Start free. Scale when you ship.
The in-browser tools and npm packages are free and open. A hosted API key unlocks the advanced engine (cross-tool & MCP rules); paid plans raise limits and add hosted AI. You only pay for hosted volume — not for the open engine.
Free
For trying the tools and small projects.
- All in-browser tools & npm packages (basic engine)
- Hosted advanced engine with an API key (cross-tool + MCP rules)
- 2,000 API requests / month
- 30 requests / minute per key
- Account-synced scan history
- Bring-your-own-key AI remediation
Pro
PopularFor teams shipping agents to production.
- Everything in Free
- 50,000 API requests / month
- 120 requests / minute per key
- Hosted AI remediation (no key to manage)
- Priority email support
Team
For organizations with higher volume and controls.
- Everything in Pro
- 250,000 API requests / month
- 300 requests / minute per key
- Team seats & SSO (planned)
- Custom rules & SLA (planned)
Paid plans aren't self-serve checkout yet — contact us and we'll set you up while we finish billing. Limits and quotas listed above are enforced today on API keys. Team seats, SSO, and custom rules are on the roadmap and labeled as planned.
What's free vs. paid
Free & open: every in-browser tool, the @opensecureai npm packages (scanner, firewall, agent-guard) with the basic engine, the CLI & GitHub Action, and the anonymous API (basic engine, IP rate-limited). No account required.
Hosted (account + API key): the advanced engine — cross-tool data-exfiltration chains, confused-deputy, MCP annotation-spoofing, tool-name shadowing, and attack-surface analysis — plus account-synced scan history. Free accounts get it at low volume; paid plans raise the limits.
Paid add-ons: hosted AI remediation without managing a provider key, higher monthly quotas and per-minute limits, and priority support. Your usage is visible on the dashboard.