Pricing
Pay for outcomes, not noise.
Konvu charges only for delivered work. No per-seat or per-scan fees.
Business
For teams getting started with Konvu.
$2,000/ month
Includes 500 triage verdicts per month.
- AI-powered triage with evidence
- Scanner integrations (Snyk, Semgrep, Trivy, and more)
- Slack and email notifications
- SOC 2 Type II
Month-to-month. Cancel anytime.
Enterprise
For organizations with security, deployment, or scale requirements.
Custom
Sized to your scanner volume.
Everything in Business, plus:
- Auto-remediation (auto-fix PRs)
- Push integrations and API/CLI access
- Self-hosted analysis option
- SSO, SCIM, audit logs
- Custom triage policies
- Dedicated SLA and named CSM
What you pay for
Confident triage verdict
Konvu reaches a confident verdict on a finding, backed by evidence.
Successful fix PR
EnterpriseKonvu opens a pull request that successfully fixes the vulnerability.
You only pay for work delivered. Inconclusive runs and failed PRs are free.
Key features
A full breakdown of what is included in each plan.
Business Sign up → | Enterprise Contact sales → | |
|---|---|---|
| Core platform | ||
| AI-powered triage with evidence | ||
| Reachability analysis | ||
| Exploitability analysis | ||
| Container CVE triage | ||
| Auto-remediation (auto-fix PRs) | — | |
| Virtual patching (WAF rules) | — | |
| Bug bounty reproduction | — | |
| Integrations | ||
| SAST, SCA, and container scanners (Snyk, Semgrep, Trivy, and more) | ||
| WAF integrations (ModSecurity, AWS WAF, Cloudflare) | — | |
| Cloud SCMs (GitHub, GitLab) | ||
| Slack and email notifications | ||
| Push to ticketing (Jira, ServiceNow) | — | |
| Self-managed SCMs (GitHub Enterprise Server, GitLab self-managed, Bitbucket DC, Azure DevOps Server) | — | |
| API and CLI access | — | |
| Deployment | ||
| Cloud analysis | ||
| Self-hosted analysis (details) | — | |
| BYO LLM keys | — | |
| Governance and access | ||
| SSO | — | |
| SCIM provisioning | — | |
| Custom roles and granular permissions | — | |
| Custom triage policies | — | |
| Audit logs | — | |
| Security and compliance | ||
| SOC 2 Type II | ||
| Zero LLM data retention | ||
| Support and commercial | ||
| Business-hours support | ||
| Dedicated SLA | — | |
| Named CSM | — | |
| Volume-based pricing | — | |
| Invoice billing and MSA | — | |