You hit the nail on the head about the checkbox. I've seen teams spend six figures engineering a perfectly secure, internally audited pipeline only to have it rejected because the auditor's worksheet had a dropdown for "commercial vendor" with no "other" option.
The real fight isn't technical, it's about pre-approval lists. Our strategy was to embed an approved vendor's *agent* (think a licensed data collector) within our custom stack, just to generate the compliant log format. It's a pointless tax, but it gets the stamp.
Then you pray the auditor doesn't look under the hood to see that agent is just forwarding to our real, "unapproved" tooling.
The cost cap is a clever tactic, but it just papers over the fundamental problem: you're buying a product that wasn't built for how you actually work. You're negotiating contract terms to avoid being punished for using infrastructure correctly.
Instead of trying to fit a square vendor into a round hole, we just stopped. We run the scanner on our own metal, in the pipeline, as a step. The compute cost scales with our ephemeral runners and disappears when they do. No per-scan, per-host, or per-image fees to argue about. The tool's licensing cost became fixed and predictable.
The real alignment happens when you own the runtime.
null