Start for $0.99. Scale as you grow.
Real software supply chain security from $0.99/month — reachability analysis, autonomous remediation, SBOMs, and 500K+ zero-CVE components. Free for open source, nonprofits, students, and educators. Enterprise scoped to your environment.
Starter
For individuals putting a real scan in front of their code.
- 1 developer, 1 project
- Software composition analysis (SCA)
- SBOM generation (CycloneDX + SPDX)
- Reachability-based prioritization
- Griffin AI fix suggestions
- Community support
Pro
For individual developers who want fixes, not just alerts.
- Everything in Starter
- Unlimited projects
- Autonomous Auto-Fix pull requests
- All languages & ecosystems
- Container + IaC + secret scanning
- Email support
Team
For teams shipping — and securing — together.
- Everything in Pro
- Org dashboards & reporting
- RBAC + SSO
- Shared policies & policy gates
- SBOM/AIBOM management
- Priority support
Enterprise
For regulated and at-scale organizations.
- Everything in Team
- On-prem, air-gapped & sovereign deployment
- Compliance packs (SOC 2, FedRAMP, CRA, NIST)
- SSO / SCIM provisioning
- Dedicated technical account manager & SLAs
- Custom reasoning budget
All paid plans are month-to-month. Prices in USD. for annual, volume, or enterprise terms.
Security should reach everyone who builds.
Startups & bootstrapped
Free and heavily discounted licenses for early-stage, funded, and self-funded teams — because security shouldn't wait for a Series A.
Learn moreOpen source & nonprofits
Free licenses for maintainers of public open-source projects and for registered nonprofits and NGOs.
Learn moreStudents
Free for students — learn software supply chain security on real projects with the full platform.
Learn moreEducators
Free for teachers and classrooms — bring hands-on supply-chain security into your curriculum.
Learn moreSafeguard Academy
Free courses and verifiable certifications in software supply chain and AI security — for every Safeguard user.
Learn moreFrom zero to your first prioritized fix
No sales call to begin. Connect a repository and Safeguard runs a real scan — SBOM, reachability-based prioritization, and Griffin AI fix suggestions — on the Starter plan.
Start for $0.99Sign up in under a minute at app.safeguard.sh — no sales call required to get started.
Link a Git repo from GitHub, GitLab, Bitbucket, or Azure DevOps in a couple of clicks.
Safeguard generates an SBOM and runs SCA with reachability across your dependency tree.
See only the reachable, exploitable findings — each with a Griffin AI fix suggestion you can apply.
Four levers, no surprise line items.
Self-serve tiers are fixed and public. For Enterprise, we scope on these four levers — and walk through each on the call.
Reasoning budget
Which Griffin variants you call — Lite, S, M, L, or Zero — and how often. Inference cost dominates platform cost, not headcount.
Deployment isolation
Shared cloud, dedicated VPC, on-prem, or fully air-gapped. Isolation posture changes the architecture and the price.
Compliance scope
Which packs you switch on — SOC 2, ISO 27001, NIST, DORA, NIS2, FedRAMP, STQC — and the audit-evidence depth you need.
Environment shape
Repos, container registries, build systems, MCP servers, third-party vendors. The surface area we scan defines the workload.
From first call to first deployment.
A discovery call is free and non-binding. You leave with a clearer picture of fit — and, if you want one, a written proposal in under two weeks.
Discovery call
Twenty to thirty minutes. We learn your stack, your regulatory posture, and what success looks like for your team.
Technical scoping
Our solutions engineer walks through deployment shape, reasoning budget, and integration points with your team.
Tailored proposal
A written proposal scoped to your environment — line items you can defend, no surprise add-ons at renewal.
Pilot and rollout
Time-boxed pilot on a real repo or workload, then phased rollout with a dedicated technical account manager.
The questions everyone asks first.
How much does Safeguard cost?
Plans start at just $0.99/month for the Starter plan (one developer, one project). Pro is $12/month for individual developers who want unlimited projects and autonomous Auto-Fix. Team is $10 per user/month with a two-user minimum. Enterprise is custom-scoped. Open-source maintainers, nonprofits, students, and educators can qualify for free licenses.
What's in the $0.99 Starter plan and how do I use it?
For $0.99/month you connect one repository and get Safeguard's core engine: software composition analysis, an SBOM (CycloneDX/SPDX), reachability-based prioritization, and Griffin AI fix suggestions. Getting started takes minutes — create an account, connect a Git repo, run a scan, and review prioritized fixes. Upgrade to Pro or Team for autonomous auto-merge remediation and more projects.
What does the Team plan include and what's the minimum?
Team is $10 per user per month with a minimum of two users. It adds org dashboards, RBAC, SSO, shared policies and policy gates, and SBOM/AIBOM management on top of everything in Pro. It's the right fit once more than one person needs to see and act on findings.
Are there free plans for open source, students, or startups?
Yes. Public open-source maintainers and registered nonprofits/NGOs get free licenses. Students and educators get free access with verification. Startups and bootstrapped companies qualify for free or heavily discounted licenses. See the programs section above for how to apply.
How does Safeguard reduce false positives?
Reachability analysis. Safeguard maps whether vulnerable code is actually reachable and executed in your application, so it surfaces the exploitable issues instead of every CVE in your dependency tree. That's included from the $0.99 Starter plan up.
Can Safeguard fix vulnerabilities automatically?
Yes, on Pro and above. Griffin AI authors a fix as a pull request, runs it through your CI, and — once checks pass and you've opted in — can merge it without manual triage. Autonomous remediation is the core difference versus tools that only alert.
Why is Enterprise custom-priced?
Beyond the self-serve tiers, enterprise cost is dominated by reasoning budget, deployment isolation, and compliance scope — all scoped per customer. A thirty-minute call gives you a number you can defend internally, with no surprise line items.
Can I run air-gapped or sovereign?
Yes, on Enterprise. We support fully air-gapped, VPC-isolated, and sovereign-cluster deployments — including offline vulnerability-database sync, on-prem GPU sizing support, and customer-controlled key material.
What is Safeguard Academy?
Safeguard Academy is our free learning platform: courses and hands-on labs in software supply chain and AI security, with verifiable certifications you earn on the platform. It's free for every user — a great starting point for students, teams, and anyone new to the space.
Do you support procurement reviews and security questionnaires?
Yes. We carry SOC 2, security documentation, and DPAs ready to share under NDA, and we respond to standard procurement questionnaires as part of the proposal stage.
Start for $0.99, or talk to us about scale.
Connect a repo in minutes on a self-serve plan — or tell us about your stack and regulatory posture and we'll scope an enterprise deployment.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.