Start with the free CLI on your own machine. Add a managed portal when a team needs runs centralized. Layer on governance when an org needs it. Each edition builds on the one below it — nothing to migrate off.
The full secfoo CLI, self-hosted, with no account required.
secfoo run, secfoo serveEverything in Community, plus a hosted portal that centralizes runs across a team.
secfoo cloud login connects a machine with an ingest-scoped API keysecfoo run syncs to the portal automaticallysecfoo serve keep working exactly as beforeEverything in Cloud, plus the controls a security org needs to standardize on Secfoo org-wide. These are on the roadmap — talk to us if your team needs one sooner.
| Feature | Community | Cloud | Enterprise |
|---|---|---|---|
| All 8 security activities | ✓ | ✓ | ✓ |
Local dashboard (secfoo serve) | ✓ | ✓ | ✓ |
| Agent-agnostic (Claude Code, Cursor, Antigravity, Gemini CLI) | ✓ | ✓ | ✓ |
| Hosted portal & automatic run sync | — | ✓ | ✓ |
| Multi-tenant workspace & API keys | — | ✓ | ✓ |
| SSO / SAML & RBAC | — | — | Roadmap |
| On-prem / VPC deployment | — | — | Roadmap |
| Audit logging | — | — | Roadmap |
| Dedicated SLA support | — | — | Roadmap |
Community is MIT and always free. Cloud and Enterprise pricing is quote-based — reach out and we'll size it to your team.
Most teams start on Community and add Cloud once more than one person is running scans.