Pricing

One meter. No surprises.

Pay per enabled scope — a subscription, account, project, or cluster. Dev scopes are half price, your first three free. No per-resource charges, ever.

Starter
$299/mo
  • 5 enabled scopes
  • 5 users
  • All connectors
  • CI/CD policy gates
  • Slack + webhook alerts
Install in 15 minutes
most teams
Team
$799/mo
  • 15 enabled scopes
  • 15 users
  • Everything in Starter
  • Priority support
  • Onboarding help
Install in 15 minutes
Enterprise
from $20K/yr
  • Custom scope count
  • Custom users
  • SLA
  • Procurement + invoicing
  • Security review support
Talk to us

Prices in USD. Self-hosted — you run it in your own cluster.

Questions, answered plainly.

What counts as a “scope”?

A scope is one thing you point Cloudkeel-DD at: an Azure subscription, an AWS account, a GCP project, or a Kubernetes cluster. You pay per enabled scope — not per resource inside it. A subscription with 5 resources and one with 5,000 cost the same.

Is there really no per-resource pricing?

No per-resource charges, ever. Scanning more infrastructure inside a scope never changes your bill. The meter is scopes, full stop.

Does the self-hosted install expire?

It scans for 30 days from the moment you create your first workspace, then stops starting new scans. Nothing is deleted and nothing else changes: your findings, history, connected sources and logins all keep working, and any scan already running finishes. Existing installs are never cut short by an upgrade — the 30 days runs from whichever is later, your first workspace or the first time you run a version that enforces it. Ask us and we extend it.

How do dev scopes work?

Dev scopes are half price, and your first three are free. So a typical team wiring up a couple of non-production environments alongside prod pays only for prod.

Is it really self-hosted?

Yes. Cloudkeel-DD runs entirely inside your own cluster from public images and a public Helm chart. Your cloud credentials stay in your environment and there is no SaaS backend holding your keys — we operate no endpoints, so there is no telemetry, no analytics and no licence server — nothing phones home, and it works air-gapped. There is a pilot timer, but it is a local date comparison inside your own cluster (see “Does the self-hosted install expire?” above). To be precise about findings: they live in your database, and the only paths that carry them outward are ones you configure yourself — a notification webhook, or a GitHub or GitLab remediation pull request.

Do you support SSO / SAML?

On the roadmap, not shipped. Today authentication is email/password with per-tenant role-based access control (owner / admin / viewer). We won’t list SSO as available until it actually is.

Can we try it before committing?

Yes, and you never have to talk to us. The install is public — run a scan against your own infrastructure and see real findings first. If you would rather not do the install and the tuning yourself, the Drift Audit is a separate paid engagement: fixed price, five business days, and you keep the install and a written report at the end.

Install in 15 minutes