Free
For anyone trying CybeDefend on real code.
$0
- 10static scans
- 50AI credits
- the whole platform
No card, no time limit.
SAST, SCA, IaC and secret scansAutoFix and BLSA, with your credits
We use analytics and ad-measurement cookies (Google, Meta). Nothing is sold, and you can decline.
For anyone trying CybeDefend on real code.
$0
No card, no time limit.
SAST, SCA, IaC and secret scansAutoFix and BLSA, with your credits
For solo devs shipping side projects with an AI agent.
$19/mo
$228 billed yearlySave 10%
3 repositories · 1 seat100 AI credits / month
In every plan
For small product teams shipping every week.
$229/mo
$2,748 billed yearlySave 8%
10-20 repositories · 5-10 seats1,500 AI credits / month
Everything in Developer, plus
For platform teams scaling a security programme.
$640/mo
$7,680 billed yearlySave 8%
25-50 repositories · 15-25 seats5,000 AI credits / month
Everything in Team, plus
Custom deployment for regulated, multi-team orgs.
Custom quote
Talk to salesTeam and Scale grow with add‑ons: $12 per extra repository, $24 per extra seat. Add‑ons are billed monthly. Annual billing applies to the base plan.
$249/mo
$249 base
What ships in each plan, side by side. No asterisks, no upsell traps.
| Feature | Developer$19/mo | Team$229/mo | Most popularScale$640/mo | EnterpriseCustom quote |
|---|---|---|---|---|
| Pricing & limits | ||||
| Repositories | 3 | 10 (up to 20, +$12/mo each) | 25 (up to 50, +$12/mo each) | Unlimited |
| Developer seats | 1 | 5 (up to 10, +$24/mo each) | 15 (up to 25, +$24/mo each) | Unlimited |
| AI credits / month | 100 | 1,500 | 5,000 | Unlimited |
| Static scans (SAST/SCA/IaC/Secrets) | Unlimited | Unlimited | Unlimited | Unlimited |
| Core security scanners | ||||
| AI-BOM · Discovery & cataloging (EU AI Act / NIST AI RMF) | Not included | Not included | Included | Included |
| SAST · Static analysis with reachability | Included | Included | Included | Included |
| SCA · Dependencies + license risk | Included | Included | Included | Included |
| Secret Detection · Catch leaked tokens before commit | Included | Included | Included | Included |
| License Compliance · Open-source license risk, classified | Included | Included | Included | Included |
| IaC · Terraform · CloudFormation · Ansible · K8s | Included | Included | Included | Included |
| Container Security · Image scanning + runtime context | Not included | Included | Included | Included |
| CI/CD · GitHub Actions · GitLab CI · Jenkinsfile · Tekton | Included | Included | Included | Included |
| BLSA (business-logic security) | Not included | Not included | Early access | Included |
| Integrations | ||||
| GitHub & GitLab | Included | Included | Included | Included |
| IDE plugins (VS Code, JetBrains, Cursor, Claude Code) | Included | Included | Included | Included |
| VibeDefend · agent-time review on every prompt | Included | Included | Included | Included |
| Action Guard · LLM judgment on risky actions | 500, then regex | 500, then regex | Unlimited* | Unlimited* |
| CI/CD (GitHub Actions, GitLab CI, Jenkins, Azure DevOps, Bitbucket Pipelines) | Not included | Included | Included | Included |
| REST API | Not included | Included | Included | Included |
| Slack integration | Not included | Included | Included | Included |
| Container Registries (Docker Hub, GCR, ACR, Quay, GitHub/GitLab Registries, AWS ECR, Harbor, JFrog) | Not included | Included | Included | Included |
| Task management (Jira, Linear) | Not included | Included | Included | Included |
| Issue tracking (GitHub Issues, GitLab Issues) | Not included | Included | Included | Included |
| Capabilities | ||||
| Cybe AutoFix (verified patches) | Included | Included | Included | Included |
| Cybe Security Champion (IDE copilot) | Included | Included | Included | Included |
| Zero-Day Threat Monitoring | Included | Included | Included | Included |
| Business-context engine | Not included | Basic | Advanced | Custom |
| Role-Based Access Control (RBAC) | Not included | Included | Included | Advanced |
| GRC / SIEM export | Not included | Included | Included | Included |
| Security Policies | Not included | Not included | Included | Included |
| SBOM generation (CycloneDX, SPDX) | Not included | Not included | Included | Included |
| Report Generation (OWASP, CWE exports) | Not included | Not included | Included | Included |
| Reports by Scanner Type | Not included | Not included | Not included | Included |
| Report storage · retention | Not included | Not included | 90 days | 365 days |
| SSO / SAML | Not included | Not included | Not included | Included |
| Dedicated tenant / on-premise** | Not included | Not included | Not included | Included |
| Services | ||||
| Community support | Included | Included | Included | Included |
| Email support | Included | Included | Included | Included |
| Dedicated Slack channel | Not included | Not included | Included | Included |
| Response time | Best effort | Within 72 hours | Within 24 hours | 24/7 Priority |
| Account manager | Not included | Not included | Not included | Included |
| Onboarding workshop | Not included | Not included | Included | Included |
| Uptime SLA | Best effort | Best effort | Best effort | 99.5% |
| Roadmap influence | Not included | Not included | Quarterly | Direct |
Building with agents? Two tiers, decided by your stage.
You have not raised yet and you are part of an incubator or an accelerator.
On the plan you pick. Then the standard price of that plan, nothing else changes.
You have raised a round.
Same deal, shorter, because you have runway.
Every account starts with 50 AI credits and 10 free static scans, no card, no time limit. Spend the credits on Cybe AutoFix patches and BLSA business-logic scans. The 10 scans cover SAST, SCA, IaC and secret detection. Paid plans unlock unlimited static scans, so you upgrade the day you need more.
AI credits power Cybe AutoFix patch generation and BLSA business-logic analyses. Static scans, SAST, SCA, IaC and secret detection, never consume credits. They're unlimited on every paid plan.
Yes. Upgrade from your dashboard at any time. Changes prorate to the day.
We run two isolated regions: EU (eu.cybedefend.com) and US (us.cybedefend.com). You pick at signup, your data stays where you put it. Enterprise customers can deploy in a private VPC or on-premise.
Enterprise comes with a contractual 99.5% uptime SLA on dedicated infrastructure (VPC or on-prem), plus SSO / SAML, advanced RBAC, 24/7 support and a named account manager. Scale runs on shared infrastructure with Slack support, BLSA early access and the advanced business-context engine, built for platform teams scaling a security programme without yet needing the dedicated-tenant + audit-heavy guarantees of Enterprise.
One command wires every coding agent on your machine to CybeDefend: your business rules, your compliance frameworks, and guards that block destructive calls before they fire.
npx -y @cybedefend/vibedefend@latest install