30-day trial · no credit card required

Pricing that scales with what you protect

Stop malicious open source packages reaching your developers, CI/CD pipelines, repositories and AI agents. Pay for the SDLC endpoints you protect, nothing else.

Free

For individuals and small projects getting started.

$0 forever
up to 3 endpoints
no card, no expiry
Includes
  • Up to 3 SDLC endpoints
  • Real-time malicious package protection
  • 7-day findings history
  • Centralized policies
  • Org-wide visibility & reporting
  • On-demand agents
Get Started

No credit card required

Most popular

Team

Org-wide protection from malicious third-party code, priced per endpoint.

How many SDLC endpoints do you protect? 5
What counts as an SDLC endpoint?
1 200
$100 per month
billed monthly
5 endpoints × $20 / month
Everything in Free, plus
  • Real-time protection across every endpoint
  • Centralized policies & org-wide findings
  • Cross-repository & endpoint visibility
  • 90-day findings history & audit trail
  • 50 on-demand scans included / month
  • Email support

Enterprise

For orgs with scale, compliance or deployment requirements.

Custom
volume endpoint pricing
Everything in Team, plus
  • Volume endpoint pricing
  • Single Sign-On (SSO)
  • Role based access control (RBAC)
  • MDM rollout & registry enforcement
  • Custom data retention & evidence
  • Enterprise integrations (SIEM, EDR)
  • SOC 2 and ISO 27001 reports
  • Central incident response
Talk to a Human

Typically replies same day

Explore all features
Feature Free Team Enterprise
Endpoints & protection
SDLC endpoints Up to 3 By subscription Custom / volume
Real-time malicious package protection
Dependency cooldown policy
Install sandboxing
Registry-level enforcement
Visibility & inventory
Endpoint & package inventory
AI agents, skills & MCP server inventory
Org-wide & cross-repository visibility
Findings history & retention 7 days 90 days 365 days
On-demand & agents
On-demand scans included / month 10 per endpoint Custom
Agent investigations included / month Custom
Overage rates $0.50 / scan Custom
Governance & platform
Centralized policies
Audit history 90 days Custom
Reporting
Single Sign-On (SSO)
Role based access control (RBAC)
MDM rollout
Enterprise integrations (SIEM, EDR)
Support & compliance
Support Community Email Dedicated
SLA
SOC 2 & ISO 27001 reports On request
Data residency Scoped in contract
Add-on Threat Intel

Our malicious package intelligence, delivered as data you can build on: the feed behind SafeDep's verdicts, queryable and pushed into the tools your security team already runs. Attach it to any paid plan.

Malicious package feed

Continuous stream of confirmed malicious packages, campaigns and indicators across npm, PyPI, Go, Maven and more.

Data hub & API

Query history and evidence directly, or pull it through the developer API into your own pipelines and detections.

SecOps & agent integrations

Push indicators into SIEM, EDR and agent guardrails so the same intel drives detection and blocking.

The unit

What counts as an SDLC endpoint?

An SDLC endpoint is any point in your lifecycle where SafeDep is integrated. That means a developer machine, a CI environment, a repository, or an AI agent. Third-party code enters at each of these, and you pay for the ones you cover. One unit, so the bill stays predictable however you deploy.

Developer machine

A laptop running pmg, blocking malicious installs before they execute.

= 1 endpoint
CI environment

A pipeline scanning dependencies on every build.

= 1 endpoint
Repository

A repo with continuous pull request scanning enabled.

= 1 endpoint
AI agent

A coding agent whose installs and tool calls you protect and observe.

= 1 endpoint

What's included, always

Protection is never metered. Scanning packages, blocking malicious installs, PR scans and inventory across your endpoints are all included, however much your team ships.

Real-time malicious package verdicts
Unlimited
Continuous PR & CI scanning
Unlimited
Inventory & findings
Unlimited

Only if you go beyond

Ad-hoc scans come with a monthly allowance that grows with your endpoints. You'll only see a usage charge for heavy, elective work, and we tell you before you get there.

Extra on-demand scan
$0.50 each

Pricing FAQs

Your endpoint count is always a unique count, and you can control how it's grouped. If you have queries about our pricing options, you're in the right place.

Our CI runs on ephemeral runners. Does every build count as a new endpoint?

No. SafeDep identifies each endpoint on a best-effort basis using a stable fingerprint, so the hundreds of throwaway VMs a hosted runner provisions resolve to one CI environment. Your endpoint count is always the unique count, and operators can override the endpoint identifier to group them exactly as you want.

What about AI agents running in the cloud?

The same way. Cloud-hosted and ephemeral agents are fingerprinted and de-duplicated, so a fleet that scales up and down through the day does not inflate your count. As with CI, operators can override the identifier to control how agents are grouped.

Does a large monorepo count as one endpoint?

Yes. One repository is one endpoint, regardless of its size or how many services live inside it.

What happens if my endpoint count changes mid-cycle?

Your count adjusts as you add or remove endpoints, and we prorate the difference. Endpoints that stop reporting drop out, so you're billed for what you're actually protecting, not what you once registered.

Do I need a credit card to start?

No. The 30-day trial needs only basic details and no card. You enter payment only when you decide to subscribe.

What happens when my 30-day trial ends?

You move to the Free plan automatically, so nothing is deleted and nothing breaks. You keep real-time protection on up to 3 endpoints. Org-wide features and extended history pause until you subscribe. We tell you what changes before the trial ends.

Will I ever get a surprise bill?

No. Protection is never metered. Verdicts, PR scans and inventory are unlimited across every endpoint you pay for. On-demand scans come with a monthly allowance that grows with your endpoint count, and we alert you well before you approach it.

Are the open source tools still free?

Permanently. vet, pmg and gryph are open source and free to use standalone with no account, no subscription and no endpoint counted. SafeDep Cloud is the commercial platform that adds centralized policy, org-wide visibility, history and support on top.

How is this different from our EDR / endpoint protection?

They solve different problems. Your EDR watches what processes do once they're running. SafeDep checks what your developers and agents pull in, meaning the packages, extensions and components entering your SDLC, before they ever execute. Most teams run both, and SafeDep coexists with EDR/XDR on the same machine.

We need SSO, an SLA, or specific data residency.

That's the Enterprise plan. SSO and role-based access control, MDM rollout, registry-level enforcement, custom retention, and SIEM/EDR integrations are all available. Data residency requirements, including EU, are scoped as part of an enterprise agreement.

What is the Threat Intel add-on?

It's the intelligence behind SafeDep's verdicts, delivered as data: a continuous malicious package feed, a queryable data hub, API access, and indicator push into SIEM, EDR and agent guardrails. Attach it to Team or Enterprise. Protection itself doesn't need it.

How is the Threat Intel add-on billed?

As a separate monthly line on the same invoice as your plan, added or removed at any time with proration. It is included for the length of your 30-day trial so you can evaluate the feed before committing.

Can I switch between plans?

Any time, in-product. Upgrades apply immediately and we prorate the difference; downgrades take effect at the end of your current cycle, with nothing deleted in between.

What payment methods do you accept?

All major credit and debit cards for self-serve subscriptions. Enterprise agreements can be invoiced annually by bank transfer, with purchase order and procurement paperwork supported.

ISO 27001 certified
SOC 2
No card for trial
Cancel anytime
No surprise bills
Background
SafeDep Logo

Ship Code.

Not Malware.

Start a 30-day trial with no credit card. Stay on Free when it ends, or scale to org-wide protection.