Security — enterprise stack.
For each requirement below, pick the option that fits your build — recommended first, then free and cheaper alternatives — or skip what your project doesn't need. Tap the info icon next to any requirement to see why it matters.
Source Code Repository & Branch Protection with Signed Commits
Where your source code lives and is collaborated on. Non-negotiable for any team or serious project.Pricing & free-tier limitsFree: unlimited public/private repos, 500MB Packages, 2000 Actions mins/mo, 1 push protection bypass / Team: $4/user/mo - 3k mins, reviewers, draft PR protection / Enterprise: $21/user/mo - 50k mins, SAML SSO, audit log streaming / Overage: $0.008/min Actions, $0.25/GB Packages over
CI/CD Pipeline & Hardened Runners
Automates testing and deploying your code. Saves enormous time and prevents “works on my machine” releases.Pricing & free-tier limitsFree: 2000 mins/mo Linux, 500MB cache, self-hosted unlimited / Team: $4/user - 3k mins incl / Paid: $0.008/min Linux, $0.016/min macOS, $0.08/min Windows 2-core, $0.32/min GPU / Cache $0.25/GB over 10GB / Overage billed minute
Artifact Registry & Signature Verification (Sigstore/Cosign)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: GHCR 500MB storage + 1GB transfer/mo free, Sigstore keyless signing free public / Harbor OSS free self-host / Paid: ECR $0.10/GB storage, $0.20/GB transfer / JFrog $50k/yr ent, $0.20/GB over / GCP AR $0.10/GB/mo + $0.12/GB egress over 1GB
Secrets Management Enterprise (Vault + HSM + CloudHSM)
Stores API keys and credentials safely, separate from your code. Leaking secrets is one of the most common breaches.Pricing & free-tier limitsFree: Vault OSS free self-hosted (no support), Infisical OSS unlimited self-host / Cheaper: AWS $0.40/secret/mo + API, Infisical $29/mo 10k secrets / Paid: HCP Vault $0.50/hr dev $1.32/hr ent (~$950/mo), $0.03/10k ops over 1M included / CloudHSM $1.88/hr/instance (~$1373/mo per HSM) + Vault Ent $50k/yr
Key Management Service (KMS) & CloudHSM
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: SoftHSM free unlimited keys for dev, LocalStack free mock / KMS: $1/key/mo, $0.03/10k requests, $0.06/10k asymmetric / CloudHSM: $1.88/hr ~$1373/mo per HSM, $0 over incl - pay for instance only / Thales: $1800/mo single, $5400/mo HA / Overages: KMS requests $0.03/10k, HSM no req overage
SAST Scanning (Static Application Security Testing)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: CodeQL unlimited public, 2000 private mins/mo / Semgrep CE unlimited scans, 2k OSS rules / SonarQube CE free unlimited LOC self-host / Team: $20/dev/mo Semgrep 5k scans, $32/mo SonarCloud 100k LOC / Paid: $98/dev/mo Snyk/Checkmarx, $150k/yr SonarQube 5M LOC + $0.05 per k LOC over
Dependency Scanning / SCA (Software Composition Analysis)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Dependabot unlimited PRs free, OSV unlimited API / Team: Snyk Team $25/dev/mo 1M tests included, $0.01 per 1k over / Socket $20/dev 500k checks / Paid: Business $98/dev 5M tests, $0.05/1k over / Mend $50k/yr ~$500/dev overage after 100 devs
Container / Image Scanning + SBOM
Where you keep files users upload or you serve — images, videos, documents — and how fast they reach visitors around the world.Pricing & free-tier limitsFree: Trivy/Grype unlimited scans OSS free self-host / Docker Scout Free 3 repo scans / Cheaper: Scout Team $12/user 200 scans/mo $0.10/scan over / Paid: Aqua $40k/yr 500 images $80/image over / Snyk Container $98/dev unlimited / Anchore $35k/yr 500 images
