anagentCompetitive Edge Audit

Ona (formerly Gitpod; product still reachable at gitpod.io, redirects to ona.com)

www.gitpod.io

10 ranked findings · 40 claims verified against source · 2 rejected

Executive summary

Ona's biggest structural problem is that the AI-agent-orchestration pitch it makes today sits on top of trust infrastructure still branded, reviewed, and proven as the old 'Gitpod' cloud-IDE product: G2 (16 stale reviews), AWS Marketplace (two split, still-Gitpod-seller listings with a live 2023 'avoid this vendor' review), and the homepage's own flagship proof points (an anonymous 'Top 100 global company') all read as thin or unverifiable next to Coder's and Cursor's named, current, high-volume equivalents. Layered on top of that is a self-serve monetization gap: security-basics like SSO and self-hosting, plus any path to a free trial, are gated behind either a $20/mo floor or a full sales cycle, while Coder, Cursor, Daytona and GitHub Codespaces all give a genuine zero-cost or self-serve path into the exact same capability. Both problems are fixable with low-to-medium effort (review campaigns, listing consolidation, named case studies, pricing-page disclosures) and should be sequenced ahead of any deeper repositioning work, especially with the OpenAI acquisition raising diligence scrutiny on exactly these signals.

The biggest gap

Ona's trust and proof infrastructure (G2, AWS Marketplace, LinkedIn, homepage case studies) is still running on the stale, low-volume, still-'Gitpod'-branded footprint of a discontinued product, undermining the credibility of the AI-agent-infrastructure pitch it is actually selling today.

Who you’re measured against

GitHub Codespaces

github.com/features/codespaces

Cloud-hosted development environments launched instantly from any GitHub repo, configured via devcontainer.json, accessible from browser or local IDE (VS Code, JetBrains). GitHub-only; cannot be self-hosted.

Pricing Free tier: 120 core-hours (60 hrs on a 2-core machine) + 15GB storage/month for individual GitHub accounts; pay-as-you-go metered compute/storage beyond that for individuals and organizations; org admins set spending controls.

Coder

coder.com

Self-hosted, enterprise development infrastructure: standardized cloud/on-prem developer workspaces plus 'Coder Agents' for running AI coding agents on customer-controlled infrastructure, with governance/audit features ('Coder AI Governance').

Pricing Community edition free/open-source (unlimited workspaces, templates, members, SSO); Premium is 'annually per user' custom-quoted (adds SLA support, multi-org access controls, audit logging, HA, group/role RBAC, custom branding).

Daytona

www.daytona.io

Secure, elastic sandbox infrastructure for running AI-generated/agent code — stateful sandboxes with sub-90ms/sub-200ms creation, snapshotting, Computer Use desktops (Linux/macOS/Windows), SSH/web terminal access; positions as 'infrastructure AI agents actually need' rather than a dev-environment/IDE product.

Pricing Usage-based pay-as-you-go: compute $0.0504/vCPU-hr, memory $0.0162/GiB-hr, storage $0.000108/GiB-hr (first 5GB free), GPU from $0.57/hr (RTX 4090) up to $2.61/hr (H200); $200 free compute credit; startup program up to $50k in credits; Enterprise custom (SSO, audit logs, BYOC).

Cursor (Anysphere)

cursor.com

AI coding agent product: IDE plus autonomous/background 'cloud agents' that build, test, and demo features end-to-end, usable in terminal, Slack, and GitHub PR review ('Bugbot'); supports multiple frontier models.

Pricing Hobby free; Individual (Pro/Pro+/Ultra) $20/month; Teams $40/user/month (Standard/Premium) with centralized billing, cloud agents, SSO; Enterprise custom (pooled usage, invoice billing, SCIM, audit logs).

Cognition (Devin)

cognition.com

'Devin,' described as an autonomous software engineer that plans, writes, tests, and ships production code independently inside customer codebases and existing tools; sold as an agent product rather than raw infrastructure, deployed at large enterprises.

Pricing Free tier; Pro $20/month; Max $200/month; Teams $80/month base + $40/month per full seat; Enterprise custom (VPC deployment, SAML/OIDC SSO, dedicated account team). Usage billed via included quota then dollar-metered overage (previously ACU-based).

10 moves, ranked

Ordered by impact, then by how little work they take. Start at the top.

1

On the two review surfaces buyers actually check, Ona is still living and dying as 'Gitpod' — 16-42 stale reviews under the old name vs. deep, current corpora at Coder and Cursor

ImpacthighEffortlow

G2's product page for the company is titled 'Gitpod Reviews 2026' with only 16 reviews at 4.3/5 (also listed via the seller profile g2.com/sellers/gitpod), and the visible reviews are dated between 2022 and April 2024, describing the legacy cloud-IDE product with no mention of Ona, background agents, Automations, or Veto. Direct competitors have far deeper, more current review corpora on the same platform: Coder shows 4.3/5 across 212 reviews, and Cursor shows 4.5-4.6/5 across 42-316 reviews depending on the profile checked. A buyer researching 'AI agent infrastructure' on G2 finds a thin, stale entry under a brand name (Gitpod) the company itself no longer leads with in its own marketing, and searching for 'Ona' on G2 returns nothing at all.

