Skip to main content

Pricing & Plans

This page documents Dralvia's commercial packaging: a smaller free evaluation lane, two self-serve paid plans with live public checkout, and enterprise sales-led packaging. If a term is unfamiliar, open the Glossary.

Seven-day plan trials

Eligible signed-in Free Evaluation and Starter workspaces can start an exact seven-day trial of the next self-serve plan from Pricing & Plans. Pro can request a guided Enterprise trial when that rollout is enabled.

The confirmation states the start behavior before access changes. No payment card is required, Stripe is not called, and the trial never creates an invoice, subscription, or automatic charge. Self-serve trials start immediately. A guided or provisioning-gated trial starts its 168-hour clock only when Dralvia marks provisioning ready. When time expires, the workspace returns to its base plan unless the customer separately buys a plan.

Scan evidence retention

Every scan keeps its full evidence for a period that depends on your plan. Full evidence means the screenshots and heavy capture artifacts. After that period the verdict, the score and the findings stay for as long as the scan does; only the heavy evidence is cleared.

PlanFull evidence kept
No account1 day
Free Evaluation7 days
Starter30 days
Pro90 days
EnterpriseBy agreement

Creating a free account takes retention from one day to seven, which is the main practical reason to make one before you decide whether to pay.

Every scan report states its own figure, so you never have to work it out from this page:

"retention": {
"payload_retention_days": 30,
"scope": "workspace",
"plan": "STARTER",
"full_evidence_until": "2026-09-25T13:33:35Z"
}

Enterprise reports say "basis": "contract" and carry no date, because the period is whatever your agreement says rather than a figure set here.

Optional recurring modules

Some higher-plan capabilities can be bought separately when a customer needs a narrower package. Pricing & Plans shows only add-ons that are configured and compatible with the selected base plan.

ModuleMonthlyAnnualNotes
Browser Protection$29$290Optional on Starter; included in Pro and Enterprise.
Activity Signals$19$190Optional on Starter; included in Pro and Enterprise.
TicketBridge Workflows$19$190Optional on Starter; included in Pro and Enterprise.
Deception Signals$39$390Optional on Starter; included in Pro and Enterprise.

Browser Extension Downloads, Wallet Risk Review, Web Access Protection, and Email Protection are included from Starter rather than sold separately to a Free Evaluation workspace. Cloud Posture, AI Agent Safety, Enterprise Controls, and endpoint response need provisioning or contract scope and are not sold as instant add-ons.

A new checkout can contain one base plan plus compatible module items. Stripe presents one combined total, one subscription, one invoice, and one payment. For an existing Stripe subscription, contact [email protected] to add or remove module items without creating a second subscription. Open Billing Portal remains the place for payment methods, invoices, cancellation, and supported plan changes. Removing an item locks that module after its paid entitlement ends and does not delete its stored workspace data.

Annual add-on prices are approximately ten monthly payments. Stripe Price identifiers remain deployment configuration. A module is not offered for payment unless its matching Stripe price is configured.

Access tiers

PlanPriceIntended forIncluded surfaces
Free EvaluationFreeIndividuals, founders, crypto users, and evaluators who want to test value before paying.Limited public scans and product preview only.
Starter$49/month or $490/yearIndividuals, founders, crypto users, and very small teams that want self-serve onboarding.1 seat, 1 workspace, browser extension access, predictable quotas, exports, and no sales call.
Pro$199/month or $1,990/yearSmall security teams and dev teams that need a shared workspace and higher limits.Multi-seat workspace, browser extension access, more API keys, higher quotas, more exports, and team workflows.
EnterpriseCustom contractEnterprise, MSSPs, and regulated organizations.Browser extension access, SSO, procurement, custom limits, dedicated support, and deployment/legal options.

All paid tiers are intended to preserve the same core Dralvia surfaces while changing quota, workflow depth, support posture, and commercial controls.

