Kubernetes security without the enterprise price tag
Graph-powered attack paths, vulnerability scanning, compliance, and admission control. Start free, upgrade when you need to. No credit card required.
Starter
For individuals and small teams evaluating Kubernetes security
No credit card required
- 5 nodes
- 1 cluster
- 5 users
- Vulnerability scanning
- Attack path analysis
- Blast radius analysis
- Graph explorer
- Identity & RBAC analysis
- Slack/webhook alerts
- PDF/JSON reports
- PSS-Baseline compliance
- PSS-Restricted compliance
Team
For teams that need compliance frameworks and room to grow
$3,500 billed annually
Start Free TrialNo credit card required
- 25 nodes then $10/node
- 5 clusters
- Unlimited users
Everything in Starter, plus:
- CIS Kubernetes compliance
- NSA/CISA compliance
- API access (rate-limited)
- Email support
Pro
For organizations with regulatory compliance and runtime security needs
$7,500 billed annually
Start Free TrialNo credit card required
- 50 nodes then $8/node
- 15 clusters
- Unlimited users
Everything in Team, plus:
- SOC 2 compliance
- PCI DSS / HIPAA / ISO 27001 control mapping
- Admission control
- SSO/OIDC
- SIEM export
- AI security assistant
- Runtime detection (audit)
- Full API access
- Priority support
Enterprise
For large deployments, MSPs, and teams with custom requirements
- Unlimited nodes
- Unlimited clusters
- Unlimited users
Everything in Pro, plus:
- Custom Rego policies
- Runtime enforcement
- Scheduled reports
- White-label reports
- Dedicated support + SLA
- Multi-tenant / MSP support
Compare Plans
Every plan includes the full security scanning engine. Higher tiers add compliance frameworks, integrations, and runtime capabilities.
| Starter | Team | Pro | Enterprise | |
|---|---|---|---|---|
| Core Security | ||||
| Vulnerability scanning | ✓ | ✓ | ✓ | ✓ |
| Attack path analysis | ✓ | ✓ | ✓ | ✓ |
| Blast radius analysis | ✓ | ✓ | ✓ | ✓ |
| Graph explorer | ✓ | ✓ | ✓ | ✓ |
| Identity & RBAC analysis | ✓ | ✓ | ✓ | ✓ |
| Slack/webhook alerts | ✓ | ✓ | ✓ | ✓ |
| PDF/JSON reports | ✓ | ✓ | ✓ | ✓ |
| Compliance | ||||
| PSS-Baseline | ✓ | ✓ | ✓ | ✓ |
| PSS-Restricted | ✓ | ✓ | ✓ | ✓ |
| CIS Kubernetes | — | ✓ | ✓ | ✓ |
| NSA/CISA | — | ✓ | ✓ | ✓ |
| SOC 2 | — | — | ✓ | ✓ |
| PCI DSS / HIPAA / ISO 27001 control mapping | — | — | ✓ | ✓ |
| Custom Rego policies | — | — | — | ✓ |
| Platform | ||||
| API access | — | Rate-limited | Full | Full |
| Admission control | — | — | ✓ | ✓ |
| SSO/OIDC | — | — | ✓ | ✓ |
| SIEM export | — | — | ✓ | ✓ |
| AI security assistant | — | — | ✓ | ✓ |
| Runtime detection (audit) | — | — | ✓ | ✓ |
| Runtime enforcement | — | — | — | ✓ |
| Scheduled reports | — | — | — | ✓ |
| White-label reports | — | — | — | ✓ |
| Support | ||||
| Support level | Community | Priority | Dedicated + SLA | |
Frequently Asked Questions
How are nodes counted?
We count the average number of Kubernetes worker nodes reporting to Juliet over the billing period. Control plane nodes and nodes that report for less than two hours are not counted. Node count is measured hourly and averaged across the month.
Can I try paid features before upgrading?
Yes. Team and Pro plans include a 30-day free trial with full access to all features in that tier. No credit card required. After the trial, you can stay on the free Starter tier or pick a paid plan.
What happens if I exceed my node limit?
Your cluster keeps working. Overage nodes are billed at the per-node rate for your plan ($10/node for Team, $8/node for Pro) at the end of each billing cycle. You can downgrade or cap spending at any time in settings.
How long does setup take?
About five minutes to install the agent via Helm. First scan results appear within 15 minutes. Attack paths, vulnerability findings, and compliance posture populate as the graph builds.
Do you offer annual billing?
Yes. Annual plans save 16% compared to monthly billing. Team is $3,500/year ($292/month equivalent) and Pro is $7,500/year ($625/month equivalent). Enterprise is custom.
We manage clusters for multiple clients. Is there a plan for us?
Yes. Juliet's multi-tenant architecture is built for MSPs and platform teams. Each client gets an isolated per-tenant Neo4j graph with its own data, while the operator team has a single management view across all clients. White-label reports are available on Enterprise. Contact us for MSP pricing.
What payment methods do you accept?
Credit card (Visa, Mastercard, Amex) for monthly and annual self-service plans. Enterprise plans can invoice via ACH, wire, or PO with net-30 terms.
Can I cancel or downgrade at any time?
Yes. Cancel or change plans any time in settings. Monthly plans stop billing at the end of the current cycle. Annual plans can be converted to monthly. We do not prorate refunds, but credit applies to remaining months.
Are there volume discounts for large deployments?
Yes. Large deployments move to custom Enterprise pricing with volume discounts, dedicated support, and an SLA. Book a call to discuss.
What data does Juliet store?
A graph representation of your cluster resources: pods, services, RBAC objects, images, SBOMs, and compliance findings. No source code, no customer application data, no application secrets. Data stays in a per-customer dedicated Neo4j instance with tenant isolation enforced on every query.
Can I self-host Juliet on-premises?
Enterprise only. Self-hosted deployments include the full platform (API, workers, Neo4j, admission controller) via Helm. Contact sales for licensing and deployment support.
How does Juliet compare to Falco, Wiz, Snyk, or Prisma Cloud?
We publish feature-by-feature comparison pages for the most common alternatives: vs Falco, vs Wiz, vs Snyk, vs Prisma Cloud, vs Kubescape, vs Trivy, and vs Tetragon.
Do you offer security documentation for the platform itself?
Enterprise customers can request architecture and security documentation under NDA. For current compliance and attestation status, contact sales.
What if I need a custom compliance framework?
Enterprise customers can author custom Rego policies and register them as a framework with its own scoring and reporting. We also take framework requests from paying customers as part of the product roadmap.
Secure your clusters in 5 minutes
Install our agent with a single Helm command. First scan results in under 15 minutes. No credit card required.