The Rapid Assessment is the core offer — a fixed-scope, two-week PCI DSS 12.3.3 cryptographic inventory plus a QSA-ready evidence pack. The free scanner and public registry are the on-ramp, not the product. No quote-only games.
For teams · the core offer
↓ Preview a sample Evidence Report
regulated mid-market · banks · healthcare · defense contractors
F500 AppSec / GRC programs
For practitioners · the on-ramp
The free scanner and public registry are how teams discover CipherM — not the revenue. Pro is on the waitlist while we stay focused on assessments, and the $99/mo team tier is deliberately parked until there are champions inside larger orgs to push it through procurement.
OSS maintainers · students · solo developers
security engineers · freelancers · internal champions
Is cipherm-scan really Apache-2.0?
Yes. The CLI scanner is OSS forever. The detection ruleset (rules/) is also Apache-2.0. The registry, hosted dashboard, Audit Pack, and continuous-monitoring pieces are proprietary.
What's a Rapid Assessment, exactly?
A 2-week fixed-scope engagement. We run the scanner across your code and configs and manually review your TLS, cert, and cloud KMS posture. We deliver a CycloneDX 1.6 CBOM, executive summary PDF, compliance matrix per standard, and a prioritized migration playbook. One founder call per week during the engagement.
When is Enterprise actually available?
Year 2 (2027). Pre-traction we don't run a 6-12 month enterprise sales cycle. The Rapid Assessment is the bridge — if it goes well it converts to a multi-year Enterprise contract.
Why no $99/mo team tier?
Mid-market tiers compete with both extremes and dilute the message. Open captures distribution. Pro captures internal champions. Rapid Assessment captures regulated mid-market. The middle returns once we have champions to push procurement.
Do I need a domain to use the CLI?
No. cipherm-scan runs locally and emits CycloneDX JSON. The registry is one upload destination among many — your CBOM is yours.
What about students and OSS maintainers?
Open tier covers you forever. If you're maintaining a popular OSS project and want a verified CipherM-scanned badge for your README, email founder@cipherm.io.