Email Protection packaging note

Every plan gets the same Email Protection capability; plans differ only by how many mailboxes you can connect:

  • Free Evaluation: manual email analysis only (paste an email or upload an EML). No connected mailboxes.
  • Starter: everything in Free, plus connected mailbox protection for up to 5 mailboxes.
  • Pro: connected mailbox protection for up to 50 mailboxes, plus API relay, raw email and EML workflow, safe-link rewrite, per-recipient click attribution, click-time verdicts, attachment checks, policy routing, operator next steps, message history, EvidencePack (Dralvia's exportable evidence report), and remediation tracking.
  • Enterprise: a custom number of connected mailboxes by contract, plus SMTP receiver options, quarantine folder profile, managed remediation audit, and custom retention.

How "connected mailbox protection" works today and what is rolling out:

  • Available now (self-serve): connect a mailbox with a provider app password (Gmail, Yahoo, iCloud, Outlook, or a custom IMAP host). Dralvia reads mail for analysis, runs a historical scan, and can monitor incoming mail. See the Email Protection guide for the step-by-step.
  • Rolling out: Microsoft 365 and Google Workspace direct collection, and automated provider retract or quarantine execution. These light up for every plan as they ship; they are not capability you have to buy a higher tier for. The mailbox count above is the only difference between plans.

Use the Email Protection Setup tab for the current readiness matrix. The matrix is informational until the final plan and quota decision is approved.

Included surfaces

The pricing page now shows a compact included-surface list on each plan card plus an expandable More included section for detailed fit checks. The intended plan boundaries are:

Free Evaluation

  • URL & phishing scanner for light evaluation use.
  • Smart contract review for light evaluation use.
  • Public scan-result previews and risk explanations.
  • Platform preview and public documentation.
  • No Email Protection submission, browser extension, team workspace, API-key management, billing exports, SLA, SSO, or dedicated support.

Starter included surfaces

  • Workspace with owner access.
  • 1 seat and 1 API key.
  • URL & phishing scanner.
  • Smart contract review.
  • Repository Risk Scanner for small repo uploads.
  • Browser Extension rollout/downloads for page-level warnings and rollout artifacts.
  • Shadow-render budget for suspicious web pages.
  • Manual Email Protection analysis for pasted email or EML samples, with basic URL, attachment, and EvidencePack output.
  • No Email Protection API relay, managed mailbox ingestion, SMTP receiver, or provider retract/quarantine execution.
  • EvidencePack/report export allowance.
  • Billing portal access after Stripe checkout.
  • Standard email support.
  • No SSO, SCIM, MSSP hierarchy, on-prem contract, or custom compliance review.

Pro included surfaces

  • Shared workspace for a small team.
  • 5 seats and 5 API keys.
  • Higher URL and smart contract scan limit for repeated team use.
  • Higher repo-scanning quota for engineering workflows.
  • Browser Extension rollout/downloads for managed users.
  • Browser Protection.
  • TicketBridge workflow for triage handoff.
  • Email Protection API relay, raw email and EML workflow, safe-link rewrite, per-recipient click attribution, click-time verdicts, attachment checks, policy routing, recommended next steps, message history, EvidencePack, and remediation tracking.
  • No Email Protection managed mailbox ingestion or provider retract/quarantine execution by default.
  • Usage exports and larger EvidencePack/report allowance.
  • Priority support path.
  • No enterprise SSO/SAML/SCIM or custom deployment terms.

Enterprise included surfaces

  • Everything in Pro.
  • Browser Extension rollout/downloads and browser governance aligned to the contract scope.
  • SSO/SAML/SCIM and identity governance.
  • Custom scan, repo, render, report, and API-key quotas.
  • MSSP or multi-customer operating model.
  • Custom legal, security, privacy, and procurement review.
  • Dedicated support and escalation paths.
  • On-prem, airgapped, or custom region deployment options.
  • Email Protection managed mailbox ingestion, SMTP receiver options, provider retract/quarantine execution, quarantine folder profile, managed remediation audit, custom retention, and custom message/mailbox/action volume by contract.
  • Custom billing, invoice, refund, and tax handling.
  • Security evidence, audit, and compliance export alignment.

Which plan unlocks which module

Every plan can run the core scanners (URL and phishing, smart contract, and a capped repository scan preview). Workspace modules follow this matrix. When your plan does not include a module, the platform shows an upgrade panel explaining which plan includes it, instead of opening a module that would fail.

