Pricing
Pricing that scales with your attack surface
Three tiers. No scan-count limits. No per-finding fees. Priced by repositories and cloud accounts, not by how many vulnerabilities we find.
Pricing tiers
Operator
$1,200/mo
For security-conscious startups and scale-ups with one to three engineering teams.
- Up to 5 repositories
- 1 cloud account (AWS, GCP, or Azure)
- API security testing (up to 3 APIs)
- Exploit chain tracing
- GitHub / GitLab PR integration
- PDF and JSON report export
- Email support (48h SLA)
Most Popular
Sentinel
$3,800/mo
For growth-stage companies with multiple product teams and a dedicated security function.
- Up to 25 repositories
- Up to 5 cloud accounts
- Unlimited API security testing
- Exploit chain tracing with full graph
- CI/CD pipeline merge blocking
- Compliance report templates (SOC 2, PCI, ISO)
- JIRA / Linear ticket integration
- Slack alerting for critical findings
- Priority support (12h SLA)
- Quarterly review call with security engineering
Command
Custom
For enterprises and regulated industries with complex multi-account, multi-region environments.
- Unlimited repositories
- Unlimited cloud accounts and regions
- Private deployment option (your VPC)
- Custom scan policies and exclusion rules
- SSO / SAML integration
- Custom compliance report frameworks
- Dedicated security engineering support
- SLA guarantees and DPA/NDA available
- Custom contract terms
Common Questions
Pricing FAQs
No. All tiers include unlimited scans and unlimited findings. Pricing is based on the number of repositories and cloud accounts connected, not on how many vulnerabilities Strix finds. We designed it this way deliberately: a per-finding model creates incentives to suppress findings.
Any VCS repository (GitHub, GitLab, Bitbucket) that Strix is authorized to scan. Forks, archived repositories, and repositories with no commits in the last 90 days do not count toward your limit.
Yes. You can upgrade at any time. The upgrade is prorated to your billing cycle. Your existing scan history, findings data, and integrations carry over without any migration step.
Yes. Annual contracts are available for all tiers. Contact us for annual pricing details. Command tier customers almost always use annual contracts.
Yes. Strix is built for environments with compliance requirements. Sentinel includes SOC 2, PCI DSS, and ISO 27001 report templates. Command tier includes DPA availability and private deployment for environments that cannot send code to a third-party SaaS. Contact us to discuss your specific regulatory context.
We offer a guided proof-of-concept engagement for qualified teams. We will run a scan against a staging environment or a subset of repositories, walk you through the findings, and give you a complete report before you commit to a subscription. Contact us to schedule one.
Get Started
Not Sure Which Tier Fits Your Environment?
We will help you scope it. Tell us how many repos and cloud accounts you have and we will recommend the right tier.
Talk to Us