Why it matters: Enterprise buyers doing vendor diligence lean on G2 volume and recency as a trust signal, and right now Ona's review footprint reads as an abandoned, stale product rather than the category leader it claims to be, giving competitors with active review pipelines a credibility edge in side-by-side procurement.

Recommended move

Claim/rebrand the G2 profile as Ona, run an in-app review-refresh campaign to recent Enterprise/Core customers, work with G2 to update the listing title/branding from Gitpod to Ona, and build parallel presence on Gartner Peer Insights/TrustRadius if absent.

Buildable

Expected
The G2 listing is titled/branded 'Ona', with reviews dated within the current year referencing agents/Automations/Veto, at review volume comparable to Coder (212) or Cursor (42+).
Actual
Listing is titled 'Gitpod Reviews 2026', has only 16 reviews, most recent dated 04/03/2024, and none reference Ona, agents, Automations, or Veto.

Evidence · 5 verified claims

  • Gitpod's G2 product page has only 16 reviews at a 4.3/5 average, still under the Gitpod name.

    Gitpod By Gitpod 4.3/5 (16) 5 star 75% 4 star 18% 1 star 6%

    Source: www.g2.com/products/gitpod/reviews

  • The visible reviews are old, dated between 2022 and early 2024, predating the Ona rebrand.

    Jelle D. ... 2/7/2024 ... "In general you see that the market is still quite young for cloud IDEs" ... Adam T. ... 7/19/2022

    Source: www.g2.com/products/gitpod/reviews

  • Coder has 212 G2 reviews at 4.3/5; Cursor has 316 G2 reviews at 4.6/5 — both far deeper than Gitpod/Ona's 16.

    Coder By Coder 4.3/5(212) 5 star 55% 4 star 41% 3 star 2%

    Source: www.g2.com/products/coder/reviews

  • Gitpod's G2 profile shows only 16 reviews, averaging 4.3/5, with content describing the legacy dev-environment product.

    Gitpod has been rated 4.3 stars by 16 verified reviews on G2 ... Gitpod provides very fast VMs for using our codespaces on very end machines...browser version of code editors to directly code through any browser

    Source: www.g2.com/sellers/gitpod

  • The most recent review visible on Gitpod's G2 profile is dated April 2024.

    Rahul S. Great platform for faster and reliable codespaces. Reviewed on Apr 03, 2024 Review provided by G2

    Source: www.g2.com/sellers/gitpod

2

Self-hosted deployment and SSO/OIDC are both Enterprise-only and sales-gated, while Coder gives away both for free, self-serve, today

ImpacthighEffortmedium

Ona's pricing page lists 'Bank-grade VPC deployment' and 'SSO and OIDC identity and access controls' exclusively under the Enterprise tier ('Custom pricing'), with Core capped at Ona's own multi-tenant cloud only, and the compare table confirms Core's 'Compute Deployment' as 'Ona Cloud (multi-tenant)' versus Enterprise's 'Self-hosted, Ona-managed VPC.' The only route into that tier from the pricing page is 'Request a demo' — there is no price shown and no self-serve path. Coder's free, self-hosted Community edition already includes 'Single Sign-On (OpenID Connect)' and lets users 'Assign long-running tasks to AI coding agents' at $0, with no seat cap and no sales call required, so a security-conscious mid-market buyer can be running Coder in their own infrastructure the same afternoon while the equivalent Ona capability requires booking and surviving a sales cycle.

Why it matters: Buyers with basic security requirements (SSO) or infra-control requirements (self-hosting) who are not yet ready for a full enterprise contract have no paid self-serve tier to land on at Ona and default to Coder for free — a structural speed and pricing disadvantage in exactly the segment Ona's Enterprise tier targets.

Recommended move

Introduce a mid-tier self-serve SKU (e.g. 'Core+' or 'Team') that unlocks SSO/OIDC at a fixed self-serve price point, and publish indicative Enterprise/VPC starting pricing with a self-serve, time-boxed VPC trial that doesn't require booking a demo first.

Buildable

Expected
SSO/OIDC or a self-hosted deployment option is purchasable at a fixed, self-serve price without contacting sales.
Actual
SSO/OIDC and self-hosted VPC deployment appear only under the Enterprise column with 'Custom pricing' and a 'Request a demo' CTA — no self-serve price exists.

Evidence · 4 verified claims

  • Ona's Enterprise tier (only) includes VPC/self-hosted deployment and SSO/OIDC; Core is limited to Ona's multi-tenant cloud.

