feature 2 min read · 6 sections

Self-serve billing

Paddle-backed checkout. Subscribe, upgrade, and manage your plan from workspace settings.

Last updated September 4, 2026

What it is

Paddle-backed billing for workspaces: a monthly or annual subscription, all self-serve in the dashboard. No “talk to sales” gate for upgrades. Enterprise is contracted directly; everything below that lights up on a card.

What you get

For every workspace:

  • An active plan (free / starter / essential / standard / scale / enterprise) with its asset cap, seat cap and included features
  • A monthly allowance of Audits and Checks — the two counted units
  • An invoice history with downloadable PDFs
  • A subscription portal: cancel, change plan, update payment method

The two units

  • Audit — one complete Deep Audit of one application, including up to ten related backends. One Audit per scan, whatever the size of the application. There is no per-backend surcharge.
  • Check — one AI verification: the Exploit button, or a CVE validation.

Both reset at the close of each billing month and do not roll over. The app shows the reset date. Re-testing a finding Umbra already reported to you is free and never counted — charging you to confirm your own fix would be a strange way to encourage fixing.

If a scan fails before producing anything, the Audit is returned automatically.

What is never metered

Monitoring, discovery, scan cadence, reports, PDF exports, translations, integrations and API access. Set whatever scan interval you like. You are not billed per scan, per port, per host or per finding.

Why it matters

The buying motion for security tooling has shifted. Teams expect to try the product without a demo call, expand on a credit card, and only talk to sales for compliance or volume. That works from signup through to Scale without a hand-off.

How to use it

  • Settings → Plan to upgrade, downgrade or cancel.
  • Settings → Billing for payment method and invoices.
  • Plan changes apply at the next billing cycle — immediate prorate for upgrades, end-of-cycle for downgrades.

If you run out of Audits or Checks before the reset date, moving up a plan raises the allowance immediately.

See Pricing for the current plan matrix.

What next
Module access & entitlements →

Two layers of module gating: per-org bundle entitlement (what the plan sells) and per-user module grants (an org-admin restricts a teammate to specific modules). Allow-by-default, dependency-closed, server-enforced, fails closed.