Audit Logs WORM Storage (Immutable Audit - S3 Object Lock)
Where you keep files users upload or you serve — images, videos, documents — and how fast they reach visitors around the world.Pricing & free-tier limitsFree: MinIO OSS free self-host WORM unlimited / B2 $0.006/GB/mo lock free / Wasabi $6.99/TB/mo immutable / AWS: S3 Standard $0.023/GB/mo, PUT $0.005/1k, CloudTrail Lake $2.5/GB ingestion + $0.75/GB/mo 7yr storage, $0.005 per 1k queries / Glacier Vault Lock $0.004/GB mo
SIEM / Log Management (Splunk, Panther, Wazuh)
Tells you when things break and why. You cannot fix what you cannot see — this is how you keep downtime short.Pricing & free-tier limitsFree: Wazuh OSS unlimited free self-host, Elastic Free 5GB/day, Graylog Community free / Cheaper: Panther Free 5GB/day > $0.30/GB over / Paid: Splunk $150/GB/day ingestion ~ $150/GB/mo, $0.10/GB over 10GB hot to warm / Chronicle $2/GB ingestion $0.20/GB retention / Elastic $95/mo + $0.15/GB over 10GB
Documentation & Security Advisory Portal (CVE Publishing)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Docusaurus/MkDocs free self-host unlimited / GitHub Pages free 100GB bandwidth / GitBook Pro $32/mo 10k views $0.01/view over / Enterprise $399/mo unlimited views + SLA / Confluence Premium $10/user/mo $870/mo 100 users / Statuspage $29/mo 100 subscribers
DAST Scanning & Dynamic Testing (OWASP ZAP, Burp)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: ZAP OSS unlimited free, Nuclei OSS free unlimited / Pro: Burp Pro $449/user/yr one-time, unlimited scans / Enterprise: $7,999/yr incl 10 scansites $1,200/site overage + $799/agent / Invicti $15k/yr 5 sites $3k/site over / OWASP ZAP Cloud scan free infra pay
Fuzz Testing Infra (AFL++, libFuzzer, ClusterFuzzLite, OSS-Fuzz)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: AFL++/libFuzzer free unlimited runs self-host / OSS-Fuzz free for public OSS / Cheaper: Spot VMs $0.01/vCPU/hr ~ $7 per core/week, $200/mo per 20 vCPU / Paid: Mayhem $75k/yr 25 targets $2k per extra target / CI $35k/yr 10 targets / GCP private Fuzz $2k/mo for 8k CPU hrs
Vulnerability Database API & Feed Sync (NVD, OSV, VulnDB)
Persistent storage for your app’s data — users, products, orders. The single most important architectural decision for most projects.Pricing & free-tier limitsFree: NVD 50 req/s with free key, OSV unlimited, CIRCL free / Community: VulnCheck 5k calls free / Paid: VulnDB $35k/yr 1M calls incl $0.01 per call over / VulnCheck $12k/yr 100k/mo $0.10 per 1k over / GH Advisory 5k/hr free $0.01/1k after enterprise
Code Signing + HSM for Product Releases (EV Certs, AV Signatures)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Sigstore free unlimited OSS signs, self-signed free / SSL.com eSigner $50/mo 100 signs $0.50/sign over / DigiCert OV $499/yr $80/mo + Trust Manager $1,200/mo 500 signs $0.40 over / EV Token $699/yr + YubiHSM2 $650 one-time / CloudHSM $1.88/hr instance
License Scanning & SBOM Generation (CycloneDX/SPDX)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Syft/Trivy/ScanCode free unlimited OSS / GitHub dep graph free / Team: FOSSA $150/mo 5k scans $0.03/scan over / Paid: FOSSA Ent $30k/yr unlimited $300/dev over 100 / Black Duck $60k/yr includes 100 devs $500 per extra / Mend $50k/yr
Identity & Access Management (SSO/MFA for Dev Team + YubiKey)
