Pricing

On-prem dependency firewall pricing

๐Ÿ‡ช๐Ÿ‡บ EU-based vendor Built in Denmark GDPR-native, no CLOUD Act exposure NIS2 and DORA ready

ShieldedStack is runtime enforcement, unified risk scoring, and license compliance for your software supply chain โ€” on-premises in your environment. You hold the data. You hold the keys. You hold the audit trail.

We don't gate features behind tiers; every tier ships the complete product. What you pay for is scale, support, and the hard engineering behind air-gapped operation and customer-managed keys.

All tiers include npm, NuGet, PyPI, and Maven. There are no per-developer fees, no per-request charges, and no surprise overage bills.

30 days. Full Standard-tier features. Free hand-held Quickstart call. No credit card. No self-serve maze.

What's in the box, on every tier

01

Inline enforcement

Two proxy modes for npm, NuGet, PyPI, and Maven. Run Trust-Then-Verify to inventory real usage, then flip workspaces to Verify-Then-Trust for zero-trust blocking. Allow/deny lists, severity gates, release grace periods, and a standalone scanner handle CI and air-gapped cases.

02

Unified 0-10 risk score

One score per package blending CVE severity, version age, license posture, maintainability, and repository health. Your team gets one prioritised view instead of five tools to correlate.

03

Compliance and audit, built in

License-change detection, SPDX intelligence, SBOM export in SPDX and CycloneDX, full package-request audit trails, CSV/JSON exports, and Keycloak-backed SSO/SAML on day one.

What you own, always

Your data.

Scan history, alerts, package metadata, and audit logs stay in your database. We never touch it.

Your auth.

Keycloak ships with the product. SSO and SAML work on day one.

Your features.

RBAC, audit export, SBOM, license intelligence, risk scoring, proxy modes, and alerts are included everywhere.

Your retention.

You decide how long to keep history. There's no TTL we control.

Pricing tiers

All prices exclude VAT. Prices in DKK. EUR conversion shown for reference at month-end rate. Invoices issued in DKK; EUR billing available on request.

Every tier ships the complete product. You pay for scale, not features.

Single deployment

Starter

For small teams running a single production deployment who want the full dependency firewall without procurement drag.

40,000 DKK

/ year (approx. EUR 5,400)

  • 1 production installation.
  • 1 tenant with 1 workspace, unlimited projects.
  • Email support during business hours.
  • Free hand-held Quickstart during trial.
Request trial

Most teams land here

Most popular

Standard

For mid-market organizations moving from a single security pilot into multiple workspaces across engineering teams.

From 150,000 DKK

/ year (approx. from EUR 20,000)

  • 1 production + 1 non-production installation.
  • 1 tenant with up to 10 workspaces for multi-team rollout.
  • Production rollout patterns and policy templates.
  • Email + chat support with 4-hour critical response.
Request trial

Scale out

Enterprise

For multi-site companies, MSPs, consultancies, and enterprises that need isolation, rollout help, and faster support.

From 250,000 DKK

/ year (approx. from EUR 33,000)

  • Unlimited installations, tenants, and workspaces.
  • MSP-capable tenant isolation.
  • Compliance pack and guided rollout included.
  • 24x5 support with named engineer and 1-hour critical response.
Talk to us

Regulated and air-gapped

Sovereign

For regulated EU buyers that require air-gapped operation, mirrored intelligence feeds, customer-managed keys, and negotiated operational guarantees.

From 400,000 DKK

/ year (approx. from EUR 53,000)

  • Unlimited installations, including air-gapped environments.
  • Mirrored, air-gap compatible CVE feed.
  • Customer-managed encryption keys included.
  • 24x7 support, dedicated CSM, and custom SLA.
Talk to us

What you pay more for, as you move up: more installations, more tenants, more workspaces, air-gapped operation, customer-managed keys, faster response SLAs, and the engineering hours behind them. Not features. Not data access. Not auth.

Why on-prem, not SaaS?

Dependency installation is a high-trust, high-volume operation. Routing every npm install and dotnet restore through a third-party SaaS creates problems regulated buyers can't accept.

ShieldedStack is built and operated by an EU-based company in Denmark. Every license is on-premises by default. Sovereign extends that to air-gapped operation with customer-held encryption keys.

Data residency

Your dependency graph reveals architectural detail, internal package names, and procurement signals.

Build availability

On-prem keeps your pipeline running even when external metadata services are down.

CLOUD Act exposure

On-prem with customer-managed keys closes a gap SaaS providers cannot close architecturally.

Professional services and training

ShieldedStack ships with everything you need to deploy yourself. We also offer fixed-scope services for teams who want help getting it right faster.

Quickstart setup

Half-day remote session: install, first workspace, ecosystems, first policy, console walkthrough.

15,000 DKK (included with Standard+ trial)

Guided rollout

Two-day engagement across two weeks: production install, policies, CI integration, alert routing, training.

50,000 DKK (included with Enterprise+)

Migration

Policy mapping, CI conversion, and parallel-run validation from Snyk, Sonatype, or Dependabot.

From 40,000 DKK

Compliance pack

SIG/CAIQ/VSA responses, GDPR, NIS2, DORA, Schrems II TIA, diagrams, BCP/DR, pen test summary.

50,000 DKK (included with Enterprise+)

Training workshops

Secure dependency management and supply chain security workshops for engineering teams.

25,000-45,000 DKK

Named engineer hours

Policy review, incident response support, architecture questions, or roadmap input.

2,500 DKK / hour

What counts as an Installation, Tenant, and Workspace?

Installation โ€” A deployed instance. Production, staging, and DR each count separately.

Tenant โ€” A top-level isolation boundary. MSPs and holding companies usually need one per customer.

Workspace โ€” A scope inside a tenant for departments, business units, product lines, or environments.

Project โ€” A repo, application, or service inside a workspace. Projects are uncapped on every tier.

Frequently asked questions

Is there a free tier?

There's a 30-day free trial with full Standard-tier features and a free hand-held Quickstart call. No credit card. We don't run a self-serve registry, so every trial is provisioned by us.

What does the free trial include?

A signed 30-day license, Docker Compose distribution, scoped private registry credentials, Standard-tier capabilities, email support, and a free 30-minute Quickstart call. If you don't convert, the license enters a 7-day alert-only grace period โ€” we will never abruptly break your CI.

Do you charge per developer?

No. We license by Installation, Tenant, and Workspace count. Add as many developers, CI agents, and projects as you need within those limits.

Are any features locked behind higher tiers?

Only operational scale features. SSO, RBAC, audit export, all ecosystems, both proxy modes, SBOM, license detection, and all alert channels are included on every tier.

Can I run ShieldedStack in an air-gapped environment?

Yes, with the Sovereign tier. The CVE feed and risk intelligence are mirrored to a sync bundle you import on your schedule.

What support is included?

All tiers include software updates, CVE feed updates, and email support. Standard adds chat and 4-hour critical response. Enterprise adds 24x5 named engineer support. Sovereign adds 24x7 and a custom SLA.

Do I need to send any data to ShieldedStack?

No. ShieldedStack runs entirely in your environment. The only outbound traffic is CVE feed sync from OSV, GitHub Advisory, and NVD โ€” and even that can be mirrored offline on Sovereign. We do not phone home. We do not collect usage telemetry. We do not see your dependency graph, ever.

What ecosystems do you support?

npm, NuGet, PyPI, and Maven on every tier. Cargo, Go modules, and RubyGems are on the roadmap.

Try ShieldedStack on your own infrastructure.

30 days. Full Standard-tier features. Free Quickstart setup included. No credit card.