Security — small scale stack.
For each requirement below, pick the option that fits your build — recommended first, then free and cheaper alternatives — or skip what your project doesn't need. Tap the info icon next to any requirement to see why it matters.
Source Code Repository & Branch Protection with Signed Commits
Where your source code lives and is collaborated on. Non-negotiable for any team or serious project.Pricing & free-tier limitsFree: unlimited public/private repos, 500MB Packages, 2000 Actions mins/mo, 1 push protection bypass / Team: $4/user/mo - 3k mins, reviewers, draft PR protection / Enterprise: $21/user/mo - 50k mins, SAML SSO, audit log streaming / Overage: $0.008/min Actions, $0.25/GB Packages over
CI/CD Pipeline & Hardened Runners
Automates testing and deploying your code. Saves enormous time and prevents “works on my machine” releases.Pricing & free-tier limitsFree: 2000 mins/mo Linux, 500MB cache, self-hosted unlimited / Team: $4/user - 3k mins incl / Paid: $0.008/min Linux, $0.016/min macOS, $0.08/min Windows 2-core, $0.32/min GPU / Cache $0.25/GB over 10GB / Overage billed minute
Artifact Registry & Signature Verification (Sigstore/Cosign)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: GHCR 500MB storage + 1GB transfer/mo free, Sigstore keyless signing free public / Harbor OSS free self-host / Paid: ECR $0.10/GB storage, $0.20/GB transfer / JFrog $50k/yr ent, $0.20/GB over / GCP AR $0.10/GB/mo + $0.12/GB egress over 1GB
Secrets Management Enterprise (Vault + HSM + CloudHSM)
Stores API keys and credentials safely, separate from your code. Leaking secrets is one of the most common breaches.Pricing & free-tier limitsFree: Vault OSS free self-hosted (no support), Infisical OSS unlimited self-host / Cheaper: AWS $0.40/secret/mo + API, Infisical $29/mo 10k secrets / Paid: HCP Vault $0.50/hr dev $1.32/hr ent (~$950/mo), $0.03/10k ops over 1M included / CloudHSM $1.88/hr/instance (~$1373/mo per HSM) + Vault Ent $50k/yr
Key Management Service (KMS) & CloudHSM
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: SoftHSM free unlimited keys for dev, LocalStack free mock / KMS: $1/key/mo, $0.03/10k requests, $0.06/10k asymmetric / CloudHSM: $1.88/hr ~$1373/mo per HSM, $0 over incl - pay for instance only / Thales: $1800/mo single, $5400/mo HA / Overages: KMS requests $0.03/10k, HSM no req overage
SAST Scanning (Static Application Security Testing)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: CodeQL unlimited public, 2000 private mins/mo / Semgrep CE unlimited scans, 2k OSS rules / SonarQube CE free unlimited LOC self-host / Team: $20/dev/mo Semgrep 5k scans, $32/mo SonarCloud 100k LOC / Paid: $98/dev/mo Snyk/Checkmarx, $150k/yr SonarQube 5M LOC + $0.05 per k LOC over
Dependency Scanning / SCA (Software Composition Analysis)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Dependabot unlimited PRs free, OSV unlimited API / Team: Snyk Team $25/dev/mo 1M tests included, $0.01 per 1k over / Socket $20/dev 500k checks / Paid: Business $98/dev 5M tests, $0.05/1k over / Mend $50k/yr ~$500/dev overage after 100 devs
Container / Image Scanning + SBOM
Where you keep files users upload or you serve — images, videos, documents — and how fast they reach visitors around the world.Pricing & free-tier limitsFree: Trivy/Grype unlimited scans OSS free self-host / Docker Scout Free 3 repo scans / Cheaper: Scout Team $12/user 200 scans/mo $0.10/scan over / Paid: Aqua $40k/yr 500 images $80/image over / Snyk Container $98/dev unlimited / Anchore $35k/yr 500 images
Audit Logs WORM Storage (Immutable Audit - S3 Object Lock)
Where you keep files users upload or you serve — images, videos, documents — and how fast they reach visitors around the world.Pricing & free-tier limitsFree: MinIO OSS free self-host WORM unlimited / B2 $0.006/GB/mo lock free / Wasabi $6.99/TB/mo immutable / AWS: S3 Standard $0.023/GB/mo, PUT $0.005/1k, CloudTrail Lake $2.5/GB ingestion + $0.75/GB/mo 7yr storage, $0.005 per 1k queries / Glacier Vault Lock $0.004/GB mo
SIEM / Log Management (Splunk, Panther, Wazuh)
Tells you when things break and why. You cannot fix what you cannot see — this is how you keep downtime short.Pricing & free-tier limitsFree: Wazuh OSS unlimited free self-host, Elastic Free 5GB/day, Graylog Community free / Cheaper: Panther Free 5GB/day > $0.30/GB over / Paid: Splunk $150/GB/day ingestion ~ $150/GB/mo, $0.10/GB over 10GB hot to warm / Chronicle $2/GB ingestion $0.20/GB retention / Elastic $95/mo + $0.15/GB over 10GB
