Cloud security posture management,
priced without a sales gate.
Every Secorvia plan maps AWS, Azure, GCP and DigitalOcean onto the same security graph. What changes between them is how much you can connect and how deep the analysis goes — not whether you are allowed to see your own attack paths. Start on the free plan with no card, and move up when the limits tell you to.
Four plans
Monthly rates below are billed annually. Billing monthly instead costs $199 on Starter and $649 on Growth.
Free
$0 /month
1 account per provider
Solo builders getting first visibility into one cloud account. Three users, 25 container images scanned, one IaC project and 30-day audit log retention, with vulnerability intelligence and IaC security included.
Start free →Starter
$149 /month
3 accounts per provider
Small teams standing up their first real cloud security program. Adds the security graph, container and Kubernetes security, threat intelligence, compliance scoring and report generation, with 10 users and 90-day audit log retention.
Choose Starter →Growth
$499 /month
25 accounts per provider
Full platform access for teams scaling past a handful of accounts. Adds runtime security and CIEM, the executive dashboard and full API access, with 50 users, 5,000 container images and a one-year audit log.
Choose Growth →Enterprise
Custom
Unlimited scale
Unlimited users, accounts, clusters, container images, IaC projects and audit log retention, with dedicated support and contract terms built around your estate rather than a price list.
Contact sales →What each plan includes
Every capability below runs against the same graph. Higher plans do not analyse differently — they analyse more.
| Capability | Free | Starter | Growth | Enterprise |
|---|---|---|---|---|
| Price per month, billed annually | $0 | $149 | $499 | Custom |
| Cloud accounts per provider | 1 | 3 | 25 | Unlimited |
| Users | 3 | 10 | 50 | Unlimited |
| Container images scanned | 25 | 200 | 5,000 | Unlimited |
| IaC projects | 1 | 5 | 50 | Unlimited |
| Kubernetes clusters | No | 1 | 10 | Unlimited |
| Audit log retention | 30 days | 90 days | 1 year | Unlimited |
| Vulnerability intelligence & IaC security | Yes | Yes | Yes | Yes |
| Security graph & attack paths | No | Yes | Yes | Yes |
| Container & Kubernetes security | No | Yes | Yes | Yes |
| Threat intelligence & compliance scoring | No | Yes | Yes | Yes |
| Runtime security & CIEM | No | No | Yes | Yes |
| Executive dashboard & full API access | No | No | Yes | Yes |
| Dedicated support | No | No | No | Yes |
Choosing a plan
The useful question is not how many findings you want, but how much of your estate you need on one graph. A finding only becomes rankable once Secorvia can see what sits around it — the network path in, the identity that can assume a role, the data store at the end of the chain. That is why the limits are counted in connected accounts rather than in findings or scans.
Start on Free if you have one account you care about and want to see real posture findings from it. You get vulnerability intelligence and infrastructure-as-code scanning against your own environment, which is enough to judge whether the findings are the ones you would have wanted flagged.
Move to Starter when one account stops being the whole picture. This is where the security graph and attack path analysis begin, and they are the reason the ranking changes: a critical CVE on an isolated asset drops below a medium finding one hop from your customer database. If you are preparing for an audit, compliance scoring and report generation start here too.
Move to Growth when identity becomes the harder problem. Twenty-five accounts per provider is enough for most mid-size estates, and CIEM plus runtime security cover the two questions posture alone cannot answer — what permissions your identities actually hold, and what is happening on the host right now. Full API access lands here as well, which matters if findings have to reach your own ticketing.
Enterprise is for estates where any number is the wrong number. It removes the limits rather than raising them, and adds dedicated support and contract terms scoped to your environment.
Pricing questions
What counts as a cloud account?
One connected AWS account, Azure subscription, GCP project or DigitalOcean team. The limit is per provider, not shared across them, so a Starter plan can connect three AWS accounts and three Azure subscriptions at the same time.
What is the difference between monthly and annual billing?
The capabilities are identical; only the rate changes. Starter is $149 per month billed annually or $199 billed monthly, and Growth is $499 per month billed annually or $649 billed monthly. Annual billing is about a quarter cheaper on both plans.
Do I need a credit card to start?
No. The Free plan needs no card and no expiry date. It connects one account per provider and includes vulnerability intelligence and IaC security, which is enough to see real findings from your own environment before you decide anything.
Which plan includes the security graph and attack paths?
Starter and above. The Free plan covers posture findings, vulnerability intelligence and infrastructure-as-code scanning; the security graph, container and Kubernetes security, threat intelligence and compliance scoring begin at Starter. Runtime security, CIEM and full API access begin at Growth.
Are users or scanned resources charged separately?
No. Each plan is a flat rate with its own limits on users, connected accounts, container images, IaC projects and Kubernetes clusters. There is no per-seat or per-asset metering on top of the plan price.
How does Enterprise pricing work?
Enterprise removes every usage limit and adds dedicated support and custom contract terms, so it is quoted against the size and shape of your estate rather than listed. Contact sales and the scope is worked out with you.
Before you decide
The plan differences are really capability differences, and those are easier to judge by reading what the capabilities do than by reading a table. What CSPM covers and where it stops is the place to start if you are comparing categories rather than vendors. Why a CVSS score cannot prioritise cloud risk explains what the Starter tier's graph actually changes, and the over-permissioned identity problem does the same for Growth's CIEM.
If you would rather see the product, the quickstart guide walks through connecting an account and reading the first scan, and connecting cloud accounts covers the read-only roles each provider needs. Both work on the free plan.
Weighing Secorvia against what you do today? Secorvia vs. manual security audits and Secorvia vs. point-in-time scanners set out the differences directly.