Plans and limits
These are repository defaults. Active catalog settings determine feature availability; project, monitor, and asset counts are backend plan quotas. Feature toggles do not change those counts. API-key quota settings can override defaults.
| Limit | Free | Teams | Enterprise |
|---|---|---|---|
| Active API keys | 5 | 10 | 25 |
| Projects | 3 | 100 | 100 |
| Monitors | 3 | 25 | 100 |
| Assets | 0 | 20 | 200 |
| API requests/second | 5 | 50 | 1,000 |
| Concurrent API requests | 10 | 50 | 500 |
API-key creation also has a five-per-minute rate limit. API token buckets allow a bounded two-times burst; sustained traffic must remain within the limit.
Feature availability
Free includes lookup, projects, and monitors. Teams enables additional detection, asset, and Slack capabilities. Rules/conversion/YARA MCP tools require Teams or Enterprise. Providers still need applicable configured credentials.
Dashboard, billing, key management, BYOK, notifications, and Settings are account surfaces. A plan flag for a future feature does not implement that feature.
Deployment and enterprise scope
OAuth requires provider configuration; SAML/SCIM scaffolds do not establish completed enterprise SSO. Native Microsoft Teams alerts, white-label tenant APIs, AI endpoints, automatic retention, and packaged OEM workflows are not established shipped capabilities. Uptime, residency, and support guarantees must be confirmed through your contract and deployment.
See credits for grant and charge behavior.