How users sign up, log in, and are authorized. Getting roles and access control right early prevents painful rewrites.Pricing & free-tier limitsFree: Keycloak/Authentik OSS free self-host unlimited / Auth0 Free 7.5k MAU $0, then $35/mo 1k MAU / Okta Developer 100 MAU free / Paid: Okta $8/user/mo SSO + $3 MFA = $11/user total, $0 over incl / Entra P2 $9/user/mo 100 incl / Duo $6/user/mo / YubiKey 5 $55 one-time per dev
Backup & Disaster Recovery (Immutable Backups, 3-2-1-1-0)
Copies of your data so a bug, hack, or outage doesn’t become permanent loss. Cheap insurance every serious project needs.Pricing & free-tier limitsFree: Restic/Kopia OSS free unlimited, MinIO free / B2 Free 10GB, then $0.006/GB/mo + $0.01/GB download / Wasabi $6.99/TB/mo no egress overage / Veeam Community free 10 VMs / Paid: Veeam $150/socket/yr or $12/vCPU/mo, AWS Backup $0.05/GB mo + $0.02/GB restore / Rubrik $45k/yr 50TB
Metrics & Uptime Monitoring for Security Backend
Where your code actually runs and serves requests. Picking the right host affects speed, scaling, and how much ops work you do.Pricing & free-tier limitsFree: Grafana OSS + Prom + Uptime Kuma free self-host / Cloud Free 10k series, 50GB logs, 50GB traces 14d retention / Pro: $8/user/mo + $8 per 1k metrics series over 10k + $0.50/GB logs over 50GB / Datadog $15/host + $0.10/GB logs $1.70/GB 15mo retention / Overage: $0.15/1k metrics series
Threat Intelligence API (VirusTotal, AlienVault OTX, MISP, Abuse.ch)
Stops bots, scrapers, and spam signups from abusing your service and inflating costs.Pricing & free-tier limitsFree: OTX free 10k/day, VT free 500/day 4/min, Abuse.ch unlimited free / VT Premium $600/mo 10k/day over $0.005/req / Enterprise: VT Ent $30k/yr 750k/mo $0.01 per req over / OTX Commercial $0 free remains / Pulsedive Pro $300/mo 50k req/mo $0.01/req over / Recorded Future $90k/yr
Sandbox / Malware Analysis Infra (Cuckoo, CAPE, Any.Run)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: CAPE/Cuckoo OSS free unlimited self-host, Triage/Hybrid free 100/day / Basic: Any.Run Basic $99/mo 300 tasks $0.50/task over / Paid: Any.Run Ent $25k/yr 10k tasks $2.5/task over / Joe Cloud Pro $24k/yr 6k $4/ex over / VMRay $60k/yr 5k $10/ex over / CAPE infra $200/mo self-host
Private PKI / Internal Certificate Authority
Encrypts traffic between your users and your servers. Without it browsers flag your site as insecure and you lose trust and search ranking.Pricing & free-tier limitsFree: Smallstep OSS, Vault PKI OSS, EJBCA CE free unlimited self-host / AWS: $400/CA/mo + $0.75 per cert (short-lived $0.10) / GCP $300/CA/mo + $0.73/cert / Paid: DigiCert $8k/yr 500 certs $15/add / Venafi $30k/yr 1000 $12/add / Sectigo $6k/yr 250 certs
WAF / Firewall Testing Lab (ModSecurity, Cloudflare lab)
Controls and protects your APIs — quotas, abuse prevention, and firewalls. Important once you have real traffic or many clients.Pricing & free-tier limitsFree: ModSecurity OSS + CRS free unlimited, GoTestWAF free / Pro: Cloudflare Pro $20/mo domain free 100k WAF events, SafeLine CE free / Paid: Cloudflare Ent $5k/mo 10 domains $250 over / Imperva $2k/mo per app 10M req $0.50/M over / F5 $15k hw + $3k/yr support
Endpoint Test Lab - Windows/macOS/Linux Malware VMs Farm
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: VirtualBox/KVM free self-host, Win Eval 90d free / Hetzner $80/mo + $25 Win lic + $0 over / Vultr $120/mo / Paid: VMware $3.5k/CPU one-time + $600/yr support / MacStadium $150/mo per mini + $0.10/hr extra / Equinix $350/mo per server $0 egress / AWS bare $4.68/hr $1.40 spot
