// PRICING

Serious security without building a security department.

Every plan includes continuous analysis, prioritized findings, and remediation guidance. What changes is how much of your environment is covered, how often it is analyzed, and how much human verification is included.

NO SETUP FEES · CANCEL ANY TIME · READ-ONLY REPOSITORY ACCESS
Billing

Essential

A real security baseline for a single application.

$299 / month

Billed monthly

Start with an assessment

Best for teams of 3–8 developers shipping one product.

  • 1 application
  • 1 repository
  • Up to 5 developers
  • Weekly full analysis
  • Static analysis (SAST)
  • Dependency monitoring
  • Secret detection
  • API route inventory
  • Security dashboard & score
  • Email alerts
  • PDF security reports
  • 90-day finding history

Advanced

Continuous analysis with human verification where it counts.

from $1,499 / month

Billed monthly

Talk to security

Best for teams of 20+ developers, or anyone handling regulated or high-value data.

  • 10 applications
  • 25 repositories
  • Unlimited developers
  • Continuous change analysis
  • Everything in Growth
  • Full attack path analysis
  • Human verification: 10 findings per quarter
  • Executive & technical reporting
  • Custom assessment policies
  • Named security contact
  • Priority support (1 business day)
  • 2-year finding history

Beyond 10 applications, or specific contractual requirements?

Larger environments, custom data-retention terms, security questionnaires, and procurement review are handled directly. We will tell you honestly if Veyra is not the right fit for your stage.

Talk to security
// START HERE

Most companies start with an assessment.

A baseline assessment establishes what is actually exposed today, produces a formal report you can share with your board or your customers, and configures continuous monitoring. The full cost is credited toward your first three months if you subscribe within 30 days.

Focused

$750

≈5 business days

  • 1 application
  • 1 repository
  • Dependency, secret & static analysis
  • API route inventory
  • Technical report
Request Focused

Comprehensive

$2,500

≈10 business days

  • Up to 10 applications
  • Expanded repository coverage
  • Everything in Standard
  • Human verification of critical findings
  • Remediation working session
  • Re-test of critical fixes
Request Comprehensive

100% credited toward your subscription

Start any plan within 30 days of receiving your assessment report and the entire assessment fee is applied to your first three months. The assessment is designed to be the beginning of continuous coverage, not a one-off report that ages badly.

// COMPARE

What is included at each tier.

Feature comparison across Essential, Growth, and Advanced plans
Capability Essential Growth Advanced
Applications110
Repositories125
DevelopersUp to 5Unlimited
Analysis frequencyWeeklyContinuous
Static analysisIncludedIncluded
Dependency monitoringIncludedIncluded
Secret detectionIncludedIncluded
API route inventoryIncludedIncluded
API security analysisNot includedIncluded
Attack surface monitoringNot includedIncluded
Correlation & attack pathsNot includedFull
Remediation verificationIncludedIncluded
GitHub issue creationNot includedIncluded
Slack / Teams alertsNot includedIncluded
Human verificationNot included10 / quarter
Executive reportingNot includedIncluded
Custom assessment policiesNot includedIncluded
SupportEmailNamed contact, 1 business day
Finding history90 days2 years

Add-ons.

Priced so that growing past a plan boundary costs what it should, rather than forcing a jump to the next tier.

Add-onPriceWhat it covers
Additional application$99 / monthBeyond the applications included in your plan.
Additional repository$49 / monthBeyond the repositories included in your plan.
Human verification pack$750 one-timeManual verification of 5 high or critical findings by a security engineer.
Point-in-time assessmentfrom $1,500A scoped assessment and formal report, outside your normal cadence.
// FOUNDING PROGRAM

Founding pricing for the first ten companies.

Veyra is working with a limited group of growing software companies to refine continuous application security for teams without dedicated AppSec resources. Founding participants receive 50% off for twelve months, locked for as long as the subscription runs.

WHAT PARTICIPANTS GET

  • Initial security assessment at founding rates
  • 50% off any plan for twelve months
  • Direct access to the team building the platform
  • Early access to new capability
  • Genuine influence over the roadmap

No public testimonial is required, and participants are never described as customers unless they become customers.

Pricing questions

How do you count an application?
An application is one product your customers use, together with the API that serves it. A web app and its API are one application. A separate admin product with its own login is a second. If you are unsure how your environment maps to plan limits, tell us what you run and we will size it honestly rather than upsell you.
How do you count a repository?
One Git repository is one repository, regardless of size. A monorepo containing twelve services counts as one — Veyra maps the services inside it and correlates across them.
What happens if we exceed a limit?
Nothing breaks and nothing is silently billed. You will see a notice in the dashboard, and you can add capacity for $99 per application or $49 per repository per month, or move to the next tier if that works out cheaper.
Is there a free trial?
There is no self-serve free trial, because a meaningful result requires authorized access to real repositories and a real assessment run. The baseline assessment is the low-commitment starting point, and its cost is credited in full if you subscribe.
Can we cancel?
Monthly plans can be cancelled at any time and stop at the end of the current period. Annual plans run to the end of the term. On cancellation you can disconnect every repository immediately and request deletion of your data — see Customer Control.
Is Veyra a replacement for a penetration test?
No, and any vendor who tells you otherwise is selling. A penetration test is an adversarial human exercise at a point in time. Veyra is continuous automated analysis with human verification on high-severity findings. Many companies use Veyra continuously and a penetration test annually; Veyra typically means the pentest starts from a much cleaner baseline.
Will this help with SOC 2 or a customer security questionnaire?
It helps materially with the vulnerability-management and secure-development evidence those processes ask for, and the reports are built to be shared with auditors and prospects. Veyra is not a compliance-automation platform and does not issue certifications. We will tell you which questions it answers and which it does not.
Do you offer discounts?
Annual billing includes two months free. The Founding Program includes 50% off for twelve months for the first ten qualifying companies. There are no other discounts, and pricing is the same for everyone in the same situation.
How does billing work?
Card payments are processed by Stripe. Veyra does not store your card details. Annual plans can be invoiced where your procurement process requires it.

Start with what you are actually exposed to.

A baseline assessment takes about a week and tells you where you stand — before you commit to anything ongoing.

Assessment fees are credited in full toward your first three months.