7-Day Pass
One payment. Seven days to investigate.
$4.99
One-time payment in USD
- 20 distinct CVEs over 7 days
- 7 days of access · no automatic renewal
- Reopen CVEs in the paid period without extra usage
- 1 seat
- No API access
- No webhooks
Honest pricing. No usage cliff.
The same evidence sources, with access and capacity for each workflow.
Pay once for 7 days, or choose a monthly plan. Prices in USD via Creem (Merchant of Record).
Payments are processed securely by Creem. Purchases are charged in USD and include applicable taxes.
One payment. Seven days to investigate.
$4.99
One-time payment in USD
For focused monthly CVE analysis.
$24.99
Billed monthly in USD
For individual operators.
$99/mo
For security teams.
$499/mo
For MSSPs and large SOCs.
$1,499/mo
Everything that changes by tier — quotas, rate limits, sources, security, and support.
| Feature | 7-Day Pass | Analyst | Pro | Team | Enterprise |
|---|---|---|---|---|---|
| Pricing & access | |||||
| Price and billing | $4.99 once | $24.99 / month | $99 | $499 | $1,499 |
| REST API access | — | — | ✓ | ✓ | ✓ |
| Web console | 20 distinct CVEs / 7-day pass | 150 distinct CVEs / monthly period | Unlimited | Unlimited | Unlimited |
| Verdict history | 7 days of history | 30 days of history | ✓ | ✓ | ✓ |
| Patch priority dashboards and sample files | — | — | ✓ | ✓ | ✓ |
| Patch history with verification evidence | — | — | ✓ | ✓ | ✓ |
| Visual CSV/Excel editor and audited corrections | — | — | ✓ | ✓ | ✓ |
| Executive PDF and editable PowerPoint reports | — | — | ✓ | ✓ | ✓ |
| Quotas & rate limits | |||||
| API daily quota | — | — | 1,000 | 150,000 | 200,000 per seat |
| Quota model | Per user | Per user | Per user | Org-shared | Per seat |
| Rate limit | 60 / min | 60 / min | 1,000 / min | 3,000 / min | 5,000 / min per seat |
| Bulk endpoint (per call) | — | — | — | Up to 500 CVEs | Up to 1,000 CVEs |
| CSV upload (per file) | — | — | 100 (sync) | 10,000 (async) | 100,000 (async) |
| Team features | |||||
| Seats included | 1 | 1 | 1 | 3 | 10 |
| Webhooks | — | — | 3 | Unlimited by plan* | Unlimited by plan* |
| Role-based seats | — | — | — | Owner / member | Owner / member |
| Email invitations | — | — | — | ✓ | ✓ |
| Signal sources | |||||
| CISA KEV | ✓ | ✓ | ✓ | ✓ | ✓ |
| FIRST.org EPSS | ✓ | ✓ | ✓ | ✓ | ✓ |
| Metasploit modules | ✓ | ✓ | ✓ | ✓ | ✓ |
| Nuclei templates | ✓ | ✓ | ✓ | ✓ | ✓ |
| ExploitDB | ✓ | ✓ | ✓ | ✓ | ✓ |
| Curated GitHub PoCs | ✓ | ✓ | ✓ | ✓ | ✓ |
| Security & compliance | |||||
| Single active session | ✓ | ✓ | ✓ | ✓ (per seat) | ✓ (per seat) |
| EU-hosted primary database | ✓ | ✓ | ✓ | ✓ | ✓ |
| Admin audit log | — | — | — | ✓ | ✓ |
| DPA available | — | — | — | On request | ✓ |
| Support | |||||
| Channel | Best-effort | Best-effort | Priority email | Priority email | |
| First-response target | Best effort | Best effort | Within 2 business days | Within 1 business day | Within 4 business hours, business days |
* Team and Enterprise have no lower commercial webhook-count limit. Fair-use security controls allow up to 1,000 active or paused endpoints per owner, three destinations per hostname, 10 create or secret-rotation requests per user per minute, and 100 endpoint-creation attempts per owner per rolling 24 hours. Rejected creation attempts count; secret rotations do not. See the webhook guide.
7-Day Pass and Analyst are web-only and do not include CSV upload. CSV batches are all-or-nothing. Pro returns up to 100 results synchronously; Team and Enterprise process larger files asynchronously, send email and console notifications, and retain private result downloads for 30 days. See the bulk analysis guide.
Need more than 10 seats? Contact sales: support@realexploit.io
Patch inventory is a separate Pro, Team and Enterprise workflow. It accepts asset context and CVE identifiers, records patch evidence and history in the workspace, and shows analysis progress in the console. Analysis is refreshed on import or when you request reanalysis; this workflow does not send completion emails.
ACTIVELY_EXPLOITED, WEAPONIZED,
POC_AVAILABLE, THEORETICAL, or
NOT_APPLICABLE — derived deterministically from
public threat-intel signals (CISA KEV, EPSS, Metasploit,
Nuclei, ExploitDB, GitHub PoCs). Every verdict ships with a
0–100 exploitability score and the list of sources used.
meta.sources field.