A flat monthly price with a monthly allowance of Audits and Checks. Two counted units, no per-scan billing, and re-testing a fix we already reported is always free.
Annual billing: twelve months for the price of ten. Switch to monthly any time.Monthly billing, cancel anytime. Annual saves two months.
All paid tiers include unlimited discovery, scheduled re-scans, 90-day data retention on cancellation, and no per-seat hidden fees. Scanning is never metered: set whatever cadence you like.
Your plan includes a set number of Audits and Checks every month. Monitoring, discovery, scan cadence, cloud posture, reports, exports, integrations and API access are never metered. If you run out, buy more or move up a plan; the page shows the date your allowance resets, so waiting is always an option.
Re-testing a finding we already reported is free and never spends a Check. Charging you to confirm your own fix would be a strange way to encourage fixing.
One complete Deep Audit of one application, whatever its size, with up to ten related backends included. No per-backend charge. A scan that fails before producing anything returns the Audit automatically.
One AI verification, whatever it took: proving a service is exploitable, or that a reported CVE is real on this exact target. Three verdicts, request and response attached.
An end-to-end web application audit. A 56-module scan finds what rules find, an AI Triager judges every finding live, and the AI Explorer hunts for what scanners can't see: IDOR, OAuth bypass, mass assignment, business-logic flaws. One Audit covers the application and up to ten related backends. The AI budget is shared across the whole mission, so extra backends split the same work rather than adding to it.
Read the full doc →Security questionnaires, DPA, subprocessors, a specific residency region, or an MSSP setup. Write to us and a person answers.
One tracked host (one IP). Discovery is unlimited and free. You only consume an asset slot when you explicitly tick a host to monitor on the Assets page. Untracked hosts stay discoverable and cost nothing.
Two things are counted: Audits and Checks. Your plan includes a set number of each every month, and re-testing a fix you have already had reported is always free. If you run out, buy more or move up a plan; the page tells you the date your allowance resets. Everything else is included and never metered.
One Audit, whatever the size of the application, covering the app and up to ten of the backends it talks to. Past ten the budget is spread too thin to test any of them properly, so the honest answer is a second Audit. If a scan fails before producing anything, the Audit is returned automatically.
Yes, from Billing in-app, no support email needed. Scans pause immediately; you keep read-only access for 90 days and can export findings as JSON or CSV. After 90 days the org's data is deletion-eligible, with emails at day 30 and day 75 first.
Yes, on every plan including Free. It is the default, not an upgrade. The platform runs in Helsinki, Finland and scan artifacts are stored in Stockholm, Sweden, both inside the EU. A specific country or a region outside the EU can be arranged by contract where supported.
No, and it's not on the roadmap. Umbra is SaaS-only: one install we maintain, predictable infrastructure, no per-customer support burden. If your security policy forbids sending external recon data off-prem, we're not the right fit.
No credit card · cancel anytime · EU data residency by default · SSO with Google and Microsoft on every plan · DPA available