Pricing

Pricing on requestwhile Qubrisk is pre-release

There is no checkout and no published price list yet. The packaging below shows how the product is shaped. Tell us the size of your estate and we will scope it with you.

Developer

Contact usfor pricing

For a product-security engineer establishing the first owned inventory.

Repositories
10
Lines / month
1 million
History
30 days
Collaborators
Unlimited
  • Local CLI and CI
  • Source, dependency, config, and TLS discovery
  • CycloneDX CBOM and SARIF
  • One policy profile
  • Migration backlog
Ask about Developer

Team

Most popular
Contact usfor pricing

For a platform team coordinating migration across active services.

Repositories
50
Lines / month
10 million
History
365 days
Collaborators
Unlimited
  • Everything in Developer
  • Ownership inference
  • Pull-request CBOM diff
  • Exceptions and approvals
  • GitHub / GitLab workflow
  • Email and webhook alerts
Ask about Team

Business

Contact usfor pricing

For multiple engineering groups operating one cryptographic program.

Repositories
250
Lines / month
50 million
History
2 years
Collaborators
Unlimited
  • Everything in Team
  • Multiple business units
  • Custom policies
  • Service catalog import
  • Evidence packages
  • SSO and API
  • Priority support
Ask about Business

Enterprise

Scoped with you

Negotiated repositories and scan volume, private data plane, custom retention and region, cloud/KMS/HSM/PKI integrations, SLA, security package, and deployment architecture support.

Discuss architecture

Every plan

The safety boundary is not an add-on.

Core evidence, portability, and deletion controls will never depend on subscription tier.

Source stays local by default
Private keys are never collected
Evidence carries confidence
Unknown remains unknown
Open CBOM and SARIF exports
No autonomous crypto rewrite
Suppression requires expiry
Workspace deletion is self-serve

FAQ

Questions before you get in touch

Is a scan a compliance assessment?

No. Qubrisk records detected assets, evidence, policy matches, and migration decisions. It does not certify FIPS, NIST, CNSA, PCI, or regulatory compliance.

Do you upload source code?

Not by default. The local scanner produces fingerprints, paths, metadata, redacted evidence, dependency identifiers, policy results, CBOM, and SARIF. You choose what metadata is uploaded.

Does Qubrisk replace cryptographic code?

No. Replacement suggestions must be validated against standards, implementation support, consumer compatibility, performance, and rollback requirements.