    Bank-grade VPC deployment ... SSO and OIDC identity and access controls ... Compute Deployment: Ona Cloud (multi-tenant) [Core] / Self-hosted, Ona-managed VPC [Enterprise]

    Source: www.gitpod.io/pricing

  • Coder's free Community edition includes SSO (OpenID Connect) and AI-agent task assignment, and is self-hosted by definition (open source install).

    ## Community Free For hobbyists and small teams ready to join Coder's open-source community. ... - Assign long-running tasks to AI coding agents - Single Sign-On (OpenID Connect)

    Source: coder.com/pricing

  • Ona's self-hosted/VPC deployment option is Enterprise-only and has no listed price or self-serve signup path

    Self-hosted, Ona-managed VPC [Enterprise row] ... EnterpriseCustom pricing ... [Get started] [Request a demo]

    Source: www.gitpod.io/pricing

  • Coder's free Community edition supports self-hosted install with SSO, no sales step required

    ## Community Free ... [Install open source] ... - Single Sign-On (OpenID Connect)

    Source: coder.com/pricing

3

AWS Marketplace — a channel enterprise buyers actually purchase through — carries two separate, non-identical 'Ona Enterprise' listings still sold under the name 'Gitpod'

ImpacthighEffortmedium

There are two live AWS Marketplace product pages: prodview-752jqvg74yo7k ('Ona Enterprise', sold by 'Gitpod', 4.3/5 from 16 external reviews) and prodview-vn4wpn7u4afrq ('Ona Enterprise (US)', showing a PeerSpot-style review plus teaser titles of the same old Gitpod-era G2 reviews duplicated from the first listing). Competitor Coder has a single AWS listing ('Coder Premium Edition') at 4.7/5 from 7 ratings with visible 'Top 10' accolade badges, and AWS's own 'Product comparison' feature explicitly pairs Coder Premium Edition against 'Ona Enterprise' by seller name 'Gitpod' on the same comparison table — putting the fragmented, lower-rated, still-Gitpod-branded listing directly next to a cleaner competitor at the exact moment procurement teams decide who to shortlist.

Why it matters: Procurement teams comparing vendors inside AWS Marketplace see a fragmented, lower-rated, still-Gitpod-branded footprint sitting right next to a cleaner, higher-rated, badge-decorated Coder listing at the exact moment they're deciding who to shortlist.

Recommended move

Consolidate the two AWS Marketplace listings into one canonical 'Ona Enterprise' entry, rebrand the seller name from Gitpod to Ona, and push for AWS Marketplace accolade eligibility now that review volume is being rebuilt.

Buildable

Expected
A single canonical 'Ona Enterprise' AWS Marketplace listing exists, sold under seller name 'Ona'.
Actual
Two separate listings exist ('Ona Enterprise' and 'Ona Enterprise (US)'), both sold under seller name 'Gitpod', with duplicated stale review titles.

Evidence · 3 verified claims

  • A first AWS Marketplace listing for Ona Enterprise is sold under the seller name 'Gitpod' and carries 4.3/5 from 16 external G2 reviews.

    Ona Enterprise Sold by Gitpod ... 4.3 16 ratings ... 0 AWS reviews | 16 external reviews External reviews are from G2

    Source: aws.amazon.com/marketplace/pp/prodview-752jqvg74yo7k

  • A second, separate 'Ona Enterprise (US)' listing exists with different content, including duplicated titles of the same old Gitpod-branded reviews.

    Rahul S. Great platform for faster and reliable codespaces. ... Hannes D. Elevate Your Development Workflow with Gitpod: A Game-Changer for Efficiency and Collaboration ... Robbert H. Cloud IDEs: fast onboarding and isolated reproducible environments ... Jelle D. Easy to set up, happy engineers and excellent support

    Source: aws.amazon.com/marketplace/pp/prodview-vn4wpn7u4afrq

  • Coder's AWS Marketplace listing carries a higher rating (4.7) and displayed 'Top 10' accolade badges, and AWS pairs it directly against Ona Enterprise in its comparison table.

    Coder Premium Edition ... 4.7 (7) ... #### Accolades Top 10 In Software Development, ML Solutions ... Product comparison ... Ona Enterprise [By Gitpod]

    Source: aws.amazon.com/marketplace/pp/prodview-zaoq7tiogkxhc

4

Ona's flagship proof points are anonymized customers and unattributed aggregate stats, while Coder and GitHub name the company and the person behind every number

ImpacthighEffortmedium

Ona's homepage leads its 'what customers achieve' section with a quote from an unnamed 'Top 100 global company' claiming '90-95% of migration work is done by Ona Automations,' and its headline stats (4x productivity, 83% of PRs co-authored, 400% productivity increase, 24/7 runs) are attributed only to anonymized tags like 'Global pharma company' and 'Top 100 global company' — never a named company or person. Named logos on the homepage (BNY, GSR, Vanta, Pearson, EquipmentShare, Hargreaves Lansdown) carry only a 'Since [year]' tag with no attached result. Coder's homepage, by contrast, headlines named-company case studies with quantified outcomes ('Dropbox Boosts Dev Onboarding Speeds by 4x', 'J.B. Hunt Reduces Developer VDI Costs by 90%', 'Palantir Tames Environment Configuration Drift with Coder'), and GitHub Codespaces attributes quotes to named individuals with titles (Clint Chester, Developer Lead, Synergy; Keith Annette, Cloud Capability Lead, KPMG UK).

