Unlimited AI red-team scans on every plan
ZeroLeaks meters seats and features, never scan volume. Testing your agents more often never costs more, so security testing can run on every pull request instead of once a quarter. Pro, Team, and Business all check out self-serve.
Compare plans
Every tier includes everything in the tier below it. The scan engine, the full probe library, and complete report evidence are in every plan from Pro upward; higher tiers add collaboration, governance, and deployment controls.
| Feature | Pro$79/mo | Team$99/seat/month | Business$999/mo | EnterpriseCustom |
|---|---|---|---|---|
| Scanning | ||||
| Scans per month | Unlimited | Unlimited | Unlimited | Unlimited |
| Prompt, endpoint & runtime scans | Included | Included | Included | Included |
| Full report evidence & remediation | Included | Included | Included | Included |
| Hardening validation | Included | Included | Included | Included |
| GitHub PR merge gates | Included | Included | Included | Included |
| PDF export & API access | Included | Included | Included | Included |
| Collaboration | ||||
| Seats | 1 | 2 minimum | 15 included | Unlimited |
| Shared workspace & roles | Not included | Included | Included | Included |
| Slack, Jira & Linear integrations | Not included | Included | Included | Included |
| Shareable report links | Not included | Included | Included | Included |
| Security & governance | ||||
| SSO / SAML | Not included | Not included | Included | Included |
| Audit logs | Not included | Not included | Included | Included |
| Data-retention controls | Not included | Not included | Included | Included |
| SCIM provisioning | Not included | Not included | Included | Included |
| Self-host / on-premise | Not included | Not included | Not included | Included |
| Compliance evidence pack | Not included | Not included | Not included | Included |
| Support | ||||
| Priority support | Not included | Not included | Included | Included |
| Dedicated support & custom SLAs | Not included | Not included | Not included | Included |
Questions about plans and billing
Are scans really unlimited on every plan?
Yes. Every paid plan includes unlimited scans. ZeroLeaks meters seats and feature access rather than scan volume, so running security testing more often never increases your bill.
Is there a free trial?
Pro includes a 14-day trial. Team and Business are available through self-serve checkout without a trial period, and Enterprise is quoted per environment.
Is there a free plan?
There is no hosted free tier. The open-source ZeroLeaks CLI and SDK are free to run with your own model provider keys, and the hosted plans add the managed attack engine, stored reports, and team features.
How does seat billing work on Team?
Team is billed per seat per month with a 2-seat minimum. Business includes 15 seats, and Enterprise seat counts are agreed as part of the contract.
Do I need to talk to sales?
Only for Enterprise. Pro, Team, and Business are all self-serve through checkout, with no demo call required before you can start testing.
Which plan do I need for CI/CD?
Pro. Every paid plan includes the GitHub App and pull-request merge gates, which block a merge when a scan finds a regression, plus scan triggering through the API in any pipeline. CI-native testing is not an upsell. Team adds shared workspaces and issue-tracker routing for the results.
Can I change plans later?
Yes. Plans can be upgraded or downgraded from workspace billing settings, and changes take effect on the next billing cycle.
What every plan tests for
Test AI applications for prompt injection, instruction hijacking, tool abuse, and multi-turn attacks before they reach production.
AI Red Teaming for LLM Apps and AgentsAutomated AI red teaming for LLM applications, agents, system prompts, retrieval flows, and tool-calling workflows.
System Prompt Extraction TestingFind whether your AI assistant leaks system prompts, hidden policies, tool schemas, retrieval instructions, or internal operating rules.
AI Agent Security TestingTest AI agents for prompt injection, unsafe tool calls, over-permissioned actions, secret exposure, and workflow boundary failures.
LLM Security Scanner for AI AppsRun automated LLM security scans for prompt injection, prompt leakage, tool abuse, model behavior regressions, and AI security reports.
