Pricing at the Speed of Thought
Find and fix exploitable vulnerabilities before release, and block attacks in real time. Simple plans that scale from a single application to the entire enterprise.
The 3-Tier IAST Pricing Model
Shift Left with the industry's only compiler-based IAST: 100% true positive rate, 0% false positives on the OWASP Benchmark.
Software & security engineers
Free trial · can be converted to a purchase order
Request Trial- 1 application per organization included
- Full IAST runtime analysis
- Basic CI/CD integration
- Standard vulnerability reporting
- Email & knowledge base support
Growing engineering & QA teams
+$833/mo per additional app (up to 2)
Contact Sales- Everything in Starter, plus:
- 3 applications included, scale up to 5
- Team collaboration
- Jira & Slack integrations1
- SSO / SAML
- Email, chat & knowledge base support with 48-hour max response
Mid-market to large enterprises
Custom / unlimited applications · invoicing & PO
Contact Sales- Everything in Team, plus:
- Custom / unlimited applications
- Advanced CI/CD plugins1
- Custom rulesets1
- Software composition analysis1
- Dedicated success manager
- Priority support & custom onboarding, with SLOs (Tier 1–4) and same-business-day max response
1 Coming Soon
Waratek RASP Pricing
Shield Right against zero-days with virtual patches applied instantly at runtime.
- Block zero-day attacks the moment they're discovered, with virtual patches applied at runtime that require no tuning, downtime, or code changes
- Detect and block AI-driven and agentic attacks by monitoring execution intent, not signatures
- Ensure performance without compromising on security at any stage of JVM execution
- Remediation for Java 6+ and Microsoft .NET Core CVEs with a CVSS score ≥ 7.0
Remediate open source library CVEs
Contact us for volume pricing
- Built-in rules that automatically block common CWEs and known, active exploits
- Remediation for open source CVEs with a CVSS score ≥ 7.0
- Drop-in replacement for vendor patches without code changes
- Includes open source libraries such as Log4j, JBoss EAP, BeanShell, Bouncy Castle, OWASP; app servers including Tomcat and WebLogic; and middleware such as Oracle's closed source products
Remediate third-party CVEs in popular apps
Contact us for volume pricing
- Built-in rules that automatically block common CWEs and known, active exploits
- Remediation for third-party CVEs with a CVSS score ≥ 7.0
- Optimized for popular packages like WebLogic, EBS, IBM WebSphere, and PeopleSoft
- Drop-in replacement for vendor patches without code changes
Compare IAST Plans
| Feature | Starter Software & security engineers | Team Growing engineering & QA teams | Enterprise Mid-market to large enterprises |
|---|---|---|---|
| Application limit | 1 application per organization included | 3 applications per organization included (scale up to +2) | Custom / unlimited |
| Add-on flexibility | None | Purchase up to 2 additional apps | Custom packaging |
| Core features | Full IAST runtime analysis, basic CI/CD integration, standard vulnerability reporting | Everything in Starter + team collaboration, Jira/Slack integrations1, SSO/SAML | Everything in Team + advanced CI/CD plugins1, custom rulesets1, software composition analysis1, dedicated success manager, SLO |
| Support | Email and knowledge base support | Email, chat and knowledge base support with max response of 48 hours | Priority email, chat, custom onboarding, and SLO for Tier 1–4 with max response of same business day |
| Payment method | Free trial, can be converted to a purchase order | Invoicing / PO (credit card, coming soon) | Invoicing / PO |
| Pricing | Free Trial | $2,499 / month (+$833/mo per additional app) | Contact Sales |
Stop Chasing Vulnerabilities. Start Fixing Them.
See how Waratek's compiler-based runtime security finds 100% of exploitable vulnerabilities pre-production and blocks attacks in production.
Request a Demo