Pricing

Pay for the assets you monitor, not the ones we discover.

A flat monthly price with a monthly allowance of Audits and Checks. Two counted units, no per-scan billing, and re-testing a fix we already reported is always free.

Annual billing: twelve months for the price of ten. Switch to monthly any time.

Free
Try continuous external attack-surface scanning.
$0 forever
25 assets1 user
Start free, no card
✓Continuous discovery, full-range ports
✓Port + service fingerprinting
✓Full-NVD CVE matching, version-aware, KEV + EPSS
✓Partner API (v1) + API keys
·AI exploit validation
·Deep Audit
·Notifications & scheduled scans
Starter
One application and a small external estate.
$208 /mo
billed annually · save $498
250 assets3 users
Start free
✓Everything in Free
✓1 Audit a month: a full AI pentest of one application, up to 10 related backends included
✓15 Checks a month: prove a service is exploitable, or that a reported CVE is real
✓Re-testing your own fixes is always free
✓All notification channels: Slack, email, webhook, Jira, GitHub
✓Weekly re-scans
Essential
A product team with a live application and a real external footprint.
$1,250 /mo
billed annually · save $3,000
500 assets10 users
Start free
✓Everything in Starter
✓2 Audits and 50 Checks a month
✓Credential exposure monitoring, 1 verified root domain
✓Cloud posture across AWS, Azure and Google Cloud, 3 accounts
✓Audit log of who did what
✓Two-way Jira and GitHub sync, Splunk and Microsoft Sentinel
✓Daily re-scans
Most security teams
Standard
A security function of one to three people across several applications.
$3,333 /mo
billed annually · save $8,000
2,500 assets40 users
Start free, upgrade when ready
✓Everything in Essential
✓10 Audits and 200 Checks a month
✓4 internal network assessments a month: Active Directory, ADCS, lateral movement
✓Compliance evidence for SOC 2, ISO 27001, NIS2 and GDPR, with auditor share links
✓Credential exposure for 2 root domains
✓15 cloud accounts
✓Re-scans every 12 hours
Scale
A real security team, a multi-product estate, and a week of a human pentester every year.
Custom
scoped with you
10,000 assets150 users
Talk to us
✓Everything in Standard
✓30 Audits, 600 Checks and 10 internal assessments a month
✓A 5-day human penetration test over a scope you agree with us, every year
✓Credential exposure for 3 root domains
✓50 cloud accounts
✓Re-scans every 6 hours
Enterprise
Multi-business-unit or MSSP. Every number contracted.
Custom
annual contract
Custom assetsCustom users
Talk to us
✓Everything in Scale
✓Every limit contracted: assets, Audits, Checks, cloud accounts, seats
✓Dedicated scanning capacity
✓Dedicated CSM and an SLA
✓MSSP multi-workspace

All paid tiers include unlimited discovery, scheduled re-scans, 90-day data retention on cancellation, and no per-seat hidden fees. Scanning is never metered: set whatever cadence you like.

How the bill works

Two things are counted. Everything else is included.

Your plan includes a set number of Audits and Checks every month. Monitoring, discovery, scan cadence, cloud posture, reports, exports, integrations and API access are never metered. If you run out, buy more or move up a plan; the page shows the date your allowance resets, so waiting is always an option.

Re-testing a finding we already reported is free and never spends a Check. Charging you to confirm your own fix would be a strange way to encourage fixing.

Unit 1
Audit

One complete Deep Audit of one application, whatever its size, with up to ten related backends included. No per-backend charge. A scan that fails before producing anything returns the Audit automatically.

1 to 3 hours typically · 10h max
Unit 2
Check

One AI verification, whatever it took: proving a service is exploitable, or that a reported CVE is real on this exact target. Three verdicts, request and response attached.

Median 73s to a verified critical CVE
Never counted: discovery · fingerprinting · CVE matching · re-scans · cloud posture · credential exposure · reports · exports · integrations · API · re-tests
Compare plans

What unlocks where.

