Simple, Developer-Friendly Pricing

The CLI is free and open source. Cloud adds team-wide visibility into audit findings, SBOM history, package alerts, and audit evidence.

Open Source

Free
  • Full CLI with all detection modules
  • Local scanning — unlimited
  • MCP config monitoring
  • Credential detection
  • Community support via GitHub
  • MIT licensed
Clone on GitHub
Most Popular

Team

$29 /dev/mo
  • Everything in Open Source
  • Cloud dashboard for team visibility
  • Team scan telemetry
  • Real-time alerts (Slack, email, webhook)
  • 30-day scan history
  • Priority support
Start Team Trial

Enterprise

Custom
  • Everything in Team
  • SSO / SAML integration
  • Unlimited scan history
  • Dedicated support engineer
  • On-premise deployment option
  • Custom compliance reports
Contact Sales
Enterprise

Book a Demo or Talk Enterprise

Sandtrace Cloud is live for teams that want shared audits, SBOM history, alerting, and compliance evidence around package risk. Tell us how you want to use it and we will help with rollout or enterprise requirements.

Centralized audit and SBOM history
Commit-level package inventory and diffs
Security alerts and API-key access control
SOC 2 and audit-friendly evidence exports

We use this information to schedule demos, prioritize beta access, and plan enterprise features.

Frequently Asked Questions

Is the CLI really free?

Yes. The Sandtrace CLI is MIT licensed and free forever. All detection modules are included. No limits on scans.

What does Cloud add?

Sandtrace Cloud adds team-wide visibility around dependency risk: centralized dashboards, audit history, SBOM timelines, package alerts, and compliance reporting.

Can I self-host the Cloud features?

Enterprise plans include on-premise deployment options. Contact us for details.

How does billing work?

Cloud plans are billed per active developer per month. You only pay for developers or CI workflows that send scan telemetry to the hosted service.

Do you upload every raw event by default?

No. The default cloud path is summary-first: findings, verdicts, package inventory, and metadata. Detailed raw telemetry is not part of the launch product.