open the intel page
Why each constraint rules out what it doesShow the reasoning ↓

one platformRules out Atlassian Bitbucket, Postman API Client, Postman API Design, Postman API Testing, Postman Governance, HashiCorp Terraform, HashiCorp Vault and HashiCorp Consul — one layer of the toolchain, not the whole platform. That leaves GitHub Enterprise, GitHub Copilot, GitLab DevSecOps Platform, GitLab Duo and Atlassian Jira.

pipeline scanningRules out GitHub Copilot, GitLab Duo, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing, HashiCorp Terraform and HashiCorp Consul — no pipeline security scanning; Atlassian Bitbucket, Postman Governance and HashiCorp Vault — one scanning type only, not the SAST + dependency + secrets set. That leaves GitHub Enterprise and GitLab DevSecOps Platform.

API toolingRules out GitHub Enterprise, GitHub Copilot, GitLab DevSecOps Platform, GitLab Duo, Atlassian Bitbucket, Atlassian Jira, HashiCorp Terraform, HashiCorp Vault and HashiCorp Consul — not API-lifecycle tooling. That leaves Postman API Client, Postman API Design, Postman API Testing and Postman Governance.

infrastructure and secretsRules out GitHub Enterprise, GitHub Copilot, GitLab DevSecOps Platform, GitLab Duo, Atlassian Bitbucket, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing and Postman Governance — not infrastructure or secrets tooling. That leaves HashiCorp Terraform, HashiCorp Vault and HashiCorp Consul.

self-hostingRules out GitHub Copilot, Atlassian Bitbucket, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing and Postman Governance — SaaS only, so India residency cannot be met by deployment choice. That leaves GitHub Enterprise, GitLab DevSecOps Platform, GitLab Duo, HashiCorp Terraform, HashiCorp Vault and HashiCorp Consul.

AI assistanceRules out Atlassian Bitbucket, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing, Postman Governance, HashiCorp Terraform, HashiCorp Vault and HashiCorp Consul — no AI assistant documented for this product. That leaves GitHub Enterprise, GitHub Copilot, GitLab DevSecOps Platform and GitLab Duo.

per-seat pricingRules out HashiCorp Terraform — consumption-metered: the bill tracks resources, not people; HashiCorp Vault and HashiCorp Consul — quote-only, and metered on clients or services rather than seats. That leaves GitHub Enterprise, GitHub Copilot, GitLab DevSecOps Platform, GitLab Duo, Atlassian Bitbucket, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing and Postman Governance.

no metered minutesRules out GitHub Enterprise, GitLab DevSecOps Platform and Atlassian Bitbucket — CI minutes are metered separately and routinely exceed the seat bill. That leaves GitHub Copilot, GitLab Duo, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing, Postman Governance, HashiCorp Terraform, HashiCorp Vault and HashiCorp Consul.

published pricingRules out HashiCorp Vault and HashiCorp Consul — quote-only. That leaves GitHub Enterprise, GitHub Copilot, GitLab DevSecOps Platform, GitLab Duo, Atlassian Bitbucket, Atlassian Jira, Postman API Client, Postman API Design, Postman API Testing, Postman Governance and HashiCorp Terraform.

an Indian regionRules nothing out on published terms. It flags GitHub Enterprise — No Indian SaaS region is documented, GitHub Copilot — No Indian region is documented and there is no self-hosted option, GitLab DevSecOps Platform — No Indian SaaS region is documented, GitLab Duo — No Indian SaaS region is documented, Atlassian Bitbucket — No Indian region is documented and there is no self-hosted option, Atlassian Jira — No Indian region is documented and there is no self-hosted option, Postman API Client — No Indian region is documented and there is no self-hosted option, Postman API Design — No Indian region is documented and there is no self-hosted option, Postman API Testing — No Indian region is documented and there is no self-hosted option, Postman Governance — No Indian region is documented and there is no self-hosted option, HashiCorp Terraform — No Indian SaaS region is documented, HashiCorp Vault — No Indian SaaS region is documented and HashiCorp Consul — No Indian SaaS region is documented — marked on the cards, not removed.

The minutes are the surprise, not the seatsGitHub Actions, GitLab CI and Bitbucket Pipelines all meter build minutes separately from the seat licence. A busy monorepo with a matrix build can exceed its seat bill without anybody noticing until the invoice — and the fix is pipeline discipline, not a different vendor.

Seat counts drift upward, quietlyAccess is easy to grant and nobody audits it. Contractors, occasional committers and people who left the team last quarter all count. Audit against actual commit activity before every renewal; it is the cheapest saving in this route.

