CidraOpen the platform

Pricing

Priced per application, not per component.

A complete bill of materials should never cost you more than an incomplete one.

Free

NO CARD

Enough to find out whether your estate has a problem.

€0
one application
Start scanning
  • One application, unlimited scans
  • CSV, XLSX, CycloneDX and SPDX upload
  • OSV matching with KEV and EPSS enrichment
  • KEV, EPSS and SSVC prioritisation
  • Explainable priority derivation
  • Identity triage queue

Team

MOST CHOSEN

Continuous watch over a real estate, with the audit trail to prove it.

€180
per month, up to 25 applications
Start a trial
  • Everything in Free
  • Up to 25 applications
  • Daily KEV and EPSS refresh against your inventory
  • Reverse alerting: which of your components a new CVE affects
  • VEX statements and accepted-risk decisions
  • Tamper-evident audit log with chain verification
  • Jira, ServiceNow and Slack
  • Email support, one business day

Enterprise

SELF-HOSTED

For organisations that will not put unremediated criticals in shared infrastructure.

Custom
annual
Talk to us
  • Everything in Team
  • Unlimited applications
  • Self-hosted or single-tenant deployment
  • Dedicated vulnerability knowledge base
  • SSO, SCIM and audit log export
  • Data residency selection
  • CRA Article 14 reporting workflow
  • Named contact, four-hour response

Questions

Why per application rather than per component?

Because a single container image is three hundred components. Per-component pricing either produces an unaffordable bill or pushes customers to upload less than they run — and a vulnerability tool that rewards an incomplete inventory is working against its own purpose. An application is the unit you already reason about.

What counts as an application?

One inventory that you scan as a unit — a product, a service, or a defined estate such as a data centre's server build. Uploading the same application repeatedly is one application, not many.

Can I run Cidra on my own infrastructure?

Yes, on the Enterprise tier. It runs on a plain Linux host — Node, MongoDB, systemd, nginx, no containers required. Enterprise security buyers frequently refuse to put unremediated findings in multi-tenant infrastructure, and that is a reasonable position rather than an objection to overcome.