Synopsis
What you get
All the features to experience the power of supply chain security
Comprehensive SDLC security, Compliance, Posture Management & Analytics
Everything in Business, plus full customization, premium support, and on-prem/VPC deployment
# Developers
Size of the development team
Unlimited for 30 days
up to 150 (in 50 developer increments)
Over 150
Vulnerability & Risk Management
Advanced software risk analytics and reports
Out-of-the-box reports covering major security and compliance KPIs
Vulnerability & Risk Management
Reports & Analytics customization
Reports fully customized to suit enterprise needs
SDLC Security
CI/CD security posture
Identify misconfigurations and gaps in your toolchain
SDLC Security
Build integrity validation
Validate your builds were not tampered with
SDLC Security
Auto pipeline discovery (code to cloud lineage)
Automatic Discovery and mapping of all your pipelines from code to cloud
SDLC Security
Continuous code signing
Sign and verify artifacts at every step of the SDLC
Sigstore
Sigstore + PKI
Sigstore + PKI
SDLC Security
AI-Ops integrity validation
Specialized signing and verification for AI models and datasets
SDLC Security
AI-BOM customization
Expanded SBOM format that includes AI models, data sets, and licenses
Build to Suit
SDLC Policy Management
Production policy gateway
Admission Controller that allows granular control on what gets deployed to production
SDLC Policy Management
Conditional signing
Conditional enforcement of code signing based on validation of mandatory SDLC
SDLC Policy Management
Full access to SDLC policy as code library
Access to 150+ best-practice configurable SDLC controls
SDLC Policy Management
Custom controls
Customized enterprise controls to match organizational security policy
Build to Suit
Compliance
SLSA compliance
Validation of adherence to SLSA
L1, L2
L1, L2
L1, L2, L3
Compliance
SSDF compliance
Validation of adherence to NIST 800-218
Compliance
Custom compliance
Scribe-supported policy authoring to meet specialized organizational needs
Build to Suit
Back Office and Integration
# Pipelines
3
Unlimited
Unlimited
Back Office and Integration
Data retention period
Retention period for raw attestations
1 month
3 months
1 Year
Back Office and Integration
SSO
Support for all popular enterprise SSO solutions
Back Office and Integration
Scribe API
Rich data extraction APIs, to support integration with SOC, SIEM and other 3rd party tools
Back Office and Integration
On-prem/ VPC deployment
Tailored deployment
Support
Customer Success
A dedicated engineer makes sure you get the maximum value from Scribe
N/A
Guided Onboarding
Technical Account Manager
Support
Support
Community
Priority
SLA (standard/ Premium 24/7)
First 50 developers: $4000/mon
Each incremental 50 developers: $2000/month
(paid annually)