Simple Pricing.
No Surprises.

Start free with no commitment. Upgrade when you need more scans, PDF reports, private repos, or team and consultant workflows. Cancel any time.

MonthlyAnnualSave up to 20%
Free

For trying Strata

$0/month

For trying Strata and running limited assessments. No credit card required — start immediately.

Start Free
  • 1 scan per day
  • Android APK + iOS IPA
  • Public repository scanning
  • OWASP mapping + JSON export
  • 1 project · 30-day history
  • PDF report export
  • Private repository scanning
  • Team members
  • Scheduled assessments
  • API access
Team

For consultants & security teams

$99/month

For security consultants, boutique security firms, AppSec teams, and development teams that need collaboration, CI/CD, scheduled assessments, and client-ready reporting.

Start Team →or Request Demo
  • Unlimited scans
  • APK · IPA · GitHub · GitLab · ZIP
  • Public + private repository scanning
  • PDF + JSON export
  • Advanced reporting + white-label PDFs
  • Unlimited projects + unlimited history
  • Unlimited team members
  • Scheduled assessments (daily / weekly / monthly)
  • CI/CD webhook integration
  • REST API access
  • Priority processing + SLA
FeatureFreeProTeam
Scanning
Daily scans1Unlimited
Android APK
iOS IPA
Public repository (GitHub / GitLab)
Private repository
ZIP source upload
Scheduled assessments
CI/CD webhook integration
Analysis
OWASP Mobile M1–M10
OWASP Web A1–A10
Secret / credential detection
Dependency CVE (OSV)
SAST code analysis
Reporting
JSON export
PDF report export
Advanced reporting (OWASP + CWE, exec summary)
White-label PDF reports
Scan history30 daysUnlimited
Collaboration
Projects1Unlimited
Team members1Unlimited
REST API access
Support
Processing priorityStandardPriority
Support tierCommunityPriority + SLA

Coming for Enterprise

The following features are in development for the Enterprise tier. No pricing yet — join the waitlist to be notified when it launches, or contact us if you need these capabilities now.

Coming Soon
🕒

Pipeline History

View and compare scan results across build runs. Track security posture per branch over time.

Coming Soon
🚫

Security Gates

Block builds or fail CI jobs automatically when findings exceed configured severity thresholds.

Coming Soon
🔒

Branch Protection

Require passing security assessments before pull requests can merge. Integrates with GitHub and GitLab.

Coming Soon
🔀

PR Scanning

Automatically scan new code on every pull request, before it is reviewed or merged.

Coming Soon
📊

SARIF Uploads

Import results from external SAST tools in SARIF format to consolidate findings in one place.

Coming Soon
📦

SBOM Generation

Generate a software bill of materials for your applications. Supports CycloneDX and SPDX formats.

Coming Soon
🔗

Dependency Review

Detailed analysis of third-party dependencies — known vulnerabilities, license risk, and update recommendations.

Coming Soon
🏗️

IaC Scanning

Assess Terraform, CloudFormation, and Kubernetes manifests for security misconfigurations.

Pricing FAQ

Yes — the Team plan is designed with security consultants in mind. You can manage multiple client projects, schedule recurring assessments, and export white-label PDF reports for client delivery. Many security consultants and boutique security firms use Strata to run mobile app and repository assessments as part of professional engagements.
Yes, as long as you have written authorization from the app owner. Strata Security is a professional assessment tool. You are responsible for ensuring you have permission to assess any application, repository, or codebase you submit. See our Terms of Service for details.
Yes. Only upload binaries, source code, or repository links that you own or have explicit authorization to test. Uploading third-party apps without permission may violate applicable laws and our Terms of Service. This is the same standard that applies to professional penetration testing engagements.
Yes. Cancel any time from your billing settings. Your plan stays active until the end of the current billing period. You won't be charged again after cancellation.
The Free plan gives you 1 scan per day with full OWASP mapping and JSON export, covering Android APKs, iOS IPAs, and public GitHub or GitLab repositories. No credit card required and no time limit — it stays free as long as you stay within those limits. PDF reports, private repository scanning, and team features require a paid plan.
The Enterprise tier is on the roadmap. Planned features include pipeline scan history, security gates with CI/CD policy enforcement, branch protection rules, PR-level scanning, SARIF uploads for consolidating external tool results, SBOM generation, dependency review, and IaC scanning. Join the waitlist to be notified when it launches.

Evaluating Strata for a security-conscious purchase? See how we handle your data on the Security page.

See Strata in action

Watch a walkthrough of the platform — from upload to full security report.

Demo video coming soon

Get a personalized walkthrough of Strata — we will cover your specific workflow live.

Request a Demo →

No Credit Card.
No Commitment.

Create your free account and run your first scan in under 2 minutes. Upgrade or cancel any time.