Pricing
Predictable pricing,built for continuous control
Unlimited collaborators on every paid plan. No consulting, migration, or assessment fees.
Developer
For a product-security engineer establishing the first owned inventory.
- Repositories
- 10
- Lines / month
- 1 million
- History
- 30 days
- Collaborators
- Unlimited
- Local CLI and CI
- Source, dependency, config, and TLS discovery
- CycloneDX CBOM and SARIF
- One policy profile
- Migration backlog
Team
Most popularFor a platform team coordinating migration across active services.
- Repositories
- 50
- Lines / month
- 10 million
- History
- 365 days
- Collaborators
- Unlimited
- Everything in Developer
- Ownership inference
- Pull-request CBOM diff
- Exceptions and approvals
- GitHub / GitLab workflow
- Email and webhook alerts
Business
For multiple engineering groups operating one cryptographic program.
- Repositories
- 250
- Lines / month
- 50 million
- History
- 2 years
- Collaborators
- Unlimited
- Everything in Team
- Multiple business units
- Custom policies
- Service catalog import
- Evidence packages
- SSO and API
- Priority support
Enterprise
From $50,000 / year
Negotiated repositories and scan volume, private data plane, custom retention and region, cloud/KMS/HSM/PKI integrations, SLA, security package, and deployment architecture support.
Discuss architectureEvery plan
The safety boundary is not an add-on.
Core evidence, portability, and deletion controls never depend on subscription tier.
FAQ
Questions before a scan
Is a scan a compliance assessment?
No. Qubrisk records detected assets, evidence, policy matches, and migration decisions. It does not certify FIPS, NIST, CNSA, PCI, or regulatory compliance.
Do you upload source code?
Not by default. The local scanner produces fingerprints, paths, metadata, redacted evidence, dependency identifiers, policy results, CBOM, and SARIF. You choose what metadata is uploaded.
Does Qubrisk replace cryptographic code?
No. Replacement suggestions must be validated against standards, implementation support, consumer compatibility, performance, and rollback requirements.