AI assistants are bundled in the trial, itemised at renewalCopilot and GitLab Duo are both separate licences however the pilot was framed. Model the platform tier PLUS the assistant when comparing vendors, because that is the number you will pay in year two.

JetBrains is carried but not ranked hereTechBag sells JetBrains licences and it belongs in this route. There are no intel pages yet, so it is named and not ranked rather than silently omitted. Its licence unit differs materially from everything carded here — per named user or a floating pool, which changes the maths for teams with part-time or shift-based developers.

Narrow to your situation

Eight situations, and what each one buys

If one of these is your sentence, the shortlist is short.

We want one vendor for the whole toolchain

Why: SCM, CI, packages, scanning and planning under one licence and one renewal conversation.

The trade-off: You pay for the whole platform whether or not you use the whole platform. Price it against what you would otherwise buy.

Repository data cannot leave India

Why: Self-hosting is the documented residency route — no vendor here publishes an Indian SaaS region.

The trade-off: Somebody owns upgrades, backups and availability. That role is the real cost, and it is usually unassigned at signature.

CI cost more than the seat licences last month

Why: Both support self-hosted runners, which trades the per-minute meter for machines you already pay for.

The trade-off: Self-hosted runners are infrastructure you now maintain and secure — and a compromised runner is a supply-chain problem.

Everything already runs through Jira

Why: Shared identity, permissions and issue linking with no integration to build or maintain.

The trade-off: Smaller ecosystem than GitHub or GitLab, and Atlassian pricing steps hard at user-count thresholds.

Nobody can list the APIs we have published

Why: An inventory of every published API plus enforceable standards across teams.

The trade-off: Enterprise tier, and governance that warns rather than blocks is ignored within a quarter.

Credentials live in CI variables and config files

Why: Centralised secrets with dynamic credentials, rotation and an audit trail of who read what.

The trade-off: Client-based metering is hard to forecast, and Vault becomes critical infrastructure the day you adopt it.

Infrastructure changes are clicked in a console

Why: Infrastructure as code with state, policy and a reviewable run history.

The trade-off: Per managed resource, so the bill tracks infrastructure sprawl rather than team size — unused resources still count.

We are deciding whether to licence an AI assistant

Why: Both are per-seat add-ons to their platform; the honest comparison is platform tier plus assistant, not assistant alone.

The trade-off: A separate line at renewal however the trial was framed, and seat counts drift upward faster than headcount.

Application security in the pipeline

Application security is a section here, not a route, because the bench is thin and the products are modules of platforms carded elsewhere. Three kinds of scanning ship inside the SCM platforms above:

  • SAST — reads your source for insecure patterns. Noisy until tuned, and the tuning is the project.
  • Dependency scanning — finds known vulnerabilities in libraries you did not write. The highest-value scan for the least tuning.
  • Secrets scanning — catches credentials before they are committed. A secret already pushed is leaked permanently; rotate it, do not delete the commit and hope.

GitHub carries all three in Advanced Security (an additional licence); GitLab carries the full set at Ultimate. The boundary is the deploy: everything above happens before it. Container and cloud posture scanning happens after, is a different purchase, and lives on Cloud & Workload Security. Web application firewalls are further out still and belong to Firewall & Network Security. Neither is carded here.

On JetBrains. TechBag carries JetBrains licences and they belong in this route. There are no intel pages for them yet, so JetBrains is named and not ranked rather than quietly left out — the same treatment given to SailPoint, Cato and Zerto elsewhere on this site. What matters commercially is that its licence unit is different from everything carded above: per named user, or a floating pool shared across a team. For an estate with contractors, shift work or part-time developers, a floating pool can be materially cheaper than per-seat SCM licensing, and the two models cannot be compared line-for-line. Ask us for a JetBrains quote alongside any shortlist here.

Ask before signature

  • How many CI minutes are included, what is the overage rate, and does it reset monthly?
  • What counts as a billable seat — repository access, or a commit in the period?
  • Is the AI assistant included at this tier, or a separate line at renewal?
  • Which scanning types are in this tier, and which need the security add-on?
  • Where does repository data reside, and is self-hosting the only residency route?
What breaks as you grow

What changes as the team grows

This route scales by developers — and by pipeline volume, which is not the same number.

1developers

Under 20 developers

  • Free tiers are genuinely capable here
  • CI minutes rarely exceed the allowance
  • One platform is simpler than a toolchain

Put this in your PoC

Prove the minutes against your real pipeline before paying.

2developers

20–100 developers

  • Seat drift starts — audit against commit activity
  • CI minutes become a visible line
  • Scanning tiers start to matter

Put this in your PoC

Audit seats before every renewal. It is the cheapest saving here.