Why it matters: Enterprise buyers comparing vendors for a security-governance purchase will discount unverifiable anonymous stats against named, checkable case studies from direct competitors, weakening Ona's strongest proof point at the exact moment it's meant to close the deal, and enterprise security/procurement reviewers will use this to slow or stall deals.

Recommended move

Get the 'Top 100 global company' and 'Global pharma company' customers to go on record (name + role + logo), or convert at least 3 of the existing named logos (BNY, GSR, Pearson) into full case studies with named contact, specific metric, and methodology, matching the Coder/GitHub pattern.

Buildable

Where
https://ona.com and https://ona.com/cases/dev-productivity
Expected
The 4x / 83% / 400% / 90-95% headline stats are each attributed to a named company and/or named person with a title.
Actual
Stats are attributed only to anonymized tags: 'Top 100 global company' and 'Global pharma company', with no name disclosed.

Evidence · 6 verified claims

  • Ona's headline productivity stat is attributed only to an anonymous 'Top 100 global company,' not a named customer or person.

    Top 100 global company > "90-95% of migration work is done by Ona Automations. We just have to do the final push commands."

    Source: ona.com

  • Coder attaches quantified outcomes directly to named enterprise customers on its homepage.

    Dropbox Boosts Dev Onboarding Speeds by 4x ... J.B. Hunt Reduces Developer VDI Costs by 90% with Coder

    Source: coder.com

  • GitHub Codespaces attributes its customer testimonials to named individuals with job titles and companies.

    "What used to be a 15-step process is just one step: open Codespaces and you're off and running." Clint Chester, Developer Lead, Synergy ... Keith Annette, Cloud Capability Lead, KPMG, UK

    Source: github.com/features/codespaces

  • Ona's headline productivity stats (4x, 83%, 400%) are attributed only to anonymized customers, not named ones.

    Global pharma company > "It's really impressive. I've tried other coding agents and it's not comparable." 400% productivity increase across our customers

    Source: ona.com/cases/dev-productivity

  • Ona's homepage customer logos carry no attached quantified result, only tenure.

    Shipping with Ona Since 2025 Since 2024 Since 2026 Since 2024 Since 2023 Since 2024 ... Top 100 global company > "90-95% of migration work is done by Ona Automations..."

    Source: ona.com

  • Coder attaches a named enterprise customer to each specific quantified outcome on its own homepage.

    Dropbox Boosts Dev Onboarding Speeds by 4x ... J.B. Hunt Reduces Developer VDI Costs by 90%

    Source: coder.com

5

Ona's pricing page shows no $0 entry point — every other agent-infra competitor lets a prospect start using the product before paying anything

ImpacthighEffortmedium

Ona's pricing page shows exactly one self-serve tier, 'Core from $20 / month,' with no free plan listed anywhere on the page content fetched. Every named competitor gives a genuine zero-cost way in: GitHub Codespaces is free up to 60 hours/month, Cursor's Hobby tier is free with 'No credit card required,' Daytona gives '$200 in free compute included' on top of a pay-as-you-go floor, and Coder's Community edition is free and open-source indefinitely. For a buyer comparing 'infrastructure to run AI coding agents,' Ona is the only option in this set that requires a paid commitment before first use.

Why it matters: In a category where four out of five named rivals let a developer try the product for free before typing in a credit card, Ona's $20/mo floor is a real conversion tax on the exact self-serve individual/small-team buyer its Core tier claims to target.

Recommended move

Ship a genuinely free (even heavily rate-limited) tier or a no-card-required trial with a fixed OCU allowance, positioned against Cursor's Hobby and GitHub's free Codespaces hours.

Buildable

Expected
A $0 tier is listed and purchasable with no credit card, comparable to Cursor's Hobby or GitHub Codespaces' free hours.
Actual
Page lists only 'Core from $20/month' and custom-priced 'Enterprise' — no free plan appears anywhere in the page content.

Evidence · 5 verified claims

  • Ona's Core plan starts at $20/month with no free tier disclosed on the pricing page

    Corefrom$20/month Ideal for individual users and teams

    Source: www.gitpod.io/pricing

  • GitHub Codespaces offers a genuinely free individual tier

    Codespaces is free for individual use up to 60 hours a month and comes with simple, pay-as-you-go pricing after that.