Documentation & Security Advisory Portal (CVE Publishing)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Docusaurus/MkDocs free self-host unlimited / GitHub Pages free 100GB bandwidth / GitBook Pro $32/mo 10k views $0.01/view over / Enterprise $399/mo unlimited views + SLA / Confluence Premium $10/user/mo $870/mo 100 users / Statuspage $29/mo 100 subscribers
DAST Scanning & Dynamic Testing (OWASP ZAP, Burp)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: ZAP OSS unlimited free, Nuclei OSS free unlimited / Pro: Burp Pro $449/user/yr one-time, unlimited scans / Enterprise: $7,999/yr incl 10 scansites $1,200/site overage + $799/agent / Invicti $15k/yr 5 sites $3k/site over / OWASP ZAP Cloud scan free infra pay
Fuzz Testing Infra (AFL++, libFuzzer, ClusterFuzzLite, OSS-Fuzz)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: AFL++/libFuzzer free unlimited runs self-host / OSS-Fuzz free for public OSS / Cheaper: Spot VMs $0.01/vCPU/hr ~ $7 per core/week, $200/mo per 20 vCPU / Paid: Mayhem $75k/yr 25 targets $2k per extra target / CI $35k/yr 10 targets / GCP private Fuzz $2k/mo for 8k CPU hrs
Vulnerability Database API & Feed Sync (NVD, OSV, VulnDB)
Persistent storage for your app’s data — users, products, orders. The single most important architectural decision for most projects.Pricing & free-tier limitsFree: NVD 50 req/s with free key, OSV unlimited, CIRCL free / Community: VulnCheck 5k calls free / Paid: VulnDB $35k/yr 1M calls incl $0.01 per call over / VulnCheck $12k/yr 100k/mo $0.10 per 1k over / GH Advisory 5k/hr free $0.01/1k after enterprise
Code Signing + HSM for Product Releases (EV Certs, AV Signatures)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Sigstore free unlimited OSS signs, self-signed free / SSL.com eSigner $50/mo 100 signs $0.50/sign over / DigiCert OV $499/yr $80/mo + Trust Manager $1,200/mo 500 signs $0.40 over / EV Token $699/yr + YubiHSM2 $650 one-time / CloudHSM $1.88/hr instance
License Scanning & SBOM Generation (CycloneDX/SPDX)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Syft/Trivy/ScanCode free unlimited OSS / GitHub dep graph free / Team: FOSSA $150/mo 5k scans $0.03/scan over / Paid: FOSSA Ent $30k/yr unlimited $300/dev over 100 / Black Duck $60k/yr includes 100 devs $500 per extra / Mend $50k/yr
Identity & Access Management (SSO/MFA for Dev Team + YubiKey)
How users sign up, log in, and are authorized. Getting roles and access control right early prevents painful rewrites.Pricing & free-tier limitsFree: Keycloak/Authentik OSS free self-host unlimited / Auth0 Free 7.5k MAU $0, then $35/mo 1k MAU / Okta Developer 100 MAU free / Paid: Okta $8/user/mo SSO + $3 MFA = $11/user total, $0 over incl / Entra P2 $9/user/mo 100 incl / Duo $6/user/mo / YubiKey 5 $55 one-time per dev
Backup & Disaster Recovery (Immutable Backups, 3-2-1-1-0)
Copies of your data so a bug, hack, or outage doesn’t become permanent loss. Cheap insurance every serious project needs.Pricing & free-tier limitsFree: Restic/Kopia OSS free unlimited, MinIO free / B2 Free 10GB, then $0.006/GB/mo + $0.01/GB download / Wasabi $6.99/TB/mo no egress overage / Veeam Community free 10 VMs / Paid: Veeam $150/socket/yr or $12/vCPU/mo, AWS Backup $0.05/GB mo + $0.02/GB restore / Rubrik $45k/yr 50TB
Metrics & Uptime Monitoring for Security Backend
Where your code actually runs and serves requests. Picking the right host affects speed, scaling, and how much ops work you do.Pricing & free-tier limitsFree: Grafana OSS + Prom + Uptime Kuma free self-host / Cloud Free 10k series, 50GB logs, 50GB traces 14d retention / Pro: $8/user/mo + $8 per 1k metrics series over 10k + $0.50/GB logs over 50GB / Datadog $15/host + $0.10/GB logs $1.70/GB 15mo retention / Overage: $0.15/1k metrics series
How this small scale security checklist works.
Each requirement below is something a small scale security build typically needs. Pick one of the four researched options — recommended, free, cheaper or paid — add your own with "Other", or skip the requirement if your project doesn't need it. Nothing is mandatory; the plan on the right tracks what you've decided so nothing gets forgotten.
Your picks are saved in this browser automatically, so you can come back anytime. Options are researched per build level and refreshed as vendors change their plans — always verify details on the provider's page before committing.