3developers

100–500 developers

  • Self-hosted runners usually pay for themselves
  • Atlassian threshold jumps become material
  • AI assistant seats need a policy

Put this in your PoC

Model the tier jump, not the per-seat rate.

4developers

500+ developers

  • Self-hosting for residency and control becomes credible
  • Platform-versus-toolchain is a strategic decision
  • Secrets and IaC become critical infrastructure

Put this in your PoC

Name the owner for the self-hosted upgrade path before choosing it.

Where a vendor does not publish list pricing, this page says so rather than implying a figure.

The switching cost

Getting out

Git is portable. Everything built around it is not.

Repositories and history

Git is distributed by design — a clone is a complete copy

Exit costFully portable

Pipeline definitions

Vendor-specific YAML, rewritten for the new platform

Exit costRebuilt

Issues, boards and pull-request history

Exportable via API; the discussion context rarely survives intact

Exit costPartly portable

Secrets and IaC state

Vault and Terraform state are portable with planning, catastrophic without it

Exit costPlan it first

The practical consequence: the code is never the lock-in. The pipelines, the scanning configuration and the accumulated review history are, and none of them appear in a switching-cost estimate.

What it costs

What it costs

Per seat, plus the meters beside it, in USD and INR.

01

Do you already own one?

Four checks, in the order most likely to return a yes.

GitHub or GitLab free tiers
Both are genuinely capable for small teams They stop at required reviewers, advanced permissions, scanning and support — the compliance features, not the coding ones.
Your Atlassian licence
Bitbucket may already be in the bundle Worth checking before buying a second SCM — particularly where Jira is already the system of record.
Postman free accounts
Almost certainly already in use across your teams Shadow usage on personal accounts is the norm. Audit it, then decide the tier.
Open-source CI
Jenkins, Drone and Woodpecker are real options Costs infrastructure and an owner instead of a per-minute meter — the same trade as observability.

The free tiers here are unusually strong. The paid case is compliance, support and scale rather than capability.

02

What the rest actually cost

One meter you expect, and several you do not.

GitHub EnterprisePer user / month + CI minutesActions minutes metered separately; Advanced Security is an additional licence. Three meters on one platform.
GitLab (Free · Premium · Ultimate)Per user / month + CI minutesFull scanning set at Ultimate. Self-managed available where India residency requires it.
Atlassian Jira · BitbucketPer user / month + Pipelines minutesPublished, and steps at user-count thresholds rather than scaling linearly.
PostmanPer user / monthCapable free tier; monitor runs metered separately.
HashiCorp TerraformPer managed resource / monthHCP with a free tier; Enterprise self-hosted on quote. Tracks infrastructure sprawl, not team size.
HashiCorp VaultPer active clientA client is any application or workload that authenticates — hard to forecast.
HashiCorp ConsulPer service instanceScales with service count.
JetBrains — carried, not cardedPer named user, or a floating poolThe one model here that can be cheaper than headcount suggests. Ask us to quote it alongside any shortlist.

TechBag quotes every one of these in INR with GST, and models your actual volumes against each meter rather than comparing rates. Where a vendor publishes no list price, this page says so instead of repeating a third-party figure.

TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale at ≈₹83/$; the tier-matched INR quote is ours.

03

What isn’t in the licence price

CI/CD minutes and runners

Metered separately everywhere, and routinely larger than the seat bill on a busy pipeline.

AI assistant seats

Copilot and Duo are separate licences however generous the trial was.

Self-hosted operational burden

Upgrades, backups, availability and runner security. A role, not a line item.

Seats for people who have left

Access is easy to grant and nobody audits it. Check against commit activity, not the directory.

Before you commit

What goes wrong

Five ways this purchase goes wrong. Four of them are meters nobody modelled.

CI/CD minutes exceeding the seat bill

A matrix build on every push, on a busy monorepo. The fix is pipeline discipline and self-hosted runners, not a different vendor.

Seats counted per repository access rather than per active developer

Contractors, occasional committers and people who left all count. Audit against commit activity before every renewal.

Self-hosted chosen for residency, then nobody owns the upgrades

The residency requirement is met on day one and the platform is three versions behind by year two. Name the owner at signature.

The AI assistant licensed separately at renewal

Bundled generously in the trial, itemised afterwards. Compare platform tier plus assistant, not the tier alone.

Atlassian tier jumps at user-count thresholds

Crossing a threshold is not a linear increase. Model the jump before hiring past it.

Three doors — pick by where you are

Researching

See the whole landscape and where each product sits.

DevOps map →

Evaluating

Get your shortlist scoped against your real estate.

Scope my shortlist →

Buying

Tier-matched USD + INR quote with GST.

Get a quote →

Vendor-neutral. No gated content. · Last reviewed