Safeguard
Pricing

Start free. Scale as you grow.

Every plan carries every feature. What changes is how much runs for you, and whether your data sits on its own.

2 months free

Free

A real scan on your code, with no card and no expiry.

$0
forever
Start free
5 fix PRs / month
  • 100 components scanned / month
  • 100 MCP tool calls / month
  • All scanners at view depth
  • At least 1 on-demand scan / month

Starter

Full scanning and autonomous fix PRs for one developer.

$9
/ month
$89 / year
Start Starter
25 fix PRs / month
  • 2,500 components scanned / month
  • 1,000 MCP tool calls / month
  • Full scan depth on every scanner
Most popular

Pro

More headroom, ticketing, and posture remediation.

$25
/ month
$249 / year
Start Pro
75 fix PRs / month
  • 7,500 components scanned / month
  • 3,000 MCP tool calls / month
  • Ticketing and posture remediation

Plus

Bulk remediation and provenance work at higher caps.

$49
/ month
$489 / year
Start Plus
200 fix PRs / month
  • 20,000 components scanned / month
  • 8,000 MCP tool calls / month
  • Bulk and compliance remediation

Max

The top consumer headroom, before data isolation.

$99
/ month
$999 / year
Start Max
500 fix PRs / month
  • 50,000 components scanned / month
  • 20,000 MCP tool calls / month
  • Highest self-serve ceiling
Compare

Every capability, plan by plan.

Straight from the pricing matrix, grouped the way the product is built. Open a category to see what each plan gives you.

Every capability by plan, grouped into categories. Generated from the pricing matrix.
Free
$0
forever
Start free
Starter
$9
/ month$89 / year
Start Starter
Most popular
Pro
$25
/ month$249 / year
Start Pro
Plus
$49
/ month$489 / year
Start Plus
Max
$99
/ month$999 / year
Start Max
Isolation levelSharedSharedSharedSharedShared
Separate data lake per tenant
Data residency = region you buy inBuy-regionBuy-regionBuy-regionBuy-regionBuy-region
Single region (set at purchase)
Multi-region option (high tiers only)
Choose single-tenant vs multi-tenant (high tiers)MultiMultiMultiMultiMulti
Region pinning (data never leaves)
Customer-managed encryption keys (BYOK)
Tenant-isolated backups
Included on this planNot on this planA value in a cell is the limit or the variant you get.

Business, Enterprise and Sovereign are scoped per customer, so their amounts are agreed in the contract rather than listed.

Add-ons

Add more to any paid plan.

Each attaches to a plan you already hold, scoped to the region you buy in. Pick the plan first, then add what you need.

Compliance packs

$2,099per framework, per year
  • Ten leading frameworks

    SOC 2, ISO 27001, HIPAA, GDPR, PCI, NIST, CMMC, FedRAMP mapping, EU AI Act and regional.

  • Bundles cost less than the parts

    Most frameworks share the majority of their controls, so a second one is far cheaper than the first.

  • Evidence collected continuously

    Controls map to what we already scan, so evidence accrues instead of being gathered at audit time.

  • Scoped to your region

    The frameworks on offer are the ones that apply where you bought.

Safeguard-run audit

from$11,999per engagement
  • One vendor, start to finish

    Software, evidence and auditor in one place rather than three procurements.

  • An independent auditor of record

    Accredited third party in our network, coordinated by us, so independence still holds.

  • Priced per engagement

    Quoted against your scope; the figure above is a starting point, not a rate card.

  • Startups have a flat rate

    SOC 2 Type II at $1,699 a year under ten people.

Choose your paid plan first, then add an add-on. Prices are proposed and confirmed per deal; frameworks are not sold on their own.

Community & Startup Programs

We also run free and discounted programs. Every program requires completing a short eligibility form; if you qualify, you are approved quickly after verification.

Not sure if you qualify? Open a program and complete its eligibility form. Every program starts with the form; approval is quick once verified.

What you are buying

Four products, one platform price.

ESSCM and OSM are priced by the tiers above. Portal and TPRM meter on their own units, so they carry standalone tiers as well as being included in ESSCM Enterprise.

