Pricing — pay for the dock, not the hull

The gate stays free. Pay for the logbook.

The CLI is free and open source forever. Pay only for the hosted dashboard — scan history, scheduled re-scans, alerts, compliance reports, and team features.

Plan

Free

$0

  • 3 hosts
  • 1 seat
  • 100 scans/mo
  • 30 days retention
  • No AI
  • email alerts
Get started
Most popular

Pro

$19/mo

  • 15 hosts
  • 1 seat
  • 1000 scans/mo
  • 365 days retention
  • AI enrichment
  • email, slack, webhook alerts
Start
Plan

Team

$99/mo

Includes the owner seat · +$15 per additional member

  • 50 hosts
  • ∞ seats
  • 10000 scans/mo
  • 730 days retention
  • AI enrichment
  • email, slack, webhook alerts
  • Audit log
Start
Plan

Enterprise

Custom

  • ∞ hosts
  • ∞ seats
  • ∞ scans/mo
  • ∞ days retention
  • AI enrichment
  • email, slack, webhook alerts
  • Audit log
  • SSO / SCIM (private preview)
  • Self-host + white-label (private preview)
Contact sales

All plans include the full deterministic check library · Annual billing saves 2 months

SSO, SCIM, audit-log export, self-host/white-label, IP-based dashboard access, and data-region preferences are in private preview on Enterprise — contact us to enable them. "Data residency" is a stored region preference, not isolated infrastructure.

The fine print, plainly

Questions, answered

The CLI is free forever. Cloud is what you pay for — here is exactly what that means.

01

Does the CLI require the Cloud dashboard?

No. The keelix CLI is free, open source, and fully standalone — it runs every deterministic check locally, prints results, and exits. The Cloud dashboard is optional and only adds scan history, scheduled re-scans, alerts, compliance reports, and team features.

02

What data leaves my server?

With the CLI alone: nothing — checks run locally. If you opt in to `keelix push` (or run the scan worker), only the structured findings (check IDs, severities, and the host label you choose) are sent to Cloud over your kx_ API key. The dashboard never asks for SSH access to your hosts.

03

Do you store my docker-compose file?

No. Keelix evaluates your compose configuration where it runs and uploads only the resulting findings. Your compose file content is not transmitted to or stored by Cloud.

04

Does AI affect my score?

No. Scoring is 100% deterministic from the open check library. The optional AI layer only explains findings and suggests fixes in plain language — it never changes which checks pass or fail. You can run AI with your own Anthropic key (bring-your-own) so prompts stay on your account.

05

How do re-scans work?

Cloud schedules re-scans per host (hourly/daily/weekly/manual). The scan worker runs the same deterministic CLI on a cadence and pushes fresh findings, so drift and newly-disclosed issues surface without you re-running anything. Free is daily; paid plans unlock hourly.

06

What happens when I hit a plan limit?

Limits are enforced server-side and fail clearly, never silently. Adding a host or API key past your plan cap returns an upgrade prompt (HTTP 402); exceeding the monthly scan quota returns a quota message (HTTP 429). Existing data is never deleted — you simply can't add more until you upgrade or the monthly quota resets.

Enterprise capabilities (SSO/SCIM, self-host + white-label, IP allowlist, data residency) are in private preview — info@keelix.dev.