Pricing
Simple, transparent pricing
Start free on public repositories. Upgrade when you need the patented cross-service taint engine, private repos, and org-wide analysis.
Free
$0 free forever
Architecture & dependency intelligence for public repos.
- ✓Public repository scanning
- ✓Architecture graph & blast radius
- ✓Heuristic security findings
Team
$499 / month
Cross-service taint analysis and private repositories.
- ✓Everything in Free
- ✓Private repository scanning
- ✓Cross-service taint findings (patented engine)
- ✓SARIF export for GitHub Code Scanning
Enterprise
Custom contact sales
Org-wide cross-repo taint, SSO and compliance.
- ✓Everything in Team
- ✓Workspace cross-repo taint analysis
- ✓HIPAA / PCI / SOC 2 compliance packs
- ✓SSO & audit log export
Compare plans
| Capability | Free | Team | Enterprise |
|---|---|---|---|
| Public repository scanning | ✓ | ✓ | ✓ |
| Architecture graph & blast radius | ✓ | ✓ | ✓ |
| Heuristic security findings | ✓ | ✓ | ✓ |
| Private repository scanning | — | ✓ | ✓ |
| Cross-service taint analysis (patented engine) | — | ✓ | ✓ |
| SARIF export & GitHub Action / CI | — | ✓ | ✓ |
| Scheduled re-scans & Slack / email alerts | — | ✓ | ✓ |
| Workspace cross-repo taint analysis | — | — | ✓ |
| Compliance packs (HIPAA / PCI / SOC 2) | — | — | ✓ |
| SSO, SCIM & audit log export | — | — | ✓ |
Pricing FAQ
Is there really a free plan?
Yes. Free is $0 forever and needs no credit card. It scans public repositories and gives you the architecture graph, blast-radius analysis and heuristic security findings — the wedge that shows you what VulnGraph sees.
What does Team unlock?
Team ($499/month) adds private repository scanning, the patented cross-service taint engine that finds injection and trust-boundary paths spanning your services, and SARIF export so findings flow into GitHub Code Scanning and your CI via the GitHub Action.
What makes Enterprise different?
Enterprise adds workspace-wide cross-repository taint analysis — detecting paths that span multiple repositories, not just multiple services in one — plus HIPAA / PCI / SOC 2 compliance packs, SSO, SCIM provisioning, and audit-log export.
Can I export findings to GitHub Code Scanning?
Yes. Every paid scan exports SARIF 2.1.0, so VulnGraph findings appear in the GitHub Security tab beside your other scanners. The GitHub Action can also fail builds on a severity threshold.
How does billing work?
Paid plans are billed monthly through Stripe and you can cancel anytime. Entitlements are tied to your workspace plan and take effect immediately after checkout.
Questions about Enterprise? Talk to us.