Unlimited scans on every plan. No per-scan fees. 20–30% more cost-effective than legacy AppSec tools.
Price shown is per developer license — billed as a single invoice to your organization.
Unlimited scans on every plan. No per-scan fees. 20–30% more cost-effective than legacy AppSec tools.
Price is per developer license, billed as a single invoice to your organization.
Enterprise & Custom Deployments
Pricing may vary for on-premises installation, single-tenant, or managed service deployments. Contact our team for further details. High-volume licenses are eligible for discounts.
| Feature | Free | Premium$19/dev/mo | Ultimate$99/dev/mo |
|---|---|---|---|
| Core Platform | |||
| Unlimited scans | ✓ | ✓ | ✓ |
| REST API access | ✓ | ✓ | ✓ |
| CI/CD integration (GitHub Actions, GitLab CI, etc.) | ✓ | ✓ | ✓ |
| VS Code & JetBrains IDE plugins | ✓ | ✓ | ✓ |
| SARIF 2.1.0 export | ✓ | ✓ | ✓ |
| GitHub / GitLab / Bitbucket / Azure DevOps | ✓ | ✓ | ✓ |
| Free Scanners | |||
| Secrets scanner (git history, configs, env files) | ✓ | ✓ | ✓ |
| PII detection (emails, phone, national IDs, PAN) | ✓ | ✓ | ✓ |
| Compliance reports (OWASP, PCI DSS, ISO 27001, NIST, DORA, NIS2) | ✓ | ✓ | ✓ |
| Premium Scanners | |||
| SAST — Static Analysis (17+ languages, taint analysis) | — | ✓ | ✓ |
| SCA — Dependency CVE & licence risk | — | ✓ | ✓ |
| DAST — Dynamic Application Security Testing | — | ✓ | ✓ |
| Container Security (Docker image CVE scanning) | — | ✓ | ✓ |
| IaC Scanner (Terraform, K8s, Dockerfile, Ansible) | — | ✓ | ✓ |
| API Security (OpenAPI / GraphQL spec analysis) | — | ✓ | ✓ |
| Ultimate — AI & Advanced | |||
| Malware & supply-chain backdoor detection | — | — | ✓ |
| Vibe Code — AI-generated code security scanner | — | — | ✓ |
| Securitron AI — per-customer model, 93.54% FP elimination | — | — | ✓ |
| AI-powered auto-remediation (patch generation + auto PRs) | — | — | ✓ |
| Securitron Chat & Security Assistant API | — | — | ✓ |
| On-premises deployment (Docker / Kubernetes Helm) | — | — | ✓ |
| Priority support | — | — | ✓ |
| 14-day free trial | — | — | ✓ |
| CSPM — Cloud Security Posture Management Add-on · Separate License | |||
| AWS, Azure, GCP & Kubernetes posture scanning | — | — | Add-on |
| 9+ compliance frameworks (CIS, NIST, PCI DSS, ISO 27001, SOC 2…) | — | — | Add-on |
| Configuration drift detection & IaC lineage tracing | — | — | Add-on |
| IAM privilege escalation path analysis & attack paths | — | — | Add-on |
| eBPF runtime threat detection (real-time, per cluster) | — | — | Add-on |
| Policy-driven auto-remediation across cloud providers | — | — | Add-on |
Enterprise & Custom Deployments
Custom seat counts, SSO/SAML, dedicated Securitron AI model, on-premises single-tenant, enterprise SLA, and volume discounts. Contact our team for a tailored quote.
Extends your AquilaX Ultimate subscription into live cloud environments. CSPM is separately licensed per connected cloud account or Kubernetes cluster and billed independently from your AppSec plan.
Yes. The Free plan is permanent, with no credit card required and no trial expiry. You get unlimited Secrets scanning, PII detection, Compliance reports, CI/CD integration, IDE plugins, and full REST API access — for free, indefinitely. There are no hidden usage caps or scan quotas on any plan.
Premium unlocks 4 additional scanner engines on top of Free: SAST (17+ languages), SCA (dependency CVE + licence risk), DAST (dynamic testing), Container Security, IaC Scanner, and API Security — 7 total scan engines. Still no per-scan fees, still unlimited scans. Priced at $19 per developer license per month, billed as a single invoice to your organisation.
Ultimate unlocks the full AI layer of AquilaX: Securitron AI (93.54% false-positive elimination), Malware & supply-chain backdoor detection, the Vibe Code scanner for AI-generated code, AI-powered auto-remediation with automated pull requests, Securitron Chat and Security Assistant API access, on-premises deployment (Docker / Kubernetes Helm), and priority support. A 14-day free trial is included — no credit card required.
No. AquilaX never charges per scan. All plans — including Free — include unlimited scans. There are no scan quotas or repository limits — the price is per developer license per month, regardless of how many scans you run or repositories you connect.
Yes. Monthly subscriptions can be cancelled at any time from your billing settings. Your plan remains active until the end of the current billing period and then reverts to the Free tier. There are no cancellation fees or minimum contract terms on monthly billing.
Annual billing with a 20% discount is coming soon. Currently all paid plans are billed monthly. Sign up to the release changelog to be notified when annual billing goes live.
Enterprise is a custom tier for organisations that need custom seat counts, SSO/SAML identity integration, a dedicated Securitron AI model with custom training data, single-tenant on-premises deployments, custom compliance framework mapping, enterprise SLA guarantees, dedicated customer success, and volume discounts. Contact us for a quote.
When you start the Ultimate trial, you get full access to every feature in the plan — including Securitron AI, Malware scanning, Vibe Code, auto-remediation, and on-premises deployment — for 14 days. No credit card is required to start the trial. At the end of the trial you can subscribe to continue at $99 per developer license per month, billed to your organisation, or your account will revert to the Free tier.
CSPM is an add-on license available exclusively to Ultimate plan subscribers. It is priced per connected cloud account or Kubernetes cluster and billed independently from your AppSec subscription. Volume discounts apply at 5, 25, and 100+ accounts/clusters, with blended rates for multi-cloud environments. CSPM requires an annual commitment; billing is available monthly or quarterly. Contact us for a quote based on your cloud footprint.
The 14-day Ultimate trial covers all AppSec features in the plan. CSPM is a separately licensed add-on and is not automatically included in the trial — however you can request a CSPM proof-of-concept alongside your trial by contacting our team. We'll connect your first cloud account and walk through initial findings together.
AquilaX charges per developer license, not a flat fee per organisation. A license is counted as every active committer in the past 30 days, plus every user with platform access (e.g. a security engineer who doesn't commit code but reviews findings). Your organisation receives a single invoice covering all licenses used that month — there's no per-seat setup or separate billing per person.
A license is counted as every active committer in the past 30 days plus every user with platform access. For example, if 8 of your 10 developers committed code last month and 1 security engineer accessed the platform without committing, you need 9 licenses. Inactive developers who didn't commit and don't have platform access aren't counted. The Free plan is capped at 10 users per organisation; Premium and Ultimate have no user cap — you're billed for however many licenses your organisation uses that month. See the full license model documentation for details.
AquilaX is typically 20–30% more cost-effective than legacy tools like Veracode, Checkmarx, or Snyk at equivalent feature coverage. Beyond the headline price, the reduction in manual triage time (93.54% fewer false positives) and automated remediation (AI-generated pull requests) translate directly to developer hours saved. Use our free AppSec Cost Calculator to model your specific savings.