Free
Try Chainsaw on a single team.
- 500 MB storage
- 1 GB bandwidth (up + down)
- 3 users
- All 25 signals on every tier
- All package managers
- Policy enforcement & monitoring
- Read & export your own SBOM + inventory
- Webhooks
- Community support
Pricing
Three plans, published limits. All 25 signals, webhooks, and read/export of your own SBOM + inventory are on every tier. Enterprise gating applies only to SSO, SCIM, SIEM streams, and on-prem. Billed through Paddle with a 14-day money-back guarantee on every paid plan.
Detection layer is not a tier
Tier gates apply to scale (storage, bandwidth, users), enterprise integrations (SSO, SCIM, SIEM), and deployment shape (on-prem, air-gapped) — never to the detection layer or your view of your own data.
Pricing
Start free, upgrade when policy moves into production, and flip to Unlimited when you need enterprise integrations or on-prem deployment.
Try Chainsaw on a single team.
Recommended
For teams rolling out in production.
Extra data billed at $1.50 / GB.
For orgs that need unlimited scale and enterprise fit.
Tier-gated capabilities. Volume limits above apply to every plan; the items below are boolean — either included in the tier or not.
| Capability | Free | Pro | Unlimited |
|---|---|---|---|
| Billy AI assistant | · | ||
| Single sign-on (SAML & OIDC) | · | · | |
| SCIM provisioning | · | · | |
| On-premise / air-gapped deployment | · | · | |
| SIEM export | · | · | |
| Ticketing integrations (Jira, ServiceNow) | · | · |
Need something custom?
Unlimited unlocks third-party integrations and on-prem eligibility. If you need bespoke deployment, air-gap, or a negotiated contract, jump on a 30-minute call.
Paid plans are sold and billed through Paddle, who handles payment processing, tax, and invoices. We never see your card details. Every subscription is covered by a 14-day money-back guarantee — full refund within 14 days of your first upgrade, prorated refund for unused time thereafter.
FAQ
Because Chainsaw does one thing well — policy enforcement on the install path — rather than bundling scanning, dashboards, remediation tickets, and every adjacent category into a single seat price. If you need broader posture management, pair Chainsaw with an SCA tool; that's the pattern we see most often.
No. Pricing is plan-based, not seat-based. Usage is bounded by storage and bandwidth caps applied to the org as a whole. Add developers freely inside the plan's user count.
Yes. 500 MB storage, 1 GB bandwidth (upload + download combined), 3 users. No credit card required. Built for a single team evaluating Chainsaw on a non-critical repo.
Usage keeps working. Additional data is billed at $1.50 per GB on Pro, you see usage in the billing dashboard, and you get an in-app nudge at 80% of cap.
Yes — all 25 signals fire on every tier. Install-script exfiltration, maintainer takeover, version anomalies, hidden Unicode, publish velocity, reserved namespaces, Docker malware feed, per-layer image enforcement, APT/Yum/DNF provenance, typosquat, repo liveness, checksum fail-closed, transitive-risk closure, maintainer-age reputation, RTT (repo trust traits), and the rest all run on Free, Pro, and Unlimited. Tier gates only apply to enterprise integrations (SSO, SCIM, SIEM streams) and on-prem deployment — never to the policy layer.
Yes. Reading and exporting the org's own SBOM and inventory is on every tier — these are your data, not ours to gate. Pro and Unlimited extend snapshot retention and add advanced dashboards / audit-trail history. The CycloneDX 1.6 + SPDX export is available on every plan.
Yes. Upgrade or downgrade from the in-app billing page. Upgrades apply immediately. Downgrades take effect at the end of the current billing period so you retain the paid features you've been using.
Yes. Webhooks are not paywalled. Every tier can configure up to five webhooks per user for events like blocked installs. Only SIEM streams (Splunk HEC, Microsoft Sentinel, IBM QRadar) and SCIM are Unlimited-only.
On-prem is Unlimited. The CLI can bake the server URL at build time so air-gapped users never see a public origin. Book a call for custom rollouts.
SAML, OIDC, and SCIM provisioning are Unlimited-only. Password plus TOTP works on Free and Pro; invite-based role assignment applies on every tier.
Yes. Contact sales for annual terms on Pro and Unlimited, and for volume pricing above 50 users.
Pro includes business-day support. Unlimited includes a 99.9% uptime SLA and dedicated onboarding. Details are shared during custom-contract discussions.