Compliance Automation (SOC2, ISO27001, PCI-DSS, FedRAMP)
Keeps you secure and compliant with regulations. Required for enterprise customers and handling sensitive data.Pricing & free-tier limitsFree: Checklist templates free, OpenAudit free, AWS Audit Manager 1 assessment free / Starter: Vanta $7k/yr 50 emp SOC2 $100/emp over / Drata $10k/yr SOC2 only / Scale: Drata Pro $20k/yr 200 emp $100/emp over / Vanta $35k/yr 200 $150/emp over / Auditor add $5k-$15k per audit
Secure Development Enclave / Isolated Builds (Air-gapped, Nitro)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Qubes + Firejail + Kata free unlimited self-host / Nitro Enclave free over EC2, EC2 $0.34/hr c5.2xlarge 8 vCPU + no overage / Paid: GovCloud $10k/mo entry 10 servers $1k per extra / Azure DCsv3 $0.50/hr 4 vCPU / Datacenter cage $2k/mo rack $300/server power overage / Outpost $10k/mo
Message Queue for Threat Feeds (Streaming IoCs)
Runs slow work (emails, exports, payouts) in the background so users don’t wait. Keeps your app snappy.Pricing & free-tier limitsFree: Kafka OSS free self-host unlimited, Redpanda Community free / Upstash Free 10k/day then $0.20/1k msgs / Confluent Free $400 credit (~$0 over 1mo) / Paid: Confluent $1.50/CCU/hr + $0.11/GB in $0.11 out / MSK Serverless $0.25/GB ingress + $0.05/GB-mo storage + free tier 1mo / SQS Standard $0.40/M req over 1M free
Database for IoCs / Signature Store (High-write, Low-latency Lookup)
Persistent storage for your app’s data — users, products, orders. The single most important architectural decision for most projects.Pricing & free-tier limitsFree: Postgres/Timescale/ClickHouse OSS free self-host / Supabase Free 500MB $0 / Neon Free 3GB $0 / Upstash Free 10k cmds / Paid: ClickHouse $300/mo min $0.25/CU/hr + $0.01/GB-mo + $0.12/GB egress over 1TB / Redis Essentials $10/mo 100MB $0.12/MB over + $0.20/100k ops over 100k / Atlas M10 $57/mo 2GB $9/GB over
Binary Analysis & Reversing Lab (Ghidra Server, IDA Teams)
Where your code actually runs and serves requests. Picking the right host affects speed, scaling, and how much ops work you do.Pricing & free-tier limitsFree: Ghidra OSS free unlimited seats, Cutter free / Personal: Binary Ninja $149/yr 1 seat, IDA Home $365/yr non-commercial / Paid: IDA Pro Teams $3,200/seat/yr floating license $200 per extra concurrent + decompiler $2,800 addon / BN Commercial $399/yr single $1,200 ent / JEB $2,500/yr
Secure File Storage & Evidence Vault (Chain of Custody)
Where you keep files users upload or you serve — images, videos, documents — and how fast they reach visitors around the world.Pricing & free-tier limitsFree: MinIO free self-host unlimited WORM / B2 free tier 10GB $0.006/GB after + free lock / Wasabi $6.99/TB/mo free egress 1TB free egress / Paid: AWS S3 $0.023/GB-mo + $0.005/1k PUT $0.0004/1k GET + Glacier $0.004/GB Deep $0.00099 / Glacier Vault Lock $0.03/1k vault + $2.5k yr enterprise / Box $35/user/mo 100GB
Penetration Testing as a Service Platform (PtaaS - Cobalt.io)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Kali self-test free infra only / Core $10k per pentest single asset 2 wk, retest $2k extra / Enterprise: Cobalt $50k/yr 6 incl $12k per extra + $0 retest / Bugcrowd $30k/yr plat + tests $10k-40k / Bishop Fox $75k/yr 5 incl $15k over / Overage: $12k per extra pentest
Bug Bounty Platform & Triage
