Offer now: 50% off your base fee for 3 months + €100 usage credit.Start trialSee what’s new

Pay for what you use.

From €99 a month. Your price is set by whichever you use most: active users, packages scanned, or downloads served.

Set each meter to your estimated usage. Whichever is highest sets your price.

10

sets your price

5,000

included, covered up to 5,000

250,000

included, covered up to 250,000

Add-ons

€99

€49.50

10 users · 5,000 packages · 250,000 downloads

Priced on active users, the meter you use most. The other two are included up to the same size.

Base covers 10 users, 5,000 packages, 250,000 downloads€99
Early access, 50% off base fee (3 months)-€49.50
Monthly total€49.50

Early access also includes a one-time €100 usage credit, on top of the discount above.

You are priced on the resource you use most

A hundred developers on a small codebase, or ten developers running CI around the clock.
We measure and charge fairly either way.

Active users

People and services with a valid access token, or who signed in to the dashboard. CI runners count the same as developers. Dormant accounts cost nothing.

10 to 500

Packages scanned

Distinct package versions we checked for you in the last 30 days, across every ecosystem, including the internal packages you publish through the firewall.

5,000 to 50,000

Downloads served

Artifacts delivered to developer machines, CI jobs and downstream mirrors. Metadata and version lookups are not counted.

250,000 to 125M

Two ways to run it

Recommended

Cloud

Self-serve, priced on whichever meter you use most.

from€99€49.50/ month

Early access: 50% off the base fee for 3 months + €100 usage credit.

Included

  • Priced on one meter: active users, packages scanned or downloads served
  • Starts at 10 users, 5,000 packages and 250,000 downloads
  • Scales to 500 users, 50,000 packages and 125M downloads
  • All supported package ecosystems
  • Vulnerability and malware blocking
  • Maturity delay for newly published versions
  • License policy enforcement and dependency confusion prevention
  • Audit logs, standard retention and standard support
  • 3 namespaces
  • EU data residency

Add-ons: SSO/OIDC €129, Container image firewall €99, Deep Scan €99 per month.

The price per unit falls as you grow, whichever meter you grow on.

Enterprise

Custom deployment, support and commercial terms.

Custom

Everything in Cloud, plus:

  • More than 500 active users
  • Unlimited namespaces
  • SIEM export
  • SSO/OIDC scoped into the contract
  • Extended log retention
  • Managed Cloud, BYO Cloud or On-Premise deployment
  • SLA and premium support
  • Custom procurement and commercial terms

Usage limits are agreed in the contract rather than metered against the published ranges.

Compare Cloud and Enterprise

Compare where each plan runs, how far the meters reach, and which controls and support terms are available.

Deployment and environment
Cloud
Enterprise
Deployment option
SaaS only
Managed Cloud, BYO Cloud or On-Premise
Data residency and hosting
EU-hosted
EU, private cloud or customer environment
Pricing model
Priced on your largest meter, from €99 / month
Agreed in the contract
Active users
10 to 500
Above 500
Packages scanned
5,000 to 50,000
Agreed in the contract
Downloads served
250,000 to 125M
Agreed in the contract
Namespaces
3
Unlimited
Identity, access and coverage
Cloud
Enterprise
User sign-in
Google, Microsoft and GitHub
Scoped to contract
SSO/OIDC
Add-on, €129 / month
Scoped to contract
Role-based access control
Included
Scoped to access model
Audit export
Audit logs included
SIEM export as needed
Log retention
Standard retention
Extended retention
Container image firewall
Add-on, €99 / month
Scoped to contract
Deep Scan
Add-on, €99 / month
Scoped to contract
Support and commercial terms
Cloud
Enterprise
Support level
Standard support
Premium support
SLA
Not included
Scoped to contract
Commercial terms
Standard monthly pricing
Custom contract and deployment terms

Frequently asked questions

What sets our price?
Whichever of the three meters you use most: active users, packages scanned, or downloads served. Each one implies a plan size. You pay for the largest, and the other two are included up to that same size at no extra cost. Most teams are priced on one meter and never think about the other two.
Why not charge for all three?
That would bill you three times for one team. The three meters measure the same organization from different angles: a team with many developers usually pulls a lot of packages. Charging for the largest is the honest way to read that.
What counts as an active user?
Anyone holding one or more valid access tokens, or who has signed in to the dashboard. We also count service tokens: a CI runner, a release pipeline or a build agent holding its own token counts the same as a developer, because it puts the same kind of load through the firewall. We count all of it for you. There is no license list to maintain, and people who leave or tokens you revoke stop counting on their own.
What counts as a package scanned?
One distinct package at one distinct version, in one ecosystem, seen in the last 30 days, including the internal packages you publish through the firewall. Ten thousand installs of the same version is one package. A version drops out of the count 30 days after it was last seen.
How do you count downloads?
Every artifact served through the firewall to a developer machine, a CI job or a downstream mirror, over the last 30 days. Metadata responses and version lookups are not counted, only the packages you actually pull.
What if one month is unusually heavy?
Nothing blocks and nothing throttles. The base fee and any add-ons are billed in advance each month. Usage above the starting allowance is billed in arrears on the next invoice, at the published rates, with no commitment and no headroom to buy up front. Downgrades work the same way, with nothing to cancel.
Which meter drives most customers?
Active users, for teams whose developers each pull a normal amount. Downloads, for teams running heavy CI against a modest codebase. Packages scanned rarely drives on its own, because the set of packages an organization touches converges, however large the organization gets.
Is there a trial?
Yes. A 14-day trial with the full capability set, no card required to start. There is no permanently free tier. Book a demo if you would rather scope a proof of concept against your own ecosystems and pipeline setup first.
What is included in Cloud?
Every rule type, at every plan size: vulnerability and malware blocking, maturity delay, license policy, dependency confusion prevention, audit logs and role-based access control. All supported ecosystems, EU data residency, standard support and login with Google, Microsoft or GitHub are included. What changes with your size is how much you can put through the firewall, never what it is allowed to block.
When is Enterprise the right fit?
When you pass the top of any meter (500 active users, 50,000 packages scanned or 125M downloads served), or when you need SIEM export, an SLA, extended retention, data residency, on-premise or BYO cloud deployment, unlimited namespaces, or procurement terms of your own.
Which package ecosystems are supported?
Dependency Firewall supports npm, Maven, PyPI, NuGet, Go, Composer, Cargo, RubyGems, Conda and OCI, all included on both Cloud and Enterprise. See docs.bytesafe.dev/firewall/ecosystems for current status and coverage per ecosystem. Container image firewall is available as a Cloud add-on and is scoped separately on Enterprise.
Can we deploy on-premise or in our own cloud?
Yes. Managed Cloud, BYO Cloud and On-Premise deployment options are available on Enterprise. Cloud is SaaS only.
Is SSO/OIDC included?
Cloud and Enterprise both include Google, Microsoft and GitHub login. For centralized user management and connecting your own identity provider, SSO/OIDC is a Cloud add-on at €129 / month, and is scoped into Enterprise when needed.
How does the firewall fit with our existing registries?
Dependency Firewall sits in front of your existing package registries. No migration needed. It works with standard package managers including npm, bun, yarn, mvn, pip and nuget. Redirect your package manager config to the firewall endpoint and your upstream registries stay unchanged.

See it in your environment

Start a trial in a few minutes, or we will walk through your setup in half an hour.