Pricing for CVE, supply chain, and name integrity
Start free. Upgrade for higher call limits and continuous monitoring. Full response schema on every tier. No field gating.
Designed for evaluation and proof-of-concept projects.
- ▸1,000 API calls / month
- ▸60 calls / minute
- ▸1,023 CVE-covered products
- ▸29,270 PyPI + 311,756 npm packages monitored
- ▸Package name integrity (typosquat + AI-hallucinated names)
- ▸Full response schema incl. cve_ids
- ▸Python SDK
- ▸Community support
- ▸Direct use only
One developer: personal tools, local agents, and side projects.
- ▸Up to 10,000 API calls / month
- ▸No per-minute limit
- ▸No overage billing
- ▸1,023 CVE-covered products
- ▸29,270 PyPI + 311,756 npm packages monitored
- ▸Package name integrity (typosquat + AI-hallucinated names)
- ▸Full response schema incl. cve_ids
- ▸Python SDK
- ▸Email support
- ▸Direct use only
Embed Attestd in an agent or platform product. Self-serve at the published cap.
- ▸Up to 100,000 API calls / month
- ▸No per-minute limit
- ▸Supply chain compromise webhooks
- ▸Scoped API keys
- ▸Weekly digest (coming soon)
- ▸1,023 CVE-covered products
- ▸29,270 PyPI + 311,756 npm packages monitored
- ▸Package name integrity (typosquat + AI-hallucinated names)
- ▸Full response schema incl. cve_ids
- ▸Priority support
- ▸Embed results in your product
Negotiated volume, SLA, custom coverage, and distribution terms.
- ▸Resale, white-label, or distribution rights
- ▸Software-integrity signal without building your own stack
- ▸Custom commercial terms
- ▸Invoicing and SLA by arrangement
- ▸Unlimited volume under contract
- ▸Signed renewal conversation
- ▸1,023 CVE-covered products
- ▸29,270 PyPI + 311,756 npm packages monitored
- ▸Package name integrity (typosquat + AI-hallucinated names)
- ▸Full response schema incl. cve_ids
- ▸Priority support
Need an SLA, custom coverage, or invoicing? Contact us on Platform.
Contact us
You already secure agent behaviour. We give you the software-integrity signal without you building vulnerability normalisation, supply-chain monitoring, and package-name integrity.
Custom commercial terms, invoicing, and SLA by arrangement. Platform Starter covers self-serve embedding at the published cap. Contact us when you need negotiated volume, an SLA, custom coverage, or distribution rights.
Frequently asked questions
Does every tier include package name integrity?
Yes. typosquat detection for classic misspellings and AI-hallucinated package names is included on Free, Solo, Platform Starter, and Platform. No field gating.
What counts as an API call?
Each request to GET /v1/check counts as one call, regardless of the response (supported or unsupported product). POST /v1/check/batch counts one call per item in the batch. POST /v1/sbom counts one call per returned row, including outside_coverage. A 429 is returned before any items are billed if the request would exceed your quota.
Do unused calls roll over?
No. Included calls reset on your billing anniversary each month.
Can I change plans?
Yes. Upgrade or downgrade at any time via your billing portal. Tier changes take effect immediately.
What happens when I hit my limit?
Free tier: further calls return HTTP 429 until your period resets. Solo: returns HTTP 429 at 10,000 calls. Platform Starter: returns HTTP 429 at 100,000 calls. Platform: no cap under contract.
Will I get a warning before hitting my limit?
Yes. You will receive emails at 50% and 80% of your included calls for the month.
Is there a trial period?
The free tier is permanent. No time limit. You can evaluate the full response schema and integrate before upgrading.
Can I embed Attestd in my product?
Platform Starter includes the right to embed Attestd responses in your own product for your users. You may not resell raw API data, redistribute the dataset, or operate a white-label Attestd API. Free and Solo remain direct use only. Volume, SLA, custom coverage, or distribution terms are Platform.
What products are supported?
CVE coverage spans 1,023 infrastructure products across 13 documented categories (77 with full docs pages): databases (13), web servers & proxies (7), messaging & streaming (6), containers & orchestration (7), service mesh & networking (5), observability & monitoring (6), infrastructure & runtimes (7), security tooling (3), ci/cd platforms (4), javascript runtimes & sandboxes (4), authentication & identity (6), language runtimes (8), and ai tooling (1). Supply chain monitoring covers 29,270 PyPI and 311,756 npm packages on the watchlist. See the full CVE catalog or featured product docs.
Does supply chain monitoring cost extra?
No. Supply chain monitoring for PyPI and npm packages is included in all tiers at the same API call rate as CVE checks. Use the same API endpoint and authentication.
How do supply chain webhooks work?
Register an HTTPS endpoint in the portal on Platform Starter. Attestd sends a signed POST when a package on the watch list has a confirmed supply chain compromise. Deliveries retry up to 5 times over the next several minutes. See the webhooks docs for payload shape and signature verification.
How often is supply chain data updated?
Ingestion runs on a scheduled basis; the last_updated field in the response shows when monitoring last ran for that package. Registry and OSV sources are checked on each run.