Pricing

Predictable pricing,built for continuous control

Unlimited collaborators on every paid plan. No consulting, migration, or assessment fees.

Developer

$99/ month

For a product-security engineer establishing the first owned inventory.

Repositories
10
Lines / month
1 million
History
30 days
Collaborators
Unlimited
  • Local CLI and CI
  • Source, dependency, config, and TLS discovery
  • CycloneDX CBOM and SARIF
  • One policy profile
  • Migration backlog
Start with Developer

Team

Most popular
$499/ month

For a platform team coordinating migration across active services.

Repositories
50
Lines / month
10 million
History
365 days
Collaborators
Unlimited
  • Everything in Developer
  • Ownership inference
  • Pull-request CBOM diff
  • Exceptions and approvals
  • GitHub / GitLab workflow
  • Email and webhook alerts
Start with Team

Business

$1,999/ month

For multiple engineering groups operating one cryptographic program.

Repositories
250
Lines / month
50 million
History
2 years
Collaborators
Unlimited
  • Everything in Team
  • Multiple business units
  • Custom policies
  • Service catalog import
  • Evidence packages
  • SSO and API
  • Priority support
Start with Business

Enterprise

From $50,000 / year

Negotiated repositories and scan volume, private data plane, custom retention and region, cloud/KMS/HSM/PKI integrations, SLA, security package, and deployment architecture support.

Discuss architecture

Every plan

The safety boundary is not an add-on.

Core evidence, portability, and deletion controls never depend on subscription tier.

Source stays local by default
Private keys are never collected
Evidence carries confidence
Unknown remains unknown
Open CBOM and SARIF exports
No autonomous crypto rewrite
Suppression requires expiry
Workspace deletion is self-serve

FAQ

Questions before a scan

Is a scan a compliance assessment?

No. Qubrisk records detected assets, evidence, policy matches, and migration decisions. It does not certify FIPS, NIST, CNSA, PCI, or regulatory compliance.

Do you upload source code?

Not by default. The local scanner produces fingerprints, paths, metadata, redacted evidence, dependency identifiers, policy results, CBOM, and SARIF. You choose what metadata is uploaded.

Does Qubrisk replace cryptographic code?

No. Replacement suggestions must be validated against standards, implementation support, consumer compatibility, performance, and rollback requirements.