ModuleFree EvaluationStarterProEnterprise
API KeysNoYesYesYes
Repository Risk ScannerPreview (3/day)YesYesYes
Browser Extension DownloadsNoYesYesYes
Email ProtectionNoYesYesYes
Web Access Protection (shadow browsing)NoYesYesYes
Wallet Risk ReviewNoYesYesYes
Billing & PaymentsNoYesYesYes
Browser ProtectionNoNoYesYes
Cloud Posture (CSPM)NoNoYesYes
Deception SignalsNoNoYesYes
Identity Risk and OAuth RiskNoNoYesYes
Endpoint ProtectionNoNoYesYes
Endpoint Agent DownloadsNoNoYesYes
Device Sensor DownloadsNoNoYesYes
Edge Connector DownloadsNoNoYesYes
Activity Signals dashboardsNoNoYesYes
TicketBridge workflowsNoNoYesYes
Pro Tier console (teams, webhooks, exports)NoNoYesYes
AI Agent SafetyNoNoNoYes
Enterprise Controls (SSO, SCIM, regions)NoNoNoYes

The same matrix is available programmatically from GET /billing/entitlements. Signed-in calls also return your workspace plan and its module list, so automation can check access before calling a module API.

Plan limits

These values represent the enforced plan defaults. Custom Enterprise limits are set by contract.

PlanPlatform feeIncluded scans/moPer scanShadow renders/moPer renderReports/moNotes
Free Evaluation$0Tight evaluation limitsN/AVery limitedN/AVery limitedNo SLA, no billing workspace
Starter$491,000 combined URL and smart contractIncluded in plan100Included in plan31 seat, 1 key, browser extension, self-serve
Pro$19910,000 combined URL and smart contractIncluded in plan750Included in plan205 seats, 5 keys, browser extension, self-serve
EnterpriseCustomCustomCustomCustomCustomCustomContract terms

Free evaluation limits

  • Positioning: enough to prove product value, not enough to run a full security workflow for free.
  • Access model: guest/public evaluation, not a paid workspace.
  • Limits: intentionally tighter than paid tiers and subject to anti-abuse controls. Repository scans are a signed-in preview capped at 3 scans per day.
  • Good fit: first-time evaluators, founders, crypto users, and lightweight product validation.

Starter

  • Audience: individuals, founders, solo operators, crypto users, and very small teams.
  • Price: $49/month or $490/year.
  • Includes: 1 seat, 1 workspace, 1 API key, 1,000 combined URL and smart contract scans/month, 10 repo scans/month, browser extension rollout/downloads, 100 shadow renders/month, 3 EvidencePack/report exports.
  • Why buy it: simple self-serve onboarding, predictable cost, and enough capacity for real day-to-day checking before links, domains, and contracts are trusted.

Pro

  • Audience: small security teams, dev teams, startups with security ownership, and teams that need a shared workspace.
  • Price: $199/month or $1,990/year.
  • Includes: 5 seats, 5 API keys, 10,000 combined URL and smart contract scans/month, 100 repo scans/month, browser extension rollout/downloads, 750 shadow renders/month, 20 EvidencePack/report exports, Browser Protection, TicketBridge, Email Protection API relay, safe-link attribution, click-time verdicts, attachment checks, recommended next steps, message history, remediation tracking, and usage exports.
  • Why buy it: team workflow, higher quota headroom, more exports, and better fit for repeated operational use.

Self-serve checkout status

Starter and Pro are available as live plans with monthly and yearly prices. The pricing page shows audience-first plan copy, monthly/yearly price switching, expandable included-surface details, Upgrade buttons for signed-in customers, Buy buttons for signed-out visitors, checkout success status, and a billing-portal action for authenticated customers.

Which button should I see?

The button always describes the move from your current plan:

Your planFree Evaluation cardStarter cardPro card
Not signed in(not offered)Buy StarterBuy Pro
Free EvaluationCurrent planUpgrade to StarterUpgrade to Pro
Starter(not offered)Current planUpgrade to Pro
Pro(not offered)Downgrade to StarterCurrent plan

Current plan is not a button. It names the plan you are already on and cannot start a checkout, so you can never pay twice for the plan you have.

Why this matters:

  • Upgrade keeps your current workspace and changes the plan on that same account.
  • Buy is the retail path for a new paid workspace when no signed-in account context exists yet.

