Honest pricing. No usage cliff.

Pricing

The same evidence sources, with access and capacity for each workflow.

Pay once for 7 days, or choose a monthly plan. Prices in USD via Creem (Merchant of Record).

Payments are processed securely by Creem. Purchases are charged in USD and include applicable taxes.

7-Day Pass

One payment. Seven days to investigate.

$4.99

One-time payment in USD

  • 20 distinct CVEs over 7 days
  • 7 days of access · no automatic renewal
  • Reopen CVEs in the paid period without extra usage
  • 1 seat
  • No API access
  • No webhooks
Choose 7-Day Pass
Most popular

Analyst

For focused monthly CVE analysis.

$24.99

Billed monthly in USD

  • 150 distinct CVEs / billing month
  • 30 days of history
  • Reopen CVEs in the paid period without extra usage
  • 1 seat
  • No API access
  • No webhooks
Choose Analyst

Pro

For individual operators.

$99/mo

  • API access
  • 1,000 calls / day
  • 3 webhooks
  • 100-CVE bulk CSV (sync)
  • Patch dashboards and history
  • Executive PDF and editable PowerPoint reports
  • Full history
  • 1 seat
  • Email support
Start Pro

Team

For security teams.

$499/mo

  • 3 seats, org-shared quota
  • 150,000 calls / day (shared)
  • Patch dashboards and shared tracking
  • Executive PDF and editable PowerPoint reports
  • Unlimited-by-plan webhooks*
  • 10,000-CVE bulk CSV (async)
  • API bulk endpoint up to 500 CVEs/call
  • Priority email support
Start Team

Enterprise

For MSSPs and large SOCs.

$1,499/mo

  • 10 seats, per-seat quota
  • 200,000 calls / day per seat
  • Patch dashboards and shared tracking
  • Executive PDF and editable PowerPoint reports
  • Unlimited-by-plan webhooks*
  • 100,000-CVE bulk CSV (async)
  • API bulk endpoint up to 1,000 CVEs/call
  • SLA available on request
Contact sales

Compare every feature

Everything that changes by tier — quotas, rate limits, sources, security, and support.

Feature 7-Day PassAnalyst Pro Team Enterprise
Pricing & access
Price and billing $4.99 once$24.99 / month $99 $499 $1,499
REST API access —— ✓ ✓ ✓
Web console 20 distinct CVEs / 7-day pass150 distinct CVEs / monthly period Unlimited Unlimited Unlimited
Verdict history 7 days of history30 days of history ✓ ✓ ✓
Patch priority dashboards and sample files ——✓ ✓✓
Patch history with verification evidence ——✓ ✓✓
Visual CSV/Excel editor and audited corrections——✓✓✓
Executive PDF and editable PowerPoint reports——✓✓✓
Quotas & rate limits
API daily quota —— 1,000 150,000 200,000 per seat
Quota model Per userPer user Per user Org-shared Per seat
Rate limit 60 / min60 / min 1,000 / min 3,000 / min 5,000 / min per seat
Bulk endpoint (per call) —— — Up to 500 CVEs Up to 1,000 CVEs
CSV upload (per file) —— 100 (sync) 10,000 (async) 100,000 (async)
Team features
Seats included 11 1 3 10
Webhooks —— 3 Unlimited by plan* Unlimited by plan*
Role-based seats —— — Owner / member Owner / member
Email invitations —— — ✓ ✓
Signal sources
CISA KEV ✓✓ ✓ ✓ ✓
FIRST.org EPSS ✓✓ ✓ ✓ ✓
Metasploit modules ✓✓ ✓ ✓ ✓
Nuclei templates ✓✓ ✓ ✓ ✓
ExploitDB ✓✓ ✓ ✓ ✓
Curated GitHub PoCs ✓✓ ✓ ✓ ✓
Security & compliance
Single active session ✓✓ ✓ ✓ (per seat) ✓ (per seat)
EU-hosted primary database ✓✓ ✓ ✓ ✓
Admin audit log —— — ✓ ✓
DPA available —— — On request ✓
Support
Channel Best-effortBest-effort Email Priority email Priority email
First-response target Best effortBest effort Within 2 business days Within 1 business day Within 4 business hours, business days

* Team and Enterprise have no lower commercial webhook-count limit. Fair-use security controls allow up to 1,000 active or paused endpoints per owner, three destinations per hostname, 10 create or secret-rotation requests per user per minute, and 100 endpoint-creation attempts per owner per rolling 24 hours. Rejected creation attempts count; secret rotations do not. See the webhook guide.

7-Day Pass and Analyst are web-only and do not include CSV upload. CSV batches are all-or-nothing. Pro returns up to 100 results synchronously; Team and Enterprise process larger files asynchronously, send email and console notifications, and retain private result downloads for 30 days. See the bulk analysis guide.