    Source: github.com/features/codespaces

  • Cursor's entry tier is free with no card required

    ### Hobby Free Includes: ✓ No credit card required ✓ Limited Agent requests ✓ Access to Composer

    Source: cursor.com/pricing

  • Daytona includes free compute before any charge applies

    Build for free, pay as you scale. ... Use what you need, when you need it. $200 in free compute included.

    Source: www.daytona.io/pricing

  • Coder's Community edition is free and self-hosted with no sales step

    ## Community Free For hobbyists and small teams ready to join Coder's open-source community.

    Source: coder.com/pricing

6

Ona's free tier is a one-time 40-OCU grant that never refills, while GitHub Codespaces' free tier renews every month forever

ImpactmediumEffortlow

On gitpod.io/pricing, the plan-comparison table lists the Free plan's included OCUs as "40 OCUs (one time)" versus Core's "80 - 2,200 OCUs (monthly recurring)" — the free allocation is explicitly one-off, not a recurring monthly quota. GitHub Codespaces, by contrast, states its free allowance is "120 core hours or 60 hours of run time on a 2 core codespace, plus 15 GB of storage each month," a quota that resets every month indefinitely. This means an individual developer or small team evaluating Ona for free burns through their entire allotment once and then must pay, while the same evaluator can keep using Codespaces for free indefinitely at low volume.

Why it matters: A one-time free grant converts evaluators into paying customers faster but also disqualifies Ona from the low-commitment, indefinitely-free 'try it on a side project' use case that Codespaces still owns, ceding that acquisition channel entirely.

Recommended move

Either make the Free plan's OCU allowance monthly-recurring (even at a lower amount, e.g. 20-40 OCUs/month) or stop competing on the word 'Free' and reposition it explicitly as a one-time trial credit in the marketing copy, since prospects comparing it to Codespaces' free tier will feel misled once they hit the wall.

Buildable

Expected
The Free plan's included OCUs are labeled as a recurring monthly allowance, matching the 'monthly recurring' framing used for Core.
Actual
The compare-plans table labels the Free plan's OCUs as '40 OCUs (one time)'.

Evidence · 2 verified claims

  • Ona's Free plan gives 40 OCUs as a one-time grant, not a recurring monthly allowance.

    Included OCUs 40 OCUs(one time) 80 - 2,200 OCUs(monthly recurring)

    Source: www.gitpod.io/pricing

  • GitHub Codespaces' free tier is a recurring monthly allowance (120 core-hours + 15GB storage), not a one-time grant.

    GitHub will provide users in the free plan 120 core hours or 60 hours of run time on a 2 core codespace, plus 15 GB of storage each month.

    Source: github.com/features/codespaces

7

OCU pricing is opaque and unpredictable — real per-hour rates live in a separate docs page and consumption varies 1-8x per task, while Daytona and Cursor publish exact, computable prices upfront

ImpactmediumEffortlow

Ona's pricing page shows "Core from $20/month" and "80 - 2,200 OCUs," but never states what an OCU costs in dollars or how fast it drains; that information ("Standard | 4 vCPUs / 16GB RAM | 1 OCU/hour", "GPU-accelerated | 16 vCPUs / 64GB RAM | 7 OCUs/hour", agent-task costs like "Add a feature to medium codebase | 8" OCUs) only appears in a separate docs page. Ona's own pricing FAQ additionally admits OCU consumption per task is highly variable ('there is a large variability in the number of OCUs consumed for each task'), ranging from 1 OCU to explain a small codebase up to 8 OCUs to add a feature to a medium codebase. Daytona, by contrast, publishes exact per-resource dollar rates directly on its pricing page ('Compute, vCPU, $0.0504/h, Memory, GiB, $0.0162/h, Storage, GiB, $0.000108/h', billed per second), and Cursor's paid tiers are flat, fixed monthly prices ($20/mo Individual, $40/user/mo Teams) rather than a variable usage credit.

Why it matters: Buyers cannot forecast their real monthly spend from Ona's pricing page alone, and a buyer who cannot predict their bill defaults to the competitor whose pricing math is a one-line multiplication — pushing budget-conscious or procurement-gated evaluators toward Daytona or Cursor before they ever request an Ona demo.

Recommended move

Add a visible OCU-to-dollar conversion rate and a runtime/task cost calculator directly on the pricing page (Daytona-style), and publish 3-5 real customer-anonymized monthly OCU totals by team size next to the existing task-cost examples.

Buildable

Expected
The pricing page states an OCU-to-dollar conversion rate and/or a cost calculator, without requiring navigation to a separate docs page.
Actual
OCU-to-dollar/hour rates (e.g. '1 OCU/hour' standard, '7 OCUs/hour' GPU) appear only at ona.com/docs/ona/billing/usage, and the pricing page FAQ states consumption 'is highly dependent on the workloads you run' with 'large variability... for each task'.