ESSCM

Enterprise Software Supply Chain Management

The platform: SCA with reachability, SBOM and AIBOM, container, IaC and secret scanning, and autonomous remediation with Griffin AI.

Priced by the tiers above

OSM

Open Source Management

Curated zero-CVE components, licence posture, and package health scoring across every ecosystem you pull from.

Included in every plan

Portal

SBOM Portal

Publish, share, and redistribute SBOMs to customers and regulators, with versioning and NTIA minimum elements.

Standalone from $49/mo, or included in ESSCM Enterprise

TPRM

Third-Party Risk Management

Request, validate, and monitor supplier SBOMs, with a 0-100 risk score per vendor and continuous KEV alerting.

Standalone from $99/mo, or included in ESSCM Enterprise

Portal standalone

per product published
TierPriceIncludedAdds
Free$01 productPublic link
Starter$495 productsLink and email, versioning, NTIA minimum elements
Growth$19925 productsBranded portal, NDA-gated, tracked, custom domain
Business$499100 productsBranded plus API, EO 14028 and FedRAMP verification, audit trails
EnterpriseCustomUnlimitedWhite-label, SIEM export, roles

TPRM standalone

per vendor monitored
TierPriceIncludedAdds
Free$05 vendorsRisk score 0-100, view only
Starter$9925 vendorsBulk requests, status tracking, alerts
Growth$299100 vendorsAutomated follow-ups, continuous monitoring, KEV alerts
Business$799500 vendorsFull automation, Slack, Teams and PagerDuty, webhooks
EnterpriseCustomUnlimitedSIEM and SOAR, custom SLAs
Compliance

Frameworks are add-ons, priced and published.

Attach a framework to any paid plan, scoped to the region you buy in. Annual, per framework, and cheaper than the automation tools that only do compliance.

Framework packs

Annual price per compliance framework
SOC 2 (Type I & II)$2,099/yr
ISO/IEC 27001$2,099/yr
HIPAA / HITECH$2,099/yr
GDPR$2,099/yr
PCI DSS v4.0$2,799/yr
NIST CSF 2.0 / 800-53$2,799/yr
NIST 800-171 / CMMC L2$3,499/yr
FedRAMP (Mod/High) mapping$4,199/yr
EU AI Act / DORA / NIS2$2,799/yr
Regional (India DPDP, SAMA/PDPL)$2,099/yr

Bundles

Most frameworks overlap heavily, so a second one costs far less than the first.

Compliance bundles
StarterSOC 2 + ISO 27001$4,199/yr
HealthcareSOC 2 + HIPAA$4,199/yr
FintechSOC 2 + PCI + ISO 27001$6,999/yr
FederalNIST + 800-171 + FedRAMP mapping$10,499/yr
Full library373 frameworksIncluded with Enterprise and Sovereign
Under 10 people
$1,699/yr, SOC 2 Type II

A flat startup rate, and the same subscription also covers your application and supply-chain security rather than compliance alone. Moves to standard pricing once you pass ten people.

The audit itself

Software, evidence and auditor from one place. Priced per engagement, so these are starting points rather than a rate card.

SOC 2 Type Ifrom $3,999
SOC 2 Type IIfrom $11,999
ISO 27001from $7,999
HIPAA attestationfrom $3,999
PCI DSSQuoted by level
FedRAMP / CMMCQuoted per engagement

Where an attestation requires an independent auditor, the auditor of record is an accredited third party in our network, coordinated by us. You deal with one point of contact and the independence requirement is still met. We do not audit ourselves.

Frameworks attach to a paid plan and are scoped to the region you purchase in. They are not sold on their own. Prices are proposed and confirmed per deal.

Gold

Start from components that are already clean.

A public directory of 6,000+ curated hardened components, free and without an account. The paid rung is for pulling them at volume, privately, with an SLA.

