The CLI is free and open source forever. Pay only for the hosted dashboard — scan history, scheduled re-scans, alerts, compliance reports, and team features.
$19/mo
$99/mo
Includes the owner seat · +$15 per additional member
Custom
All plans include the full deterministic check library · Annual billing saves 2 months
SSO, SCIM, audit-log export, self-host/white-label, IP-based dashboard access, and data-region preferences are in private preview on Enterprise — contact us to enable them. "Data residency" is a stored region preference, not isolated infrastructure.
The CLI is free forever. Cloud is what you pay for — here is exactly what that means.
No. The keelix CLI is free, open source, and fully standalone — it runs every deterministic check locally, prints results, and exits. The Cloud dashboard is optional and only adds scan history, scheduled re-scans, alerts, compliance reports, and team features.
With the CLI alone: nothing — checks run locally. If you opt in to `keelix push` (or run the scan worker), only the structured findings (check IDs, severities, and the host label you choose) are sent to Cloud over your kx_ API key. The dashboard never asks for SSH access to your hosts.
No. Keelix evaluates your compose configuration where it runs and uploads only the resulting findings. Your compose file content is not transmitted to or stored by Cloud.
No. Scoring is 100% deterministic from the open check library. The optional AI layer only explains findings and suggests fixes in plain language — it never changes which checks pass or fail. You can run AI with your own Anthropic key (bring-your-own) so prompts stay on your account.
Cloud schedules re-scans per host (hourly/daily/weekly/manual). The scan worker runs the same deterministic CLI on a cadence and pushes fresh findings, so drift and newly-disclosed issues surface without you re-running anything. Free is daily; paid plans unlock hourly.
Limits are enforced server-side and fail clearly, never silently. Adding a host or API key past your plan cap returns an upgrade prompt (HTTP 402); exceeding the monthly scan quota returns a quota message (HTTP 429). Existing data is never deleted — you simply can't add more until you upgrade or the monthly quota resets.
Enterprise capabilities (SSO/SCIM, self-host + white-label, IP allowlist, data residency) are in private preview — info@keelix.dev.