Free while we ship.
Paid as capacity opens.
One domain, three scans a day, three watchers, drafted remediations, public trust page. Hard limits enforced at the API. No card.
Start free.
One domain, today.
Free Beta is the live product. Continuous detection, drafted remediations, and a public trust page on every verified domain. Limits below are real and enforced.
- 2 verified domains per account
- 7 deep scans per day
- Up to 5 active watchers
- Cora drafted remediations (approval first)
- Weekly briefing email
- Public trust page included
- Slack and email alerts
- Fair use abuse controls (auto pause on flood)
Limits are enforced at the API layer. Hitting a limit returns a clear 429 with the reset window. Existing Free Beta accounts keep working when paid plans go live.
Paid plans, queued.
The four tiers below activate as Free Beta capacity fills. Join a waitlist to lock in the listed price for the first billing cycle.
Single domain on a paid lane. Higher scan ceiling, longer audit retention, and a card on file for continuity.
- 1 production domain on dedicated capacity
- Unlimited daily scans
- 7 day audit log retention
- Cora drafted fixes, approval first
- Slack + email alerts + public trust page
- Priority response under 24 hours
Lean security teams. Up to 5 domains, full Cora autopilot for vetted fix types, audit log retention extended.
- Up to 5 production domains
- Cora autopilot (auto apply with revert)
- Custom WAF rules via DefenderShield
- Vendor incident correlation
- Inbound mailbox for security tickets
- Compliance binders (PCI / SOC 2 / ISO 27001)
- 90 day audit log retention
- Priority response under 4 hours
Multi domain estates and parent / subsidiary structures. Role based access, segregated audit trails.
- Up to 25 production domains
- Multi tenant workspace
- Role based access control
- SSO via SAML or OIDC
- Segregated audit log per tenant
- Dedicated incident channel
- 365 day audit log retention
Regulated and financial estates. Custom data residency, contractual SLAs, dedicated solution engineer.
- Unlimited production domains
- Data residency: AU, US, EU
- Contractual uptime SLA
- Named solution engineer
- Custom retention and BYOK
- Quarterly executive briefings
- Annual penetration test review
What changes as the plan ladder climbs.
Free Beta covers the live product. Paid tiers add capacity, autopilot, multi tenant, and contractual SLAs.
Questions answered before they land in support.
Run the live product. Free.
Verify a domain in 90 seconds. Cora drafts the first remediation before you finish reading the report.