Need more than 10 seats? Contact sales: support@realexploit.io

Patch inventory is a separate Pro, Team and Enterprise workflow. It accepts asset context and CVE identifiers, records patch evidence and history in the workspace, and shows analysis progress in the console. Analysis is refreshed on import or when you request reanalysis; this workflow does not send completion emails.

FAQ

What is a "verdict"?
A single, actionable label per CVE — one of ACTIVELY_EXPLOITED, WEAPONIZED, POC_AVAILABLE, THEORETICAL, or NOT_APPLICABLE — derived deterministically from public threat-intel signals (CISA KEV, EPSS, Metasploit, Nuclei, ExploitDB, GitHub PoCs). Every verdict ships with a 0–100 exploitability score and the list of sources used.
Is there a free tier?
No. 7-Day Pass costs USD 4.99 once for 7 days and 20 distinct CVEs. Analyst costs USD 24.99 per month for 150 distinct CVEs and 30 days of history. Reopening a CVE within the same paid period does not consume another slot. Invalid identifiers, missing CVEs, and pending analyses do not consume the allowance. Both plans are web only, with no API, webhooks or CSV uploads. No Telegram account is required.
How does shared quota work on the Team plan?
All API calls from any of the 3 seats count against one org-wide pool of 150,000 / day. The counter resets at UTC midnight. Enterprise is different — each seat has its own 200,000 / day pool, so a 10-seat Enterprise org has 2,000,000 / day in aggregate without any one seat being able to starve another.
Can I change my plan anytime?
Contact support@realexploit.io to change an existing plan. We confirm the effective date and any charge or credit before applying it. You can cancel renewal from Billing and keep the period already paid.
Do unused requests roll over to next month?
No. Pass includes 20 distinct CVEs for its 7-day period. Analyst includes 150 distinct CVEs for each paid monthly period. Unused allowance does not carry over. Pro, Team and Enterprise API quotas reset daily at UTC midnight.
What happens when I hit my quota?
There are no overage charges or automatic upgrades. Pass and Analyst can reopen CVEs already counted in the current paid period; new CVEs require a new paid period or a plan change. API quota errors return HTTP 429 with rate-limit headers; daily API quotas reset at UTC midnight.
How do bulk CSV limits and quota interact?
The file limit is the largest batch shape accepted by your plan; quota is the number of lookups you still have available. A batch must fit both. We reject the complete request before processing if it exceeds either limit, so there is no ambiguous partial result or automatic overage charge. To protect shared capacity, CSV creation across sync and async modes is also limited to 100 persisted upload attempts per rolling 24 hours: per user on Pro and Enterprise, and shared by a Team organization. Idempotent retries do not consume another slot; completed, cancelled, failed, and quota-rejected attempts remain in the window. A separate, non-refundable creation budget counts unique CVEs submitted to asynchronous jobs in the same rolling window: 150,000 per Team organization and 200,000 per Enterprise seat. Quota-rejected, cancelled, and failed attempts remain in this abuse-control budget, although normal lookup-quota refunds still apply. Exact idempotent retries do not consume this creation budget.
Are there setup fees?
None. The price you see is the only price — Creem handles global tax and VAT inclusive of the listed amount.
Do you offer educational or non-profit discounts?
Contact us for educational and non-profit pricing — case-by-case basis. Email support@realexploit.io with proof of affiliation.
How is CVE data sourced and licensed?
All signals come from public, commercially-usable feeds: CISA KEV (public domain), NVD (US government work), FIRST.org EPSS (CC BY 4.0), ExploitDB, Rapid7's Metasploit Framework (BSD-3), ProjectDiscovery's Nuclei templates (MIT), and curated GitHub PoC indexes (we link out, never redistribute exploit code). Attribution and license details ship in every response's meta.sources field.
Do paid tiers auto-renew?
7-Day Pass is a one-time purchase and never auto-renews. Analyst, Pro, Team and Enterprise renew monthly until canceled. Cancel renewal from Billing; access remains available through the period already paid.
How is my data protected?
Account and job data are protected by encrypted HTTPS connections with TLS 1.3 support, access controls, and private storage for temporary exports. See the Privacy Policy for hosting regions, international transfers, and retention.
Who handles billing and tax?
Creem (Armitage Labs OÜ) acts as Merchant of Record. They handle global tax collection (VAT, GST, sales tax), receipts, dunning, and chargebacks. We never see your card number.
Can I share my Pro plan with my team?
No. Pro is single-seat by design and the web console enforces single active session per user — a new login revokes the prior session. For multi-person use, choose Team (3 seats) or Enterprise (10 seats).
Do you offer refunds?
Yes — 14-day money-back guarantee for first-time customers. Full details on the Refund Policy.