Transparent pricing for all your needs
Choose the plan that fits your maturity. All plans include continuous monitoring and EOL and CVE alerts.
Starter
Built for startups and SMBs that want continuous visibility into software risk.
i.e. €2,388 /year
Included
- Projects & components
- 5 projects
- 300 components
- 10 users
- Manual component entry
- Dependency file imports
- Git repository sync (GitHub, GitLab, Bitbucket)
- SBOM file import
- EOL / EOS & CVE
- End-of-support date tracking (open source and proprietary components)
- Daily CVE sync (NVD/NIST) with CVSS and EPSS scores, CISA KEV catalog
- EOL alerts at 12 months, 6 months and 30 days before end of support
- Alerts
- Configurable alert rules per project
- CVE by severity, CISA KEV catalog and EPSS threshold
- Events: CVE, end of life, new patch or new version, unrecognized component
- Channel: email
- Automatic ticket creation
- Frequencies: immediate, daily or weekly
- SBOM
- Unlimited SBOM generation
- SBOM in SPDX or CycloneDX format
- Reporting
- Project report (summary, 12-month trends, PDF export)
- Data
- Detailed information on components and vendors
- Retention: 1 year
- Workflow & Collaboration
- Owner assigned to each project and component
- Ticket assignment and tracking (status, comments)
- Comments on each component change
- Action history per component
- Security
- Data hosted in the European Union
- MFA (TOTP)
- Per-organization isolation
- Project roles (manager, contributor, reader)
- Organization roles (administrator, user, guest)
- Support
- Documentation
- Standard support (48 business hours)
- 30-day free trial (no card, no commitment)
Business
For SMBs and mid-market teams with advanced compliance and security governance needs.
i.e. €5,988 /year
Included
- Projects & components
- 15 projects
- 1,500 components
- 30 users
- Manual component entry
- Dependency file imports
- Git repository sync (GitHub, GitLab, Bitbucket)
- SBOM file import
- EOL / EOS & CVE
- End-of-support date tracking (open source and proprietary components)
- Daily CVE sync (NVD/NIST) with CVSS and EPSS scores, CISA KEV catalog
- EOL alerts at 12 months, 6 months and 30 days before end of support
- Alerts
- Configurable alert rules per project
- CVE by severity, CISA KEV catalog and EPSS threshold
- Events: CVE, end of life, new patch or new version, license change, unrecognized component
- Channel: email
- Automatic ticket creation
- Frequencies: immediate, daily or weekly
- SBOM
- Unlimited SBOM generation
- SBOM in SPDX or CycloneDX format
- Public secure SBOM sharing link
- Reporting
- Project report (summary, 12-month trends, PDF export)
- Global report (consolidated multi-project view)
- PDF, CSV and JSON exports
- Full audit trail
- Compliance & evidence
- NIS 2 evidence (Article 21)
- ISO 27001 evidence (controls A.5.9 and A.8.8)
- DORA evidence (Article 8)
- Data
- Detailed information on components and vendors
- Retention: 2 years
- Workflow & Collaboration
- Owner assigned to each project and component
- Ticket assignment and tracking (status, comments)
- Comments on each component change
- Action history per component
- Security
- Data hosted in the European Union
- MFA (TOTP)
- Per-organization isolation
- Project roles (manager, contributor, reader)
- Organization roles (administrator, user, guest)
- Support
- Documentation
- Priority support (24 business hours)
- 30-day free trial (no card, no commitment)
Enterprise
For mid-market and large enterprises with advanced governance requirements.
i.e. €11,988 /year
Included
- Projects & components
- 50 projects
- 10,000 components
- 100 users
- Manual component entry
- Dependency file imports
- Git repository sync (GitHub, GitLab, Bitbucket)
- SBOM file import
- EOL / EOS & CVE
- End-of-support date tracking (open source and proprietary components)
- Daily CVE sync (NVD/NIST) with CVSS and EPSS scores, CISA KEV catalog
- EOL alerts at 12 months, 6 months and 30 days before end of support
- Alerts
- Configurable alert rules per project
- CVE by severity, CISA KEV catalog and EPSS threshold
- Events: CVE, end of life, new patch or new version, license change, unrecognized component
- Channel: email
- Automatic ticket creation
- Frequencies: immediate, daily or weekly
- SBOM
- Unlimited SBOM generation
- SBOM in SPDX or CycloneDX format
- Public secure SBOM sharing link
- Reporting
- Project report (summary, 12-month trends, PDF export)
- Global report (consolidated multi-project view)
- PDF, CSV and JSON exports
- Full audit trail
- Compliance & evidence
- NIS 2 evidence (Article 21)
- ISO 27001 evidence (controls A.5.9 and A.8.8)
- DORA evidence (Article 8)
- Data
- Detailed information on components and vendors
- Retention: 3 years
- Workflow & Collaboration
- Owner assigned to each project and component
- Ticket assignment and tracking (status, comments)
- Comments on each component change
- Action history per component
- Security
- Data hosted in the European Union
- MFA (TOTP)
- SSO (SAML, OAuth)
- Per-organization isolation
- Project roles (manager, contributor, reader)
- Organization roles (administrator, user, guest)
- Support
- Documentation
- Dedicated support (4 business hours)
All prices exclude VAT. Monthly or annual billing available. Annual billing commits for one year; monthly billing commits for 30 days. Cancellations take effect at the end of the commitment period. You can upgrade at any time. Limit extensions are available for an additional fee.
Your first scan in 15 minutes
Your components, their CVEs, and their end-of-support dates-visible at a glance.
30 days freeNo credit cardNo commitment