The Browser Extension is part of paid packaging only. Free Evaluation users can preview public scanner value, but Starter, Pro, and Enterprise users can access the extension rollout/download surface.

Public checkout is live for Starter and Pro, monthly and yearly. If you prefer a guided start, or you are evaluating Enterprise, use the public request-access form so Dralvia gets your team, route, and expected volume in one intake.

The backend now also has shared workspace-provisioning logic for both manual onboarding and Stripe-webhook resume flows. Stripe invoice.paid and invoice.payment_failed events are mirrored into Dralvia billing records already. The public Stripe catalog, checkout session, checkout status, and webhook routes are allowed through the live auth layer; billing portal, invoice, and export routes still require authenticated workspace access. The remaining gap is webhook health verification, broader billing reconciliation hardening, and live rollout verification.

Checkout and plan-change safeguards

Self-serve checkout protects you from accidental duplicate purchases:

  • Retried checkout reuses your open session. If you click Buy or Upgrade again for the same plan and billing interval within 24 hours, the API returns your existing open checkout link (reused: true in the POST /billing/checkout/session response) instead of creating a second checkout. You are never queued for two subscriptions because of a double-click or a page refresh.
  • Already on that plan? An upgrade request for the exact plan and interval your workspace already has active is rejected with 409 plan_change_noop. Nothing is charged.
  • Plan changes on an active subscription go through the billing portal. If your workspace already has a live self-serve subscription, a checkout request for a different plan is rejected with 409 plan_change_requires_portal. Use the Manage billing portal action instead: the portal amends your existing subscription with correct proration, so you are never billed for two subscriptions at once.
  • Expired checkouts close honestly. A checkout link that is not completed within Stripe's validity window is marked expired. GET /billing/checkout/status then reports subscription_status: expired, and a fresh checkout request creates a new session.
  • Portal plan changes sync back automatically. When you switch plans in the billing portal, Dralvia detects the price change from the subscription update, applies the new plan to your workspace, and refreshes your license and limits without any support ticket.

Failed payment and cancellation behavior

  • A failed Stripe invoice places the workspace into a 7-day payment grace window.
  • During active grace, existing paid scan and report workflows can continue so teams have time to fix billing.
  • After grace expires, new scans, report exports, paid write actions, and new API-key creation are blocked until billing is restored.
  • Cancelling a subscription drops the workspace to the free plan. Your data stays intact, and the workspace keeps working within the free plan's limits. Paid-only modules are locked again until you resubscribe. You cancel from the billing portal (Pricing & Plans, Open Billing Portal).

How to enroll

  1. Request access: submit the public request-access form with your company, buyer contact, primary use case, and rough scan volume. Dralvia usually responds within one business day.
  2. Confirm scope and route: Dralvia confirms whether your best entry point is Free Evaluation, Starter, Pro, or Enterprise.
  3. Receive credentials: we ship a license bundle (license.yaml and feature toggles) plus deployment instructions tailored to your plan.
  4. Set usage expectations: open Usage & Limits (#/tenant-usage) to watch your allowance, and Billing & Payments (#/tenant-billing) for invoices and payment state.

Next best actions

After finishing this page, continue with related workflows so your setup stays end-to-end complete:

FAQ

What happens when we outgrow the free evaluation lane?

Move to Starter if you are still mostly an individual or very small team. Move to Pro if Dralvia becomes a shared team workflow. Move to Enterprise if you need procurement, SSO, compliance review, or custom deployment terms.

Do you offer annual subscriptions?

Yes in the commercial packaging model: Starter yearly is $490/year and Pro yearly is $1,990/year. Both are available in public self-serve checkout.

Is PAYG part of Stripe self-serve?

No. PAYG remains out of Stripe v1. Self-serve launch scope is Starter and Pro only, while Enterprise remains sales-led.

Who this is for

This guide is for owners, admins, and security operators who need clear, repeatable steps without support intervention for day-to-day execution.

Role-based start here

  • Owner / buyer: decide the plan from the Access tiers table, then follow How to enroll.
  • Workspace admin: after enrollment, review Usage & Limits and invite seats (Pro and Enterprise).
  • Security operator: confirm the surfaces your plan includes (Included surfaces) so you know which workflows are available day to day.

