Umbra
Pricing

Pay for the assets you monitor, not the ones we discover.

Flat per-month for the monitoring product. AI validation metered in real dollars with a ~2× markup. No surprise bills.

Free

Try continuous external attack-surface scanning.

$0 / mo
$0 / mo
  • 10 assets
  • 1 users
  • Continuous discovery
  • Port + service fingerprint
  • Full-NVD CVE matching: version-aware, KEV + EPSS prioritized
  • Partner API (v1) + API keys
  • · AI exploit validation
  • · Deep Audit
  • · Notifications & scheduled scans
Start free
Starter

External monitoring + AI exploit validation for a small team.

$99 / mo
billed monthly
$83 / mo
billed annually · save $198
  • 100 assets
  • 3 users
  • $20 bundled AI / mo
  • Everything in Free
  • AI exploit validation (per-CVE, metered) + optional auto-verify of new KEV findings
  • Deep Audit web-app audits (metered, see add-on)
  • All notification channels: Slack, email, webhook, Jira, GitHub, SIEM
  • Weekly email digest
  • Scheduled re-scans
  • $20/mo AI validation included
Start 14-day trial
most popular
Pro

The daily driver for growing cloud-native security teams.

$499 / mo
billed monthly
$416 / mo
billed annually · save $998
  • 1,000 assets
  • 10 users
  • $100 bundled AI / mo
  • Everything in Starter
  • Cloud security posture: AWS, GCP & Azure (read-only): misconfig findings, internet→data attack paths, remediation, PDF
  • Auto-create Jira / GitHub tickets from rules
  • Google + Microsoft SSO (OIDC)
  • Audit log + CSV / JSON export
  • Granular access: per-target grants + per-user module access (restrict a teammate to specific modules)
  • Asset business-context (criticality, owner)
  • $100/mo AI validation included
Start 14-day trial
Business

Compliance + internal pentest for regulated teams.

$1,999 / mo
billed monthly
$1,666 / mo
billed annually · save $3,998
  • 10,000 assets
  • 25 users
  • $400 bundled AI / mo
  • Everything in Pro
  • Internal Pentest: enroll on-prem agents, run internal-network assessments (84 techniques, 54 native / $0) + AI exploit runs
  • Compliance evidence packs: SOC 2 · ISO 27001 · NIS2 · GDPR
  • Shareable compliance pack (password-gated public link)
  • Executive risk report (board-ready PDF)
  • $400/mo AI validation included
Start 14-day trial
Enterprise

Custom: SLA, dedicated CSM, MSP multi-tenancy.

Custom
  • Custom assets
  • Custom users
  • Everything in Business
  • Unlimited internal pentest: agents, assessments, org-wide scan
  • Dedicated CSM
  • 99.9% SLA
  • White-label / MSP multi-tenancy
  • Volume-discounted AI
Talk to us

All paid tiers include: unlimited discovery, scheduled re-scans, 90-day data retention on cancellation, no per-seat hidden fees. AI metered separately so a team that doesn't use AI doesn't pay for it.

Add-on

Deep Audit: $100/scan + $75/extra host

End-to-end web app audit: JupiterSec scans, AI Triager judges every finding, AI Explorer hunts for what scanners can't see (IDOR, OAuth bypass, mass assignment, business-logic flaws). $100 for the first host + $75 per additional host in the same scan. Available on Starter and every plan above. Buy one when you need it, no upgrade required within your tier. AI processing capped at $30 per scan (paid for by the fee, not your AI balance).

1–3 hours typically, 10h max. Read the full doc →

$100
+ $75 / extra host
Start an audit

Common questions

What exactly counts as an asset? +

One tracked host (one IP). Discovery is unlimited and free. You only consume an asset slot when you explicitly tick a host to monitor on the Assets page. Untracked hosts stay discoverable and cost nothing.

How does the AI billing work? +

AI validation runs are metered in real dollars. Each paid plan includes a monthly bundled allowance (resets at billing close, use-it-or-lose-it). You see an estimated cost before every run and can buy top-up credits ($25 / $100 / $500) that persist with 12-month expiry. Per-run ceiling caps any single anomalously-expensive run. If a run blows past the ceiling, Umbra eats the overage.

How is Deep Audit billed? +

$100 per scan for the first host, plus $75 for each additional host in the same multi-host scan, charged at launch. The fee covers the entire pipeline: JupiterSec runtime, AI Triager (Phase 3), AI Explorer (Phase 4), and persistence. AI processing is hard-capped at $30 per scan and is paid for by the flat fee, NOT debited from your bundled/topup AI balance. Those buckets are reserved for metered actions (CVE validation, agent runs, Ask Lumi). If a pathological target somehow blows the $30 AI cap, the scan completes with partial coverage; you're never billed beyond the scan's per-host total. Deep Audit is available on Starter and every plan above (not Free).

Can I cancel anytime? What happens to my data? +

Yes, cancel from Billing in-app, no support email needed. Your scans pause immediately; you keep read-only access to all your data for 90 days during which you can export findings as JSON / CSV. After 90 days the org's data is deletion-eligible (you'll get an email at day 30 and day 75 first).

Do you offer EU data residency? +

Not yet for the SMB tiers. Business+ customers who need EU-only hosting can request it during their trial and we'll bring up an EU region for them. Single-region (Hetzner Falkenstein) for v1.

Do you have an on-prem or self-hosted version? +

No, and it's not on the roadmap. Umbra is SaaS-only: one install we maintain, predictable infrastructure, no per-customer support burden. If your security policy forbids sending external recon data off-prem, we're not the right fit.

Start free →

No credit card. Upgrade when you outgrow the free tier.