Pricing
Published prices. Organization-wide, never per seat.
Both billing intervals are shown together. Annual billing charges ten monthly
payments for twelve months.
Free
- Monthly
- USD 0
- Annual
- USD 0
Security Operations
- Monthly
- USD 189
- Annual
- USD 1,890
Penetration Test Management
- Monthly
- USD 229
- Annual
- USD 2,290
Compliance Automation
- Monthly
- USD 629
- Annual
- USD 6,290
Complete Bundle — all three
- Monthly
- USD 919
- Annual
- USD 9,190
Enterprise
- Monthly
- Quoted
- Annual
- Quoted
The commercial rules
- Prices are organization-wide, never per seat.
- Unlimited organization members. People are never counted.
- No commercial quota on assessments, pentest uploads or generated reports —
technical, concurrency, rate, safety and fair-use controls still apply.
- List prices cover up to 500 billable assets for Security
Operations and the Complete Bundle. Penetration Test Management and
Compliance Automation carry no asset threshold.
- Annual billing is ten monthly payments for twelve months.
- Prices are tax-exclusive where legally permitted; tax is calculated at checkout.
- AI provider usage is paid by your organization directly to your
provider. CheckAI does not resell it or mark it up.
- No mandatory setup fee.
- Best-effort email support is included. See the support terms.
- Payment is by card through Stripe-hosted checkout.
What counts as a billable asset
A billable asset is a distinct target that generates its own assessment or
collection cycle. It is a narrower set than the full inventory CheckAI builds
for you — most of what appears in your asset list is never billable.
Counted
- A verified domain or discovered hostname under active assessment
- A compute workload — an EC2 instance, an ECS or EKS service,
a Lambda function, or an RDS instance
- A source repository under active assessment
- A container image under active assessment
- An identity-provider tenant
Never counted
- Packages and dependencies — enumerated inside a repository sync
- Configuration and network objects — security groups, network
interfaces, VPCs, IAM policies, KMS keys, CloudTrail and Config
metadata, S3 bucket configuration
- Registries, and logical application or service groupings
- People and identities of every kind — users, service
accounts, cloud roles and API identities
Kubernetes and other ephemeral compute is counted as services or task
definitions, never as running pods or instances — so autoscaling never
changes your bill. Your current billable count is shown in the product, against
the 500 included.
When we quote instead
We quote an organization running more than 500 billable assets,
because a larger estate consumes proportionally more scanning and collection.
We also quote where you need negotiated contract terms, a data processing
addendum beyond our standard route, a support SLA, SSO/SAML, or custom
engineering work.
Crossing 500 assets never stops your scans, never removes a capability and
never silently excludes an asset from assessment. It starts a conversation,
not an outage. Email us about a quote.