Evidence · 5 verified claims

  • Ona's OCU consumption rates for both environment runtime and agentic tasks are documented only in a separate docs page, not on the pricing page.

    Standard | 4 vCPUs / 16GB RAM | 1 OCU/hour GPU-accelerated | 16 vCPUs / 64GB RAM | 7 OCUs/hour ... Add a feature to medium codebase | 8

    Source: ona.com/docs/ona/billing/usage

  • Daytona publishes itemized dollar-per-resource-hour pricing directly on its pricing page.

    Compute, vCPU, $0.0504/h, Memory, GiB, $0.0162/h, Storage, GiB, $0.000108/h

    Source: www.daytona.io/pricing

  • Ona explicitly states OCU consumption per task is highly variable and unpredictable

    How much usage does each OCU represent? This is highly dependent on the workloads you run. ... Keep in mind that there is a large variability in the number of OCUs consumed for each task.

    Source: www.gitpod.io/pricing

  • Daytona publishes exact per-second unit compute pricing on its public pricing page

    Compute, vCPU, $0.0504/h, Memory, GiB, $0.0162/h, Storage, GiB, $0.000108/h ... All billing is calculated per second.

    Source: www.daytona.io/pricing

  • Cursor's paid individual and team tiers are flat, fixed monthly prices rather than a variable usage credit

    ### Individual $20 / mo. ... ### Teams $40 / user / mo.

    Source: cursor.com/pricing

8

Ona offers no self-serve volume discount on overage usage — Core customers pay a flat $10/40-OCU add-on rate forever, or must jump straight to a sales-negotiated Enterprise contract

ImpactmediumEffortlow

Ona's pricing page states Core add-on OCUs cost a flat "from $10 / 40 OCUs" with no tiered or volume-based pricing shown, and the only alternative unit economics come from Enterprise's "Custom credits," which requires a sales conversation. Daytona explicitly markets scaling discounts within its self-serve, no-sales-call tier: "Pay as you go with usage-based pricing" and "Unlock volume discounts as you scale." A Core customer on Ona who outgrows the $20-$220ish OCU-add-on range has no self-serve path to better pricing — they must go straight to a custom Enterprise quote, even if all they need is more compute at a better rate, not VPC/SSO/audit features.

Why it matters: Growing Core customers who just need cheaper bulk compute — not enterprise governance features — are forced into a full sales cycle for better pricing, adding friction and sales-cycle cost to a segment Ona could otherwise retain and expand with a simple tiered discount.

Recommended move

Publish a self-serve volume-discount schedule for add-on OCUs at defined usage breakpoints (e.g. 500+, 2,000+ OCUs/month) so scaling Core customers get better unit economics without needing to contact sales.

Buildable

Expected
The add-on OCU section shows a tiered price schedule (e.g. lower $/OCU at higher volume breakpoints).
Actual
Add-on OCUs are priced at a flat 'from $10 / 40 OCUs' with no volume tiers shown; the only other rate is Enterprise's unlisted 'Custom credits'.

Evidence · 2 verified claims

  • Ona's Core add-on OCU rate is a flat "from $10 / 40 OCUs" with no published volume discount tier; better rates require moving to Enterprise custom pricing.

    Add-on OCUs from $10 / 40 OCUs [Core] Custom credits [Enterprise]

    Source: www.gitpod.io/pricing

  • Daytona advertises self-serve volume discounts as usage scales, without requiring a move to a sales-negotiated tier.

    Pay as you go with usage-based pricing Unlock volume discounts as you scale

    Source: www.daytona.io/pricing

9

Ona's SOC 2 badge doesn't disclose Type I vs Type II, while Daytona, Coder, and Cursor all state their SOC 2 type explicitly

ImpactmediumEffortlow

Ona's trust center and homepage display a generic 'SOC 2' badge with a document simply labeled 'SOC 2 Report' — no Type I/Type II distinction visible on the page. Daytona's trust center explicitly lists both 'SOC 2 Type 1' and 'SOC 2 Type 2' as separate compliance badges plus HIPAA. Coder's footer displays an explicit 'SOC 2 Type II Certified' badge. Cursor's security page states outright that 'A SOC 2 Type II attestation report is available on request.' For a security-conscious enterprise buyer, Type II (proving controls operated effectively over time) is materially stronger evidence than Type I (a point-in-time design check), and Ona is the only one of the four not stating which it has on the page.

Why it matters: Enterprise security questionnaires and procurement checklists specifically ask for Type II; an ambiguous badge forces extra back-and-forth or reads as weaker than competitors who state it upfront, adding friction at exactly the stage (security review) Ona's own Trust Center is trying to shortcut.