Before you start

You need: a workspace (or the intent to create one), a billing contact, and a rough monthly scan volume so the right plan is chosen. If you are evaluating, no billing details are needed for the Free Evaluation lane.

Step-by-step

  1. Pick a plan from Access tiers using your team size and expected volume.
  2. If signed in, use the Upgrade button on the plan card. If signed out, use Buy, or submit the request-access form while public checkout is still being enabled.
  3. Complete checkout (or receive your license bundle for sales-led plans).
  4. Open Usage & Limits to confirm your allowance and watch consumption.
  5. Invite additional seats if your plan includes them.

Day-2 operations

  • Watch usage against your plan limits (Plan limits) in Fabric Billing & Exports.
  • Set warning thresholds so you are alerted before you hit a quota.
  • Upgrade when you are consistently near a limit, rather than after you hit it.
  • Review failed-payment grace status if a billing event fails (Failed payment and cancellation behavior).

Self-check playbook

  • Confirm your active plan and renewal date in the billing portal.
  • Confirm seat and API-key counts match your plan tier.
  • Run one scan and confirm it is counted against the expected quota.
  • Confirm exports are available if your plan includes them.

What each button does

  • Upgrade to Starter / Upgrade to Pro: changes the plan on your current signed-in workspace.
  • Buy Starter / Buy Pro: retail path for a new paid workspace when you are signed out.
  • Billing portal: manage payment method, invoices, and cancellation for a workspace that bought its plan through self-serve checkout. A workspace whose plan was set up for you by Dralvia (for example an Enterprise plan, or a plan granted directly by the team) is managed by Dralvia and does not use the self-serve portal; to change or cancel it, contact [email protected].
  • Request access: intake form for guided onboarding or Enterprise conversations.

Troubleshooting

  • You see Buy when you expected Upgrade: you are signed out. Sign in to your workspace first.
  • Checkout is unavailable: this is usually a temporary service condition; retry after a minute. If it persists, use the request-access form so Dralvia can complete your signup directly.
  • Scans or exports are blocked: check whether a failed payment moved the workspace past its grace window.
  • Quota looks wrong: confirm your active plan in the billing portal, since limits follow the plan tier.

API and automation

  • Usage and quota state are visible through the workspace usage endpoints and in Fabric Billing & Exports.
  • Stripe invoice.paid and invoice.payment_failed events are mirrored into Dralvia billing records, so automated billing reconciliation reflects payment state.
  • Public catalog, checkout session, checkout status, and webhook routes are reachable through the live auth layer; billing portal, invoice, and export routes require authenticated workspace access.

Next steps

API error quick reference

Use this matrix when a UI action or API call fails with an HTTP error.

ErrorMeaningWhat to do now
401 UnauthorizedSession token or API key is missing, expired, or not authenticated.Sign in again (or refresh your API key) and retry in the correct workspace.
403 ForbiddenAuthenticated, but your role or plan does not allow this action.Confirm your role and that your plan includes the feature. Ask a workspace admin to grant access.
404 Not FoundThe route or resource does not exist in the current workspace context, or the feature is not enabled.Confirm the route, workspace context, and feature availability, then retry.
409 ConflictThe checkout request conflicts with your current subscription: plan_change_noop means the workspace already has that exact plan and interval, and plan_change_requires_portal means an active subscription must be changed in the billing portal.For a no-op, no action is needed. For a portal-managed change, open Manage billing and switch plans there.
429 Too Many RequestsA rate limit or plan quota window was exceeded.Wait for the reset window, retry once, then reduce burst volume or upgrade the plan.
500 Internal Server ErrorThe backend failed unexpectedly while processing the request.Retry after 30 to 60 seconds. If it persists, escalate with workspace ID, UTC time, route, and error text.

Known limits and rate limits

  • Plan quotas are the enforced defaults in the Plan limits table above: scan, render, report, repository, and API-key limits follow your plan tier.
  • API requests are rate limited per workspace. A 429 Too Many Requests response means a rate or quota window was exceeded; wait for the reset window, then retry once and reduce burst volume.
  • Free Evaluation has the tightest limits and is subject to anti-abuse controls. Paid plans raise the limits; Enterprise sets custom limits by contract.