Pay per enabled scope: a subscription, account, project, or cluster. No per-resource charges, ever, and the meter never asks which cloud a scope is on.
Team is billed annually at $79 per enabled scope per month; $99 month-to-month. Prices in USD.
Self-hosted: you run it in your own cluster. One AWS account and one GCP project per install today; Azure subscriptions and Kubernetes clusters are not limited this way.
A scope is one thing you point Cloudkeel-DD at: an Azure subscription, an AWS account, a GCP project, or a Kubernetes cluster. You pay per enabled scope, not per resource inside it. A subscription with 5 resources and one with 5,000 cost the same.
No per-resource charges, ever. Scanning more infrastructure inside a scope never changes your bill. The meter is enabled scopes, full stop, and it never asks which cloud a scope is on.
Free is $0 and does not expire. It is the same build as every other tier (one image, one chart) with a limit of one enabled scope and three users, and every feature present. A new install starts with 30 days unmetered so you can see the whole product, and when that ends it settles onto Free rather than stopping.
The install keeps scanning within the Free limits. Nothing is deleted: your findings, history, connected sources and logins all keep working, and any scan already running finishes. Scopes beyond the limit stop getting new scans and say so on their own row, so it is visible rather than silent. Enable a licence key or free up a scope and they start again.
One AWS account and one GCP project per install today. There is no AssumeRole across accounts and no multi-project GCP yet, so a second account or project means a second install. Azure subscriptions and Kubernetes clusters are not limited this way. We would rather say this here than have you find it during a rollout.
Yes. Cloudkeel-DD runs entirely inside your own cluster from public images and a public Helm chart. Your cloud credentials stay in your environment and there is no SaaS backend holding your keys: we operate no endpoints, so there is no telemetry, no analytics and no licence server. A licence key is checked by verifying its signature against a key compiled into the image, so it works air-gapped and nothing phones home. To be precise about findings: they live in your database, and the only paths that carry them outward are ones you configure yourself: a notification webhook, or a GitHub or GitLab remediation pull request.
On the roadmap, not shipped. Today authentication is email/password with per-tenant role-based access control (owner / admin / viewer). We won’t list SSO as available until it actually is.
Yes, and you never have to talk to us. The install is public: run a scan against your own infrastructure and see real findings first. If you would rather not do the install and the tuning yourself, the Drift Audit is a separate paid engagement: fixed price, five business days, and you keep the install and a written report at the end.