Recommended move

Add explicit 'Type I' or 'Type II' language next to the SOC 2 badge on both ona.com and the SafeBase trust center landing page (not just inside the gated report).

Buildable

Expected
The SOC 2 badge/label states 'Type I' or 'Type II' explicitly, matching the pattern on Daytona, Coder, and Cursor's pages.
Actual
The badge and document are labeled only 'SOC 2' / 'SOC 2 Report' with no Type qualifier anywhere on the page.

Evidence · 4 verified claims

  • Ona's Trust Center and homepage list SOC 2 as a certification but do not state a Type on the page.

    ## Compliance - GDPR - SOC 2 - EU AI Act ... REPORTSSOC 2 Report

    Source: ona.com/security

  • Ona's homepage repeats the same unqualified 'SOC 2' badge.

    ## Enterprise-ready. Compliant, certified, and trusted by Fortune 500 companies. SOC 2 Fortune 500

    Source: ona.com

  • Coder displays an explicit SOC 2 Type II certified badge.

    Badge indicating compliance with a SOC 2 Type 2 security audit based on AICPA's Trust Services Criteria SOC 2 Type II Certified

    Source: coder.com

  • Cursor states explicitly it holds SOC 2 Type II.

    A SOC 2 Type II attestation report is available on request at trust.cursor.com.

    Source: cursor.com/security

10

Ona's own public Trust Center discloses a history of authentication and token-exposure security incidents under the Gitpod name — undermining the 'secured at the kernel' positioning it's now selling

ImpactmediumEffortlow

Ona markets itself as 'Orchestrated, governed, secured at the kernel' with a dedicated 'Veto' kernel-level security product, but its own Trust Center's public 'Security Notifications' log lists multiple past incidents: an OAuth token exposure (Aug 2025), an account-impersonation bug that forced re-authentication of all Gitpod Cloud users, and a CVE-2023-0957 vulnerability that could allow shared-workspace takeover. None of the competitor security pages fetched (Cursor's security page, Daytona's trust center summary) surfaced an equivalent public incident log on the page checked. This is a double-edged asset: transparency is good, but a buyer doing diligence on a company now positioning itself as the security layer for AI agents will find a track record of exactly the class of vulnerability (auth/token handling) that agent governance is supposed to prevent.

Why it matters: Buyers evaluating Ona specifically for its security/governance pitch will read this incident history against the current kernel-security claim, and a competitor sales rep can use it directly in a security-review objection.

Recommended move

Add a short 'what we changed since these incidents' narrative near the notification log connecting past auth/token fixes to the current Veto architecture, turning the disclosure into a credibility asset instead of leaving it as a bare incident list.

Buildable

Expected
Each historical incident entry (OAuth token exposure, impersonation bug, CVE-2023-0957) is followed by a note connecting the fix to the current Veto/kernel-level security architecture.
Actual
Incidents are listed as a bare notification log (dates and descriptions only) with no stated connection to the current security architecture.

Evidence · 4 verified claims

  • Ona's public Trust Center lists a 2025 Bitbucket OAuth token exposure vulnerability under the Gitpod product.

    August 21, 2025 # Security Vulnerability affecting Gitpod Classic As part of our ongoing security reviews, we've resolved a vulnerability in our Bitbucket OAuth token handling that, under specific conditions, could have exposed a user's access token if they clicked a malicious link.

    Source: ona.com/security

  • Ona's Trust Center discloses a prior account-impersonation incident that forced re-authentication of all Gitpod Cloud users.

    Our investigation revealed a technical glitch within Gitpod's authentication logic, resulting in the impersonation of a singular, distinct account. ... Consequently, all Gitpod Cloud users were mandated to re-authenticate.

    Source: ona.com/security

  • Ona's Trust Center discloses a 2023 CVE for shared workspace takeover.

    Vulnerability affecting Gitpod Context: Gitpod been notified of a vulnerability that may lead to a takeover of shared workspaces (CVE-2023-0957)

    Source: ona.com/security

  • Ona positions itself on kernel-level security enforcement as a current core product pillar.

    ### Runtime AI security Runs in your VPC with complete network control. Audit trails, scoped credentials, and kernel-level policy enforcement.

    Source: ona.com

Checkable defects (10)

These findings state a specific expected-vs-actual that someone who never read this audit could go and confirm. The rest are judgement calls — valuable, but not mechanically checkable.

Verification appendix

Every claim above was re-checked by a separate agent that never saw the reasoning which produced it — only the claim and its source URL. Anything it could not confirm was cut from the report. This is that record, including what did not survive.

42

claims checked

40

verified & shipped

2

rejected

Verifier model: claude-sonnet-5

Claims we threw out (2)

These did not survive verification, so they are not part of the findings above. They are listed because a report that cannot tell you what it got wrong gives you no way to judge what it got right.