Gold Open Source

gold.safeguard.sh
Free
  • Public directory, no login
  • CVE, KEV and zero-day coverage
  • 20+ ecosystems
  • Read-only JSON API
  • README badges and a CI gate action

Gold Registry Free

registry.safeguard.sh
Free
  • Public hardened-artifact pull, rate limited
  • Free read API

Gold Registry Pro

Talk to us
  • Unlimited pulls
  • An SLA on custom Gold requests
  • Private Gold forks of your own packages

Gold Registry Enterprise

Custom
  • A dedicated Gold mirror inside your VPC
  • Air-gapped snapshot delivery
  • Custom SLA

Private forks of your own packages are in beta, so the paid rung is quoted rather than listed. The directory and its read API stay free.

Start in minutes

From zero to your first prioritized fix

No sales call to begin. Connect a repository and Safeguard runs a real scan: SBOM, reachability-based prioritization, and Griffin AI fix suggestions, on the free tier.

  1. 01

    Create your account

    Sign up in under a minute at app.safeguard.sh. No sales call required to get started.

  2. 02

    Connect a repository

    Link a Git repo from GitHub, GitLab, Bitbucket, or Azure DevOps in a couple of clicks.

  3. 03

    Run your first scan

    Safeguard generates an SBOM and runs SCA with reachability across your dependency tree.

  4. 04

    Review prioritized fixes

    See only the reachable, exploitable findings, each with a Griffin AI fix suggestion you can apply.

Enterprise

Four levers, no surprise line items.

Self-serve tiers are fixed and public. Business and above are scoped on these four, walked through on a call that is free and non-binding.

Reasoning budget

Which Griffin variants you call, Lite, S, M, L, or Zero, and how often. Inference cost dominates platform cost, not headcount.

Deployment isolation

Shared cloud, dedicated tenant, private VPC, on-prem, or fully air-gapped. Isolation posture changes the architecture and the price.

Compliance scope

Which packs you switch on, SOC 2, ISO 27001, NIST, DORA, NIS2, FedRAMP, STQC, and the audit-evidence depth you need.

Environment shape

Repos, container registries, build systems, MCP servers, third-party vendors. The surface area we scan defines the workload.

From first call to first deployment

  1. 01

    Discovery call

    Twenty to thirty minutes. We learn your stack, your regulatory posture, and what success looks like for your team.

  2. 02

    Technical scoping

    Our solutions engineer walks through deployment shape, reasoning budget, and integration points with your team.

  3. 03

    Tailored proposal

    A written proposal scoped to your environment, with line items you can defend and no surprise add-ons at renewal.

  4. 04

    Pilot and rollout

    Time-boxed pilot on a real repo or workload, then phased rollout with a dedicated technical account manager.

FAQ

The questions everyone asks first.

Will our code train your models?

No. Your source, your SBOMs and your telemetry are never used to train shared models, and that is true on every plan including the free one. If you need the models themselves isolated, Enterprise and Sovereign can run them dedicated to you, deployed on-premise or air-gapped, and on Sovereign they run entirely inside your environment so nothing leaves it. This is the answer to the question regulated buyers ask first, so it is a commitment rather than a setting you have to find.

How much does Safeguard cost?

There is a Free tier at $0 forever with no card required. Paid individual plans are a flat monthly price for your own account, not a seat price: Starter $9, Pro $25, Plus $49, and Max $100 a month. All four paid tiers carry every feature and differ only in how much you may use. Seat pricing starts where teams do: Team S is $19 per user per month with a two-user minimum, which is where data isolation begins, then Team M at $49 and Team L at $99. Business, Enterprise, and Sovereign are scoped per customer, so they are quoted on a call rather than listed. Open-source maintainers, nonprofits, students, and educators can qualify for free licences. All figures are proposed pending final sign-off.

What do I get on the Free plan?

Five fix PRs a month, 100 components scanned, and 100 MCP tool calls. Paid plans carry unlimited projects; what is metered is components scanned. Every scanner is usable on Free at view depth, along with software composition analysis, an SBOM in CycloneDX and SPDX, reachability-based prioritization, and Griffin AI fix suggestions. Full scan depth starts at Starter. Free is free forever, with no card and no expiry, and includes at least one on-demand scan a month, not a time-limited trial.

What separates the paid self-serve tiers?

