Pricing

On-prem dependency firewall pricing

From €5,400/yr — all features, all ecosystems, no per-seat fees.

🇪🇺 EU-based vendor Built in Denmark GDPR-native, no CLOUD Act exposure Supports NIS2 and DORA ICT risk controls

ShieldedStack is runtime enforcement, unified risk scoring, and license compliance for your software supply chain — on-premises in your environment. You hold the data. You hold the keys. You hold the audit trail.

We don't gate features behind tiers; every tier ships the complete product. What you pay for is scale, support, and the hard engineering behind air-gapped operation and customer-managed keys.

All tiers include all package ecosystems. There are no per-developer fees, no per-request charges, and no surprise overage bills.

7-day Portal evaluation. Explore package activity and policy with synthetic package activity. A separate 30-day on-premises trial lets you test your own setup.

What's in the box, on every tier

01

Inline enforcement

Two proxy modes across all package ecosystems. Run Trust-Then-Verify to inventory real usage, then flip workspaces to Verify-Then-Trust for zero-trust blocking. Allow/deny lists, severity gates, release grace periods, and a standalone scanner handle CI and air-gapped cases.

02

Unified 0-10 risk score

One score per package blending CVE severity, version age, license posture, maintainability, and repository health. Your team gets one prioritised view instead of five tools to correlate.

03

Compliance and audit, built in

License-change detection, SPDX intelligence, SBOM export in CycloneDX, full package-request audit trails, CSV/JSON exports, and Keycloak-backed SSO/SAML on day one.

What you own, always

Your data.

Scan history, alerts, package metadata, and audit logs stay in your database. We never touch it.

Your auth.

Keycloak ships with the product. SSO and SAML work on day one.

Your features.

RBAC, audit export, SBOM, license intelligence, risk scoring, proxy modes, and alerts are included everywhere.

Your retention.

You decide how long to keep history. There's no TTL we control.

Pricing tiers

All prices exclude VAT. Invoices are issued in DKK; EUR billing is available on request.

Every tier ships the complete product. You pay for scale, not features.

50 devs on Socket Business ≈ $30k/yr; ShieldedStack Starter is a flat annual price with no per-seat fees.

Single deployment

Starter

For small teams running a single production deployment who want the full dependency firewall without procurement drag.

€5,400

/ year (invoiced as 40,000 DKK)

  • 1 production installation.
  • 1 tenant with 1 workspace, unlimited projects.
  • Email support during business hours.
  • Quickstart setup is available separately.
Start free trial

Most teams land here

Standard

For mid-market organizations moving from a single security pilot into multiple workspaces across engineering teams.

From €20,000

/ year (invoiced from 150,000 DKK)

  • 1 production + 1 non-production installation.
  • 1 tenant with up to 10 workspaces for multi-team rollout.
  • Production rollout patterns and policy templates.
  • Email + chat support with 4-hour critical response.
Start free trial

Scale out

Enterprise

For multi-site companies, MSPs, consultancies, and enterprises that need isolation, rollout help, and faster support.

From €33,000

/ year (invoiced from 250,000 DKK)

  • Unlimited installations, tenants, and workspaces.
  • MSP-capable tenant isolation.
  • Compliance pack and guided rollout included.
  • 24x5 support with named engineer and 1-hour critical response.
Talk to us

Regulated and air-gapped

Sovereign

For regulated EU buyers that require air-gapped operation, mirrored intelligence feeds, customer-managed keys, and negotiated operational guarantees.

From €53,000

/ year (invoiced from 400,000 DKK)

  • Unlimited installations, including air-gapped environments.
  • Mirrored, air-gap compatible CVE feed.
  • Customer-managed encryption keys included.
  • 24x7 support, dedicated CSM, and custom SLA.
Talk to us

What you pay more for, as you move up: more installations, more tenants, more workspaces, air-gapped operation, customer-managed keys, faster response SLAs, and the engineering hours behind them. Not features. Not data access. Not auth.

Why on-prem, not SaaS?

Dependency installation is a high-trust, high-volume operation. Routing every npm install and dotnet restore through a third-party SaaS creates problems regulated buyers can't accept.

ShieldedStack is built and operated by an EU-based company in Denmark. Every license is on-premises by default. Sovereign extends that to air-gapped operation with customer-held encryption keys.

Data residency

Your dependency graph reveals architectural detail, internal package names, and procurement signals.

Build availability

On-prem keeps your pipeline running even when external metadata services are down.

CLOUD Act exposure

On-prem with customer-managed keys closes a gap SaaS providers cannot close architecturally.

Professional services and training

ShieldedStack ships with everything you need to deploy yourself. We also offer fixed-scope services for teams who want help getting it right faster.

Quickstart setup

Half-day remote session: install, first workspace, ecosystems, first policy, console walkthrough.

€2,000 (available separately)

Guided rollout

Two-day engagement across two weeks: production install, policies, CI integration, alert routing, training.

€6,700 (included with Enterprise+)

Migration

Policy mapping, CI conversion, and parallel-run validation from Snyk, Sonatype, or Dependabot.

From €5,400

Compliance pack

SIG/CAIQ/VSA responses, GDPR, NIS2, DORA, Schrems II TIA, diagrams, BCP/DR, pen test summary.

50,000 DKK (included with Enterprise+)

Training workshops

Secure dependency management and supply chain security workshops for engineering teams.

€3,350-€6,000

Named engineer hours

Policy review, incident response support, architecture questions, or roadmap input.

€335 / hour

What counts as an Installation, Tenant, and Workspace?

Installation — A deployed instance. Production, staging, and DR each count separately.

Tenant — A top-level isolation boundary. MSPs and holding companies usually need one per customer.

Workspace — A scope inside a tenant for departments, business units, product lines, or environments.

Project — A repo, application, or service inside a workspace. Projects are uncapped on every tier.

Frequently asked questions

Is there a free tier?

There is no permanent free tier. You can request a 7-day Portal evaluation with synthetic package activity, or a 30-day on-premises trial to test ShieldedStack in your own environment.

What does the Portal evaluation include?

A 7-day Portal evaluation with synthetic package activity lets you explore package decisions and policy. Choose a separate 30-day on-premises trial to test your own package-manager configuration, CI, networking, identity, private registries, or operations.

Do you charge per developer?

No. We license by Installation, Tenant, and Workspace count. Add as many developers, CI agents, and projects as you need within those limits.

Are any features locked behind higher tiers?

Only operational scale features. SSO, RBAC, audit export, all ecosystems, both proxy modes, SBOM, license detection, and all alert channels are included on every tier.

Can I run ShieldedStack in an air-gapped environment?

Yes, with the Sovereign tier. The CVE feed and risk intelligence are mirrored to a sync bundle you import on your schedule.

What support is included?

All tiers include software updates, CVE feed updates, and email support. Standard adds chat and 4-hour critical response. Enterprise adds 24x5 named engineer support. Sovereign adds 24x7 and a custom SLA.

Do I need to send any data to ShieldedStack?

Customer-operated production deployments run in your environment and do not require product telemetry or a ShieldedStack control service; outbound traffic can include CVE feed sync, which can be mirrored offline on Sovereign. The separate Portal evaluation is operated by ShieldedStack and may expose evaluation account, access, service, and synthetic activity data to us.

What ecosystems do you support?

npm, NuGet, PyPI, Maven, Go modules, Cargo, RubyGems, Dart, Composer, and Hex on every tier. See the supported ecosystems page for details.

Explore ShieldedStack.

Choose a 7-day Portal evaluation with synthetic package activity, or request a 30-day on-premises trial to test your own environment.