pricing
Pricing for CVE, supply chain, and name integrity
Start free. Upgrade for higher call limits and continuous monitoring. Full response schema on every tier. No field gating.
For evaluation and low-volume use cases.
- ✓5,000 API calls / month
- ✓60 calls / minute
- ✓356 CVE-covered products
- ✓27,459 PyPI + 237,601 npm packages monitored
- ✓Package name integrity (typosquat + AI-hallucinated names)
- ✓Full response schema incl. cve_ids
- ✓Python SDK
- ✓Community support
- ✓Direct use only
Flat rate for individual direct use.
- ✓Up to 250,000 API calls / month
- ✓No per-minute limit
- ✓No overage billing
- ✓356 CVE-covered products
- ✓27,459 PyPI + 237,601 npm packages monitored
- ✓Package name integrity (typosquat + AI-hallucinated names)
- ✓Full response schema incl. cve_ids
- ✓Python SDK
- ✓Email support
- ✓Direct use only
Monitoring and assurance for direct org use.
- ✓Up to 2,000,000 API calls / month
- ✓No per-minute limit
- ✓Supply chain compromise webhooks
- ✓Scoped API keys
- ✓Weekly digest (coming soon)
- ✓356 CVE-covered products
- ✓27,459 PyPI + 237,601 npm packages monitored
- ✓Package name integrity (typosquat + AI-hallucinated names)
- ✓Full response schema incl. cve_ids
- ✓Priority support
- ✓Direct use only
For SaaS products embedding Attestd across their customer base.
- ✓Embed or resell in your product
- ✓Custom commercial terms
- ✓Invoicing and SLA by arrangement
- ✓Unlimited volume under contract
- ✓Signed renewal conversation
- ✓356 CVE-covered products
- ✓27,459 PyPI + 237,601 npm packages monitored
- ✓Package name integrity (typosquat + AI-hallucinated names)
- ✓Full response schema incl. cve_ids
- ✓Priority support
Need an SLA, custom coverage, or invoicing? Contact us on Platform.
Contact us
Custom commercial terms, invoicing, and SLA by arrangement.
Frequently asked questions
Does every tier include package name integrity?
Yes. typosquat detection for classic misspellings and AI-hallucinated package names is included on Free, Solo, Team, and Platform. No field gating.
What counts as an API call?
Each request to GET /v1/check counts as one call, regardless of the response (supported or unsupported product). POST /v1/check/batch counts one call per item in the batch. A 429 is returned before any items are billed if the batch would exceed your quota.
Do unused calls roll over?
No. Included calls reset on your billing anniversary each month.
Can I change plans?
Yes. Upgrade or downgrade at any time via your billing portal. Tier changes take effect immediately.
What happens when I hit my limit?
Free tier: further calls return HTTP 429 until your period resets. Solo: returns HTTP 429 at 250,000 calls. Team: returns HTTP 429 at 2,000,000 calls. Platform: no cap under contract.
Will I get a warning before hitting my limit?
Yes. You will receive emails at 50% and 80% of your included calls for the month.
Is there a trial period?
The free tier is permanent. No time limit. You can evaluate the full response schema and integrate before upgrading.
Can I embed Attestd in my product?
Embedding Attestd in a product you resell to your own customers requires a Platform arrangement. Solo and Team tiers are for direct use by the paying customer only. Contact us on the Platform tier.
What products are supported?
CVE coverage spans 356 infrastructure products across 13 documented categories (77 with full docs pages): databases (13), web servers & proxies (7), messaging & streaming (6), containers & orchestration (7), service mesh & networking (5), observability & monitoring (6), infrastructure & runtimes (7), security tooling (3), ci/cd platforms (4), javascript runtimes & sandboxes (4), authentication & identity (6), language runtimes (8), and ai tooling (1). Supply chain monitoring covers 27,459 PyPI and 237,601 npm packages on the watchlist. See the full CVE catalog or featured product docs.
Does supply chain monitoring cost extra?
No. Supply chain monitoring for PyPI and npm packages is included in all tiers at the same API call rate as CVE checks. Use the same API endpoint and authentication.
How do supply chain webhooks work?
Register an HTTPS endpoint in the portal on the Team plan. Attestd sends a signed POST when a package on the watch list has a confirmed supply chain compromise. Deliveries retry up to 5 times over the next several minutes. See the webhooks docs for payload shape and signature verification.
How often is supply chain data updated?
Ingestion runs on a scheduled basis; the last_updated field in the response shows when monitoring last ran for that package. Registry and OSV sources are checked on each run.
Ready to get started? A free key takes under a minute to set up.