Pricing
Real plans, enforced limits, no published prices
The three tiers below are the ones TRUSTIVAN actually enforces — the limits come from the entitlement tables, not from a designer's table. Free does not expire and there is no trial to run out. What is not on this page is a number: a plan's price lives in the payment provider's catalogue rather than in this database, and this service has not published one yet, so a plan is arranged by conversation.
Plans
Evaluation and small projects.
Free
Enough to run TRUSTIVAN against a handful of images and see whether the lifecycle and the audit trail earn their place. Public registries only; the policy engine and webhooks are not included. There is no time limit and no trial to expire — Free stays Free until you change plan.
Teams shipping containers continuously.
Pro
Adds what a release path needs: a policy engine that returns a recorded verdict, webhooks that publish state changes as they happen, and scanning of registries that require credentials.
Organizations with compliance, SSO and directory requirements.
Enterprise
Adds SAML and OIDC single sign-on and SCIM directory provisioning, so access is granted and revoked where your directory already says it should be. Invoiced by contract rather than bought from a page.
What each plan allows
The numbers the software enforces
These are not marketing tiers layered over an unmetered product. A scan that would exceed the asset ceiling or the monthly scan count is refused with an entitlement error, an invitation past the seat count is refused, and scans beyond the concurrent-scan limit wait in the queue. The values below are the ones the entitlement tables are seeded with.
| Limit | Free | Pro | Enterprise |
|---|---|---|---|
| Container images tracked | 5 | 100 | Unlimited |
| Scans per month | 50 | 2,000 | Unlimited |
| Minimum rescan interval | Daily | Hourly | Hourly |
| Seats (members and pending invitations) | 3 | 25 | Unlimited |
| API keys | 1 | 10 | Unlimited |
| Webhook endpoints | None | 5 | Unlimited |
| Policies | 1 | 10 | Unlimited |
| Concurrent scans, at most | 1 | 5 | 20 |
| Finding history retained | 30 days | 1 year | 2 years |
| Usage and metering history retained | 30 days | 1 year | 2 years |
| Agents and other non-human identities | 2 | 20 | Unlimited |
| Vulnerability scanning | Included | Included | Included |
| Finding lifecycle and suppression | Included | Included | Included |
| Scheduled rescans | Included | Included | Included |
| Machine API and API keys | Included | Included | Included |
| Private registry scanning | — | Included | Included |
| Policy engine and recorded verdicts | — | Included | Included |
| Webhooks | — | Included | Included |
| SAML and OIDC single sign-on | — | — | Included |
| SCIM directory provisioning | — | — | Included |
| SBOM export and import (CycloneDX, SPDX) | Included | Included | Included |
| Licence inventory | Included | Included | Included |
| Compliance evidence mapping | Included | Included | Included |
| Audit trail export | — | — | Included |
| NHI Security: non-human identity inventory and risk | Included | Included | Included |
A seat is a member or an invitation that has not been accepted yet, so withdrawing an unused invitation frees one. Concurrent scans is a ceiling, not a reservation: how many scans run at once is also bounded by the scan workers your deployment runs, which every organisation shares. An agent counts against the ceiling for as long as it is delegated; revoking one frees it immediately, the same as a seat.
Scanning itself is never gated on billing. If the entitlement layer is misconfigured or absent, a scan runs rather than being refused — a vulnerability scanner stopped by a billing bug is a worse outcome for a customer than an unmetered one.
Why there are no prices
The price lives at the payment provider, not in this page
TRUSTIVAN has plans, enforces them, and — with a payment provider configured — sells them: a hosted checkout, a customer portal for the payment method and invoices, and subscription webhooks whose signature is verified before anything is believed. What it does not have is a published price, because no price has been set up in a provider catalogue for this service yet.
Printing a monthly figure that no configured price backs would be the one thing an evaluator checks first and the cheapest possible way to lose them. A price also has currency, tax, region and effective dates, all of which a billing system models properly and this page would model badly — so when a price exists it will come from the provider rather than from a number typed here. What a plan includes will still be whatever the entitlement tables say, because that is the copy that cannot drift from the product.
A self-hosted installation and an enterprise invoiced by contract both run with no payment provider at all, permanently. That is a supported configuration rather than a degraded one: the plan is assigned by agreement, the limits are enforced exactly the same way, and nothing in the product can charge you.
TRUSTIVAN is self-hosted today, so your findings and your decision record stay in your own PostgreSQL instance on every plan. See what we can and cannot claim about assurances before you commit to an evaluation.