Pricing

Simple, transparent pricing

Start free on public repositories. Upgrade when you need the patented cross-service taint engine, private repos, and org-wide analysis.

Free

$0 free forever

Architecture & dependency intelligence for public repos.

  • Public repository scanning
  • Architecture graph & blast radius
  • Heuristic security findings
Most popular

Team

$499 / month

Cross-service taint analysis and private repositories.

  • Everything in Free
  • Private repository scanning
  • Cross-service taint findings (patented engine)
  • SARIF export for GitHub Code Scanning

Enterprise

Custom contact sales

Org-wide cross-repo taint, SSO and compliance.

  • Everything in Team
  • Workspace cross-repo taint analysis
  • HIPAA / PCI / SOC 2 compliance packs
  • SSO & audit log export

Compare plans

CapabilityFreeTeamEnterprise
Public repository scanning
Architecture graph & blast radius
Heuristic security findings
Private repository scanning
Cross-service taint analysis (patented engine)
SARIF export & GitHub Action / CI
Scheduled re-scans & Slack / email alerts
Workspace cross-repo taint analysis
Compliance packs (HIPAA / PCI / SOC 2)
SSO, SCIM & audit log export

Pricing FAQ

Is there really a free plan?

Yes. Free is $0 forever and needs no credit card. It scans public repositories and gives you the architecture graph, blast-radius analysis and heuristic security findings — the wedge that shows you what VulnGraph sees.

What does Team unlock?

Team ($499/month) adds private repository scanning, the patented cross-service taint engine that finds injection and trust-boundary paths spanning your services, and SARIF export so findings flow into GitHub Code Scanning and your CI via the GitHub Action.

What makes Enterprise different?

Enterprise adds workspace-wide cross-repository taint analysis — detecting paths that span multiple repositories, not just multiple services in one — plus HIPAA / PCI / SOC 2 compliance packs, SSO, SCIM provisioning, and audit-log export.

Can I export findings to GitHub Code Scanning?

Yes. Every paid scan exports SARIF 2.1.0, so VulnGraph findings appear in the GitHub Security tab beside your other scanners. The GitHub Action can also fail builds on a severity threshold.

How does billing work?

Paid plans are billed monthly through Stripe and you can cancel anytime. Entitlements are tied to your workspace plan and take effect immediately after checkout.

Start free — no credit card

Questions about Enterprise? Talk to us.