Plans and limits

These are repository defaults. Active catalog settings determine feature availability; project, monitor, and asset counts are backend plan quotas. Feature toggles do not change those counts. API-key quota settings can override defaults.

LimitFreeTeamsEnterprise
Active API keys51025
Projects3100100
Monitors325100
Assets020200
API requests/second5501,000
Concurrent API requests1050500

API-key creation also has a five-per-minute rate limit. API token buckets allow a bounded two-times burst; sustained traffic must remain within the limit.

Feature availability

Free includes lookup, projects, and monitors. Teams enables additional detection, asset, and Slack capabilities. Rules/conversion/YARA MCP tools require Teams or Enterprise. Providers still need applicable configured credentials.

Dashboard, billing, key management, BYOK, notifications, and Settings are account surfaces. A plan flag for a future feature does not implement that feature.

Deployment and enterprise scope

OAuth requires provider configuration; SAML/SCIM scaffolds do not establish completed enterprise SSO. Native Microsoft Teams alerts, white-label tenant APIs, AI endpoints, automatic retention, and packaged OEM workflows are not established shipped capabilities. Uptime, residency, and support guarantees must be confirmed through your contract and deployment.

See credits for grant and charge behavior.