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: GitHub advisories free disclosure + huntr.dev free / HackerOne Community 0 platform fee - pay bounties $100-$30k each / Intigriti $2k prog fee + bounties / Enterprise: HackerOne $40k/yr 2 progs 50 hackers $100-$30k per bounty $10k triage bundle / Bugcrowd $50k/yr + $20k-$100k pool / Over: $500-$30k per valid bounty + $10k per 10 programs over
Network Traffic Analysis & IDS Testbed (Zeek/Suricata)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Zeek/Suricata/Arkime OSS free self-host unlimited / Security Onion Community free 1k EPS / Cheaper: Self-host $300/mo infra 5k EPS free license / Paid: Corelight $30k/yr per 1Gbps appliance $10k/Gbps over / Stamus $25k/yr 5 sensors $5k per extra sensor / ExtraHop $60k/yr 5Gbps $12k/Gbps over
Cloud Security Posture & Hardened Dev Cloud Accounts (CSPM)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Prowler/ScoutSuite OSS free unlimited, Security Hub 30d free then $0.0010/check + GuardDuty $1/M events / Wiz Go $1k/mo 100 workloads / Paid: Wiz $40k/yr 1000 workloads $40/workload over / Prisma $50k/yr 500 resources $100 per 100 over / Lacework $70k/yr 500 $0.25/workload over 500
Incident Response / SOAR & Case Management (TheHive, XSOAR)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: TheHive/Cortex/Shuffle Community free unlimited self-host / Shuffle Community 10k exec free then $0.05/exec / Tines Free 5 stories 1k tasks / Paid: XSOAR $30k/yr 10k actions/day $0.10 per 1k over (approx $3k per 1k daily over) / Splunk SOAR $15k/yr 5k $3 per 1k over / Swimlane $40k/yr 5k $0.20 per exec over
Customer Telemetry Ingestion Pipeline (Secure, PII-Scrubbed)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Snowplow Micro free 1M events dev, RudderStack OSS 1M/mo free, PostHog 1M/mo free / Free Cloud: RudderStack Free 500k/mo 1 source $0.50 per 1k over / Segment Free 1k MTU $0 / Paid: Segment Team $120/mo 10k MTU $0.12 per MTU over $0.20/1k events over 500k / RudderStack Growth $500/mo 2M $0.25/1k over / Snowplow $2k/mo 10M $0.20/1k over
Zero-Trust Network Access (ZTNA) for Developers (Tailscale, Cloudflare)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Tailscale Free 3 users 100 devices $0 / Cloudflare Free 50 seats $0 / Teleport OSS free unlimited self-host / Pro: Tailscale Pro $6/user 100 devices $0.10/device over / Paid: Cloudflare $7/seat/mo 50 incl $7 over / Tailscale Enterprise $18/user/mo 500 dev $0.10/dev over / Teleport Enterprise $15/user/mo + $5/resource over 50 / Zscaler $30/user/mo 100 users min
IaC Scanning & Policy as Code (Checkov, OPA, Conftest)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Checkov/OPA/tfsec/KICS free unlimited OSS / Trivy IaC free / Community: Bridgecrew 50 scans free, Snyk 200 tests free / Team: Bridgecrew $10/mo 200 scans $0.05/scan over / Paid: Snyk IaC $25/dev 5k tests $0.05 per test over / Prisma Bridgecrew $50k/yr 1000 repos $50/repo over / Styra DAS $25k/yr 100 polys $100/pol over
How this enterprise security checklist works.
Each requirement below is something a enterprise security build typically needs. Pick one of the four researched options — recommended, free, cheaper or paid — add your own with "Other", or skip the requirement if your project doesn't need it. Nothing is mandatory; the plan on the right tracks what you've decided so nothing gets forgotten.
Your picks are saved in this browser automatically, so you can come back anytime. Options are researched per build level and refreshed as vendors change their plans — always verify details on the provider's page before committing.