Recon
1 root domain
••• / month
For a single product or brand you need watched continuously.
Request accessPricing
No per-asset surprises and no seat counting. OsintR is priced per root domain with unlimited subdomains underneath; OscalIQ is priced per system with unlimited users.
One quick check and every figure on this page fills in. No email, no form.
OsintR
Priced per root domain. Every subdomain we find underneath it is included - because charging you more for finding more is a strange way to sell a discovery tool.
1 root domain
••• / month
For a single product or brand you need watched continuously.
Request access5 root domains
••• / month
For a portfolio: multiple brands, acquisitions, or regional domains.
Request access20 root domains
••• / month
For consultancies and MSSPs monitoring a book of clients.
Request accessMonitoring more than 20 domains, or need an on-premises deployment? Talk to us about Enterprise.
OscalIQ
Priced per system - one authorization boundary, the same unit FedRAMP uses. Users are never metered, so your team, your consultants and your 3PAO all work in it at no extra cost.
Platform
••• / system / year
Billed annually · unlimited users
Add-on modules
CMMC 2.0 / NIST 800-171 · ••• / system / year
Assess Level 1 and Level 2 against all 110 NIST 800-171 requirements, with DoD SPRS scoring, POA&M eligibility, and a machine-readable export.
DISA STIG · ••• / system / year
Import XCCDF and CKL checklists or pull straight from the STIG library, migrate answers onto new releases, map CCIs to 800-53, and export .ckl or .cklb.
Scan parsing · ••• / system / year
Import Nessus and Qualys exports and keep every scan. Each finding carries host, port, service, CVSS and CVE detail. Severity analytics roll up across systems, and any finding becomes a POA&M item or a Jira issue in one click.
Modules are enabled per workspace and can be added or removed at renewal.
Both modules are sold on their own, without the FedRAMP platform, for the organizations that only need one of them.
••• per company / year
For defense contractors pursuing CMMC without a FedRAMP authorization. Unlimited users.
Request access••• per system / year
For government programs assessing an enclave against STIGs, with no FedRAMP baseline required.
Request accessFAQ
Because per-asset billing punishes you for good discovery. Most attack surface tools count every subdomain they find as a billable asset, so the better the tool works, the more you pay - and you end up quietly hoping it finds less. We charge for the root domain and discover as much as exists underneath it.
A registrable domain such as example.com. Every subdomain found beneath it - however many - is included. If you own example.com, example.co.uk and examplecorp.com, that is three root domains.
One authorization boundary, the same unit FedRAMP itself uses. Most cloud providers have one to three. Users are not metered, so your whole compliance team, your consultants and your 3PAO can all work in it without changing the price.
Yes. CMMC and DISA STIG are both sold standalone for organizations that are not pursuing a FedRAMP authorization - a defense contractor working to 800-171, or a government program assessing an enclave against STIGs.
No. Every engagement starts with a conversation and a scoped pilot, because both products need to be pointed at your real environment to be worth anything. We will run a one-off external exposure report on your domain at no cost so you can see what OsintR finds before you commit.
By invoice, not by card. OsintR is billed at the listed monthly rate; OscalIQ is billed annually per system. Longer terms and multi-year agreements are worked out as part of the conversation.
We will run a one-off external exposure report on your domain at no cost - the same discovery OsintR does continuously. If it shows you nothing you did not already know, we will say so.
Book a free exposure report