Pricing at the Speed of Thought

Find and fix exploitable vulnerabilities before release, and block attacks in real time. Simple plans that scale from a single application to the entire enterprise.

The 3-Tier IAST Pricing Model

Shift Left with the industry's only compiler-based IAST: 100% true positive rate, 0% false positives on the OWASP Benchmark.

Starter

Software & security engineers

Free Trial

Free trial · can be converted to a purchase order

Request Trial
  • 1 application per organization included
  • Full IAST runtime analysis
  • Basic CI/CD integration
  • Standard vulnerability reporting
  • Email & knowledge base support
Enterprise

Mid-market to large enterprises

Custom

Custom / unlimited applications · invoicing & PO

Contact Sales
  • Everything in Team, plus:
  • Custom / unlimited applications
  • Advanced CI/CD plugins1
  • Custom rulesets1
  • Software composition analysis1
  • Dedicated success manager
  • Priority support & custom onboarding, with SLOs (Tier 1–4) and same-business-day max response

1 Coming Soon

Waratek RASP Pricing

Shield Right against zero-days with virtual patches applied instantly at runtime.

  • Block zero-day attacks the moment they're discovered, with virtual patches applied at runtime that require no tuning, downtime, or code changes
  • Detect and block AI-driven and agentic attacks by monitoring execution intent, not signatures
  • Ensure performance without compromising on security at any stage of JVM execution
  • Remediation for Java 6+ and Microsoft .NET Core CVEs with a CVSS score ≥ 7.0
Open Source Apps

Remediate open source library CVEs

Per app/agent

Contact us for volume pricing

  • Built-in rules that automatically block common CWEs and known, active exploits
  • Remediation for open source CVEs with a CVSS score ≥ 7.0
  • Drop-in replacement for vendor patches without code changes
  • Includes open source libraries such as Log4j, JBoss EAP, BeanShell, Bouncy Castle, OWASP; app servers including Tomcat and WebLogic; and middleware such as Oracle's closed source products
Closed-Source Apps

Remediate third-party CVEs in popular apps

Per app/agent

Contact us for volume pricing

  • Built-in rules that automatically block common CWEs and known, active exploits
  • Remediation for third-party CVEs with a CVSS score ≥ 7.0
  • Optimized for popular packages like WebLogic, EBS, IBM WebSphere, and PeopleSoft
  • Drop-in replacement for vendor patches without code changes
Contact Sales

Compare IAST Plans

FeatureStarter Software & security engineersTeam Growing engineering & QA teamsEnterprise Mid-market to large enterprises
Application limit1 application per organization includedCustom / unlimited
Add-on flexibilityNoneCustom packaging
Core featuresFull IAST runtime analysis, basic CI/CD integration, standard vulnerability reportingEverything in Team + advanced CI/CD plugins1, custom rulesets1, software composition analysis1, dedicated success manager, SLO
SupportEmail and knowledge base supportPriority email, chat, custom onboarding, and SLO for Tier 1–4 with max response of same business day
Payment methodFree trial, can be converted to a purchase orderInvoicing / PO
PricingFree TrialContact Sales

Stop Chasing Vulnerabilities. Start Fixing Them.

See how Waratek's compiler-based runtime security finds 100% of exploitable vulnerabilities pre-production and blocks attacks in production.

Request a Demo