FreeStarterEssentialStandardScaleEnterprise
Assets monitored 25 250 500 2,500 10,000 Custom
Users 1 3 10 40 150 Custom
Audits / month · 1 2 10 30 Custom
Checks / month · 15 50 200 600 Custom
Re-scan cadence manual weekly daily 12 h 6 h Custom
Continuous discovery + CVE matching ✓ ✓ ✓ ✓ ✓ ✓
AI exploit validation · ✓ ✓ ✓ ✓ ✓
Deep Audit (web apps) · ✓ ✓ ✓ ✓ ✓
Notifications, Jira, GitHub, Slack · ✓ ✓ ✓ ✓ ✓
Cloud posture accounts · · 3 15 50 Custom
Credential exposure domains · · 1 2 3 Custom
Two-way sync · Splunk · Sentinel · · ✓ ✓ ✓ ✓
Internal assessments / month · · · 4 10 Custom
Compliance evidence packs · · · ✓ ✓ ✓
Human pentest (5 days / year) · · · · ✓ ✓
SSO · audit log · API SSO, API ✓ ✓ ✓ ✓ ✓
Dedicated capacity · CSM · SLA · · · · · ✓
Add-on · available on Starter and every plan above

Deep Audit: one Audit per scan, backends included.

An end-to-end web application audit. A 56-module scan finds what rules find, an AI Triager judges every finding live, and the AI Explorer hunts for what scanners can't see: IDOR, OAuth bypass, mass assignment, business-logic flaws. One Audit covers the application and up to ten related backends. The AI budget is shared across the whole mission, so extra backends split the same work rather than adding to it.

Read the full doc →
Deep Audit · app.example.com1 Audit
1
application
6 /10
backends included
$0
per-backend surcharge
api.example.com · auth.example.com · editor.example.com · cdn · search · billingin scope
AI processing, triage and explorationincluded
Scan fails before producing anythingAudit returned
Common questions

The answers a procurement thread usually needs.

Something not covered?

Security questionnaires, DPA, subprocessors, a specific residency region, or an MSSP setup. Write to us and a person answers.

Talk to usSecurity page
DPA on request · subprocessor list published · PGP key on /security
What exactly counts as an asset?

One tracked host (one IP). Discovery is unlimited and free. You only consume an asset slot when you explicitly tick a host to monitor on the Assets page. Untracked hosts stay discoverable and cost nothing.

How does the AI billing work?

Two things are counted: Audits and Checks. Your plan includes a set number of each every month, and re-testing a fix you have already had reported is always free. If you run out, buy more or move up a plan; the page tells you the date your allowance resets. Everything else is included and never metered.

How is Deep Audit billed?

One Audit, whatever the size of the application, covering the app and up to ten of the backends it talks to. Past ten the budget is spread too thin to test any of them properly, so the honest answer is a second Audit. If a scan fails before producing anything, the Audit is returned automatically.

Can I cancel anytime? What happens to my data?

Yes, from Billing in-app, no support email needed. Scans pause immediately; you keep read-only access for 90 days and can export findings as JSON or CSV. After 90 days the org's data is deletion-eligible, with emails at day 30 and day 75 first.

Do you offer EU data residency?

Yes, on every plan including Free. It is the default, not an upgrade. The platform runs in Helsinki, Finland and scan artifacts are stored in Stockholm, Sweden, both inside the EU. A specific country or a region outside the EU can be arranged by contract where supported.

Do you have an on-prem or self-hosted version?

No, and it's not on the roadmap. Umbra is SaaS-only: one install we maintain, predictable infrastructure, no per-customer support burden. If your security policy forbids sending external recon data off-prem, we're not the right fit.

Start with 25 assets. Upgrade when you outgrow them.

Start freeTalk to us

No credit card · cancel anytime · EU data residency by default · SSO with Google and Microsoft on every plan · DPA available