Pricing
Pricing on requestwhile Qubrisk is pre-release
There is no checkout and no published price list yet. The packaging below shows how the product is shaped. Tell us the size of your estate and we will scope it with you.
Developer
For a product-security engineer establishing the first owned inventory.
- Repositories
- 10
- Lines / month
- 1 million
- History
- 30 days
- Collaborators
- Unlimited
- Local CLI and CI
- Source, dependency, config, and TLS discovery
- CycloneDX CBOM and SARIF
- One policy profile
- Migration backlog
Team
Most popularFor a platform team coordinating migration across active services.
- Repositories
- 50
- Lines / month
- 10 million
- History
- 365 days
- Collaborators
- Unlimited
- Everything in Developer
- Ownership inference
- Pull-request CBOM diff
- Exceptions and approvals
- GitHub / GitLab workflow
- Email and webhook alerts
Business
For multiple engineering groups operating one cryptographic program.
- Repositories
- 250
- Lines / month
- 50 million
- History
- 2 years
- Collaborators
- Unlimited
- Everything in Team
- Multiple business units
- Custom policies
- Service catalog import
- Evidence packages
- SSO and API
- Priority support
Enterprise
Scoped with you
Negotiated repositories and scan volume, private data plane, custom retention and region, cloud/KMS/HSM/PKI integrations, SLA, security package, and deployment architecture support.
Discuss architectureEvery plan
The safety boundary is not an add-on.
Core evidence, portability, and deletion controls will never depend on subscription tier.
FAQ
Questions before you get in touch
Is a scan a compliance assessment?
No. Qubrisk records detected assets, evidence, policy matches, and migration decisions. It does not certify FIPS, NIST, CNSA, PCI, or regulatory compliance.
Do you upload source code?
Not by default. The local scanner produces fingerprints, paths, metadata, redacted evidence, dependency identifiers, policy results, CBOM, and SARIF. You choose what metadata is uploaded.
Does Qubrisk replace cryptographic code?
No. Replacement suggestions must be validated against standards, implementation support, consumer compatibility, performance, and rollback requirements.