  • Cursor's G2 profile has more reviews (42) at a comparable/higher rating (4.5/5) for its current AI-agent product.

    Source did not support itCursor's G2 product/seller pages currently show 316 reviews at 4.6/5 (or 314 on the seller page), not 42 reviews at 4.5/5 as claimed; the 42-review figure does not match what is live on G2 today.

    www.g2.com/products/cursor/reviews

  • Daytona explicitly names both SOC 2 Type 1 and Type 2 as separate compliance items.

    Source did not support itDaytona's trust-center announcement page only names 'SOC 2 Type I' and HIPAA, not both SOC 2 Type 1 and Type 2 as distinct items — no mention of Type 2 appears on this page.

    www.daytona.io/dotfiles/trust-center

Things we suspected but did not assert (20)

Noticed during research, not provable from a page we fetched. Deliberately kept out of the findings.

  • Whether Ona's automatic top-up ('When your balance drops below 20 OCUs, Ona charges your default payment method') is disclosed anywhere on the pricing page itself versus only in billing docs — confirmed only in docs, not re-checked against every pricing page variant/locale.
  • Whether Coder's free Community 'Assign long-running tasks to AI coding agents' feature has any usage cap not shown on the pricing page (e.g. rate limits on agent runs) that would narrow the free-vs-paid gap with Ona.
  • Exact effective $/hour cost of an Ona standard environment when paying via Core's base $20 allocation versus add-on OCUs, since the $20 tier's per-OCU cost is not separately broken out from the bundled monthly allocation.
  • Whether Ona/Gitpod has any listing on Google Cloud Marketplace or Azure Marketplace — searches did not surface a live listing page to confirm presence or absence.
  • GitHub Codespaces' own G2 review count and rating as a standalone product entry — G2's Codespaces-specific review page could not be extracted (Codespaces reviews appear folded into GitHub's aggregate 4.7/5, 2,397-review G2 seller page rather than a separate product listing).
  • The exact LinkedIn follower figures are from third-party search-result snippets, not a directly fetched/rendered LinkedIn page (LinkedIn blocked direct extraction), so the 6,250 and 8,912 figures should be treated as approximate and re-checked before citing publicly.
  • Whether the 16 G2 reviews feeding both AWS Marketplace 'Ona Enterprise' listings are literally the same 16 or two overlapping-but-distinct sets — the second listing only showed review title teasers, not full duplicate confirmation.
  • Whether Ona's actual environment cold-start time is faster or slower than Daytona's stated sub-90ms — Ona does not publish a comparable number anywhere fetched.
  • Whether the anonymous 'Top 100 global company' customer quoted on ona.com is a real, verifiable account or a composite/aggregate example.
  • Whether Ona's Enterprise-tier 'Uptime guarantees (SLAs)' bullet corresponds to a specific published SLA percentage — the pricing page lists the feature but states no number.
  • Whether Cursor's 'over half of the Fortune 500' and Ona's 'trusted by Fortune 500 companies' claims are independently substantiated by either company beyond the homepage text itself.
  • Whether Ona holds an ISO 27001 certification (not listed on the Trust Center's visible Compliance section, which showed only GDPR, SOC 2, and EU AI Act; could not access the gated full document list to confirm absence definitively).
  • Total review count or rating for Coder and Daytona on G2 (page fetches failed/timed out for both G2 profiles).
  • Whether the SOC 2 report Ona lists is Type I or Type II — the badge/document title on the public page does not specify, and the underlying report is gated behind an access request.
  • Whether any of Ona's named logos (BNY, GSR, Vanta, Pearson, EquipmentShare, Hargreaves Lansdown) have ever had a specific quantified outcome published anywhere else (e.g. press release, conference talk) — only unnamed 'Global pharma company' and 'Top 100 global company' quotes were found on the pages fetched.
  • Whether Cognition/Devin or GitHub Codespaces publish an equivalent public security-incident disclosure log (not fetched in this lane; out of scope competitors for direct trust-center comparison beyond what was already sourced).
  • Whether Ona's Core signup at https://app.gitpod.io/ requires a credit card before provisioning the first environment — the app subdomain could not be fetched (dynamic app, failed to load) so the actual checkout/signup flow was not directly observed.
  • Whether Ona's 'Request a demo' flow (https://ona.com/contact/demo) promises any response-time SLA — the form fields did not render in the extracted content, likely because the form is loaded client-side; no response-time text was present in what was captured.
  • Devin/Cognition's free tier claim from the prior competitor research could not be independently re-confirmed in this pass — devin.ai/pricing returned no readable content on fetch.
  • Mobile web experience of Ona's pricing/signup pages versus competitors' — not testable with the available text-extraction tooling.

Want this for your market?

Same process, your competitors: research across five independent lanes, every claim re-checked against its source by a separate agent, and an appendix listing everything that did not survive.