Start with Free. Evaluate evidence and workflow tiers.
Local discovery, proposal preview, and CI gating are available without a paid licence in the current Free product. Tier A adds evidence for auditors; Tier B adds fleet operations and enterprise integrations. Public prices are planning anchors, while paid evaluation, activation, and self-service checkout remain closed during the source preview.
Developer source preview is request-only
Public native downloads and paid self-service checkout remain closed until release promotion. The Free developer preview builds a reviewed, history-free source archive locally. Tier A and Tier B are shown for future planning only; paid evaluation and activation are not available in the current Preview.
Prices below are indicative annual commercial pilot pricing; self-service checkout closed.
Free Discovery
Find and triage post-quantum risk locally, with no licence required.
- Broad multi-language source, dependency, IaC & committed-key scanning
- Readiness grade with text, JSON & SARIF 2.1.0 output
- Severity, git-diff & CI fail gates (
--fail-on) - Remediation preview (
fix --dry-run) - Verification, demo & local administration commands
Standalone Auditor
Machine-readable CBOM generation and attestable HTML reports for auditors.
- Compliance profiles: cnsa-2.0, fips-140-3, nist-sp-800-56b (
--target) - CycloneDX 1.6 CBOM, SPDX 2.3 & OpenVEX export
- HTML report with detached Ed25519 attestation (
report --attest) - Auditor bundle with integrity manifest
- Air-gapped vault (AES-256-GCM, offline verified)
DevSecOps Enterprise
Up to 30 Contributing Developers
- Everything in Standalone Auditor
- PR bots for GitHub, GitLab, Azure DevOps & Bitbucket Cloud
- Jira, Slack, OTLP & Dependency-Track delivery
- Beta self-hosted fleet server on macOS/Linux, plus sync, Prometheus metrics & badges
Proposal preview is Free. Tier A provides readiness evidence. Tier B includes Tier A and adds integrations and fleet operations. Growth and Scale differ only by seats within Tier B.
Your source never leaves your machine
Scans run locally: we never see or host your source code. The CLI sends anonymous aggregate telemetry (counts and durations only — no file names, no code snippets). Opt out any time with --no-telemetry, CIPHERMAP_NO_TELEMETRY=true, or run fully offline with --offline.
Compare Plans & Feature Matrix
Tier A provides readiness evidence with audit artifacts. Tier B includes Tier A and adds integrations and fleet operations. Planned source-changing capabilities are labeled unavailable rather than shown as unlocked.
| Feature | Free Discovery | Standalone Auditor ($4,999/yr) | DevSecOps Enterprise ($24,999–$49,999/yr) |
|---|---|---|---|
| Local scanning across all supported languages | Included | Included | Included |
| Text, JSON & SARIF 2.1.0 output | Included | Included | Included |
| Severity filtering, diff scanning & CI fail gate | Included | Included | Included |
| Basic CI templates & local pre-commit hook | Included | Included | Included |
| Remediation preview (ciphermap fix --dry-run) | Included | Included | Included |
| Bundle/vault verification, demo & local diagnostics | Included | Included | Included |
| CNSA 2.0, FIPS 140-3 & NIST SP 800-56B detection profiles | Not included | Included | Included |
| CycloneDX 1.6 CBOM, SPDX 2.3 & OpenVEX | Not included | Included | Included |
| Executive and technical reports with Ed25519 attestation | Not included | Included | Included |
| Auditor bundle with integrity manifest | Not included | Included | Included |
| Encrypted air-gap export and import | Not included | Included | Included |
| Source-changing remediation publication (planned)planned Go, Python and Node ESM proposal review is available, but production source publication is disabled until the isolated Gate 2 transaction and recovery evidence are promoted. | Not included | Not included | Planned — unavailable |
| TUI and LSP source-changing actions (planned)planned TUI and LSP inspection remain read-only; source-changing actions are planned and are not unlocked by a Tier B licence in this release. | Not included | Not included | Planned — unavailable |
| GitHub, GitLab, Azure DevOps & Bitbucket PR botscontract-tested Deterministic local provider contracts pass; disposable live-service validation is still pending and is not claimed. | Not included | Not included | Included |
| Jira, Slack, OTLP & Dependency-Track deliverycontract-tested Deterministic local provider contracts pass; disposable live-service validation is still pending and is not claimed. | Not included | Not included | Included |
| Self-hosted fleet server, sync, metrics & badgesbeta The packaged single-process fleet server is beta on macOS and Linux only; Windows remains unavailable until native console-control shutdown and restart are proven. Fleet synchronization targets the local single-process server and does not imply CipherMap's future multi-tenant HA control plane. | Not included | Not included | Included |
| Seats | Unlicensed | Single auditor seat | 30 (Growth) / 100 (Scale) |
Frequently Asked Questions
How do pricing and procurement work during the Preview?
The annual amounts are transparent planning anchors, not an active order form or binding quote. Paid evaluation and checkout remain closed. A fit discussion can inform future planning but does not create an order or activate a licence.
How does offline license activation work on air-gapped networks?
License keys are validated 100% offline: the binary verifies an Ed25519 signature with an embedded public key, with expiry and clock-rewind checks (ciphermap auth). No network phone-home or internet connection is required.
How should we think about team size?
Growth and Scale are 30- and 100-contributor planning bands for the same Tier B capability set. Custom sizing, billing changes, and procurement mechanics remain subject to a future commercial agreement.
What can we validate before a commercial decision?
Approved users can run a bounded Free validation locally and inspect clearly labeled sample evidence on this site. Paid Tier A and Tier B activation stays disabled in the normal source build. Review the technical evaluation path before discussing a future commercial scope.