Free
For solo learners.
$0
Free forever
- 5 CVE / week (web console only)
- 10-CVE bulk CSV cap (sync; subject to 5/week allowance)
- Telegram channel gate required
- 1 seat
- No API access
- No webhooks
Honest pricing. No usage cliff.
Same data on every tier. The only thing that scales is throughput.
Billed monthly in USD via Paddle (Merchant of Record). Cancel anytime.
For solo learners.
$0
Free forever
For individual operators.
$99/mo
Approx. ~17 calls/min sustained
For security teams.
$499/mo
For MSSPs and large SOCs.
$1,499/mo
Everything that changes by tier — quotas, rate limits, sources, security, and support.
| Feature | Free | Pro | Team | Enterprise |
|---|---|---|---|---|
| Pricing & access | ||||
| Monthly price | $0 | $99 | $499 | $1,499 |
| REST API access | — | ✓ | ✓ | ✓ |
| Web console | 5 CVE / week | Unlimited | Unlimited | Unlimited |
| Verdict history | — | ✓ | ✓ | ✓ |
| Quotas & rate limits | ||||
| Daily quota | 20 | 1,000 | 150,000 | 200,000 per seat |
| Quota model | Per user | Per user | Org-shared | Per seat |
| Rate limit | 60 / min | 1,000 / min | 3,000 / min | 5,000 / min per seat |
| Bulk endpoint (per call) | — | — | Up to 500 CVEs | Up to 1,000 CVEs |
| CSV upload (per file) | 10 (sync) | 100 (sync) | 10,000 (async) | 100,000 (async) |
| Team features | ||||
| Seats included | 1 | 1 | 3 | 10 |
| Webhooks | — | 3 | Unlimited by plan* | Unlimited by plan* |
| Role-based seats | — | — | Owner / member | Owner / member |
| Email invitations | — | — | ✓ | ✓ |
| Signal sources | ||||
| CISA KEV | ✓ | ✓ | ✓ | ✓ |
| FIRST.org EPSS | ✓ | ✓ | ✓ | ✓ |
| Metasploit modules | ✓ | ✓ | ✓ | ✓ |
| Nuclei templates | ✓ | ✓ | ✓ | ✓ |
| ExploitDB | ✓ | ✓ | ✓ | ✓ |
| Curated GitHub PoCs | ✓ | ✓ | ✓ | ✓ |
| Security & compliance | ||||
| Single active session | ✓ | ✓ | ✓ (per seat) | ✓ (per seat) |
| EU-hosted primary database | ✓ | ✓ | ✓ | ✓ |
| Admin audit log | — | — | ✓ | ✓ |
| DPA available | — | — | On request | ✓ |
| Support | ||||
| Channel | Best-effort | Priority email | Priority email | |
| First-response target | Best effort | Within 2 business days | Within 1 business day | Within 4 business hours, business days |
* Team and Enterprise have no lower commercial webhook-count limit. Fair-use security controls allow up to 1,000 active or paused endpoints per owner, three destinations per hostname, 10 create or secret-rotation requests per user per minute, and 100 endpoint-creation attempts per owner per rolling 24 hours. Rejected creation attempts count; secret rotations do not. See the webhook guide.
CSV batches are all-or-nothing. Free files may contain up to 10 data rows, but the unique valid CVEs must fit the user's remaining five-per-week web allowance. Pro returns up to 100 results synchronously; Team and Enterprise process larger files asynchronously, send email and console notifications, and retain private result downloads for 30 days. See the bulk analysis guide.
Need more than 10 seats? Contact sales: [email protected]
ACTIVELY_EXPLOITED, WEAPONIZED,
POC_AVAILABLE, THEORETICAL, or
NOT_APPLICABLE — derived deterministically from
public threat-intel signals (CISA KEV, EPSS, Metasploit,
Nuclei, ExploitDB, GitHub PoCs). Every verdict ships with a
0–100 confidence score and the list of sources used.
429 Too Many Requests with rate-limit headers
(X-RateLimit-Limit,
X-RateLimit-Remaining,
X-RateLimit-Reset). No surprise overage fees, no
auto-upgrade. Quota resumes at UTC midnight; if you need more
capacity, upgrade from the dashboard.
meta.sources field.