Pricing

Honest pricing for an open-core security tool.

Free if you self-host. Cheap if you don't. Custom only when scope genuinely requires it.
Plan calculator

Choose the deployment path

Open core
$0Self-host
$15Team annual
CustomPrivate tenant
Open source

Self-host the full platform under Apache 2.0. The binary the hosted plan runs is the same one you do.

$0forever
  • Trust graph + path resolution
  • AWS, Kubernetes, GitHub OIDC connectors
  • Repo exposure scanning
  • Policy simulator (read-only)
  • Community support on Discord
  • No usage limits, no hidden detections
Enterprise

Private tenancy, regional controls, named support, and the procurement surface large security organisations expect.

Customtailored to scope
  • Everything in Team
  • Private single-tenant deployment
  • SCIM, audit log streaming
  • Custom data residency
  • Named TAM and onboarding program
  • Custom SLA, security review, MNDA
Compare in detail

What's in each plan, line by line.

If a row matters to you and is missing here, ask — we'll either explain or add it.
CapabilityOpen sourceTeamEnterprise
AWS IAM trust-path resolutionIncludedIncludedIncluded
Kubernetes RBAC + workload identityIncludedIncludedIncluded
GitHub Actions OIDC stitchingIncludedIncludedIncluded
Repo credential exposure scanningCore detectorsExtended detectors + auto-revoke playbooksCustom detectors per workspace
Policy simulatorRead-onlyRead-only + dry-run + canaryAll gates + scoped enforcement windows
Hosted in our cloudNo (self-host)US or EUUS, EU, or your region
SAML SSOSelf-host any IdPIncludedIncluded + SCIM
Audit log streamingLocal logWebhookS3, Splunk, Datadog, Elastic
SupportCommunity DiscordEmail, business hours24/7 with named TAM and custom SLA

Pricing FAQ

Why is the hosted plan cheaper than other security tools?

Because the engine is open source. We are not amortising a private platform investment over every seat — we are charging for the part you genuinely benefit from outsourcing: hosting, hardening, scheduled scans, alerting, support. If you do not need any of those, the OSS edition is the same code, free.

Is there a free trial?

The Open source edition is free forever. The hosted Team plan includes a 14-day trial with no card required. Enterprise pilots are scoped per engagement.

Do you require write access to my cloud?

No. Connector setup uses read-only credentials. Policy enforcement is a separate, opt-in surface that requires explicit approval and named operators. You can run Identrail in read-only mode forever.

What about data residency?

Hosted Team customers pick US or EU. Enterprise customers pick a region or run a private single-tenant deployment in a region of their choice. Self-host gives you complete control.

Is Identrail SOC 2 compliant?

Honest answer: not yet. SOC 2 Type I is in progress and on a public roadmap on the /security page. Enterprise customers can review our security posture and receive an MNDA-protected security questionnaire on request.

Start free. Upgrade when the team grows.

The fastest way to evaluate Identrail is the free risk scan — read-only, ten minutes, real findings against your environment.