Usage headroom, and nothing else. Starter, Pro, Plus, and Max all include the same capabilities; you move up when you need more repositories, more fix PRs, more components scanned, or more API calls. That means you are never blocked from a feature by your plan, only by volume.

What does a Team plan include and what is the minimum?

Team S is $19 per user per month with a minimum of two users. Team is where data isolation starts: your own data lake rather than a shared one, plus org dashboards, RBAC, SSO, shared policies and policy gates, and SBOM and AIBOM management. Team M at $49 and Team L at $99 add headroom and governance depth. The move from Pro to Team is the real boundary in the model: a shared tenant becomes an isolated one.

Do you offer annual billing?

Yes. Annual billing gives you two months free: you pay for ten and get twelve. On the individual plans that is $90 a year for Starter, $250 for Pro, $490 for Plus, and $1,000 for Max. On teams it is $190 per user a year for Team S, $490 for Team M, and $990 for Team L.

Do prices change by country?

Yes. There are four lists: a global list for the US, UK, Western Europe, Canada, Australia and the Gulf; a list about 25% lower for Eastern Europe and Latin America; a list about 55% lower for South and Southeast Asia and Africa; and an Indian list in rupees routed through TechD. The page detects your region and shows its list, with a switcher if you want to see another. Data residency follows the region you actually buy in, and the compliance frameworks available are that region's. Enterprise and Sovereign unlock multi-region deployment.

Is API and MCP access included?

Yes. The MCP server is on from the Free tier and the REST API is available everywhere, read-only on Free and full access from Starter up. Neither is sold separately; both are metered by the call allowance your tier already grants, from 100 MCP calls a month on Free to 20,000 on Max. Team plans and above agree volume and per-minute peaks in the contract.

Are there free plans for open source, students, or startups?

Yes. Public open-source maintainers and registered nonprofits and NGOs get free licences. Students and educators get free access with verification. Startups and bootstrapped companies qualify for free or heavily discounted licences. See the programs section above for how to apply.

How does Safeguard reduce false positives?

Reachability analysis. Safeguard maps whether vulnerable code is actually reachable and executed in your application, so it surfaces the exploitable issues instead of every CVE in your dependency tree. That is included from the Free tier up.

Can Safeguard fix vulnerabilities automatically?

Yes. Griffin AI authors a fix as a pull request, runs it through your CI, and once checks pass and you have opted in, can merge it without manual triage. Fix PRs are available from Free at five a month, and every paid tier includes autonomous remediation, differing only in monthly volume.

Why are Business and Enterprise scoped rather than listed?

Beyond the self-serve tiers, cost is dominated by reasoning budget, deployment isolation, and compliance scope, all of which are specific to your environment. Business is sized for a dedicated tenant of around 25 developers, Enterprise adds a private VPC and multi-region residency, and a thirty-minute call turns that into a number you can defend internally with no surprise line items.

Can I run air-gapped or sovereign?

Yes, on Sovereign. We support fully air-gapped, VPC-isolated, and sovereign-cluster deployments, including offline vulnerability-database sync, models that run entirely offline in Zero AI mode, on-prem GPU sizing support, and customer-controlled key material.

How are Portal and TPRM priced?

Both meter on their own natural units rather than on seats, so they have standalone tiers: Portal from $49 a month by products published, and TPRM from $99 a month by vendors monitored. Each also has a free entry tier — that is a $0 rung inside Portal or TPRM (1 product published, 5 vendors monitored), and is a different thing from the platform's Free plan, which is per developer and covers scanning. Both Portal and TPRM are included in ESSCM Enterprise.

What is Safeguard Academy?

Safeguard Academy is our free learning platform: courses and hands-on labs in software supply chain and AI security, with verifiable certifications you earn on the platform. It is free for every user, and a good starting point for students, teams, and anyone new to the space.

Do you support procurement reviews and security questionnaires?

Yes. We carry SOC 2, security documentation, and DPAs ready to share under NDA, and we respond to standard procurement questionnaires as part of the proposal stage.

Start free, or talk to us about scale.

Connect a repo in minutes on a self-serve plan, or tell us about your stack and regulatory posture and we'll scope an enterprise deployment.

Start free

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.