Kubernetes security without the enterprise price tag
Graph-powered attack paths, vulnerability scanning, compliance, and admission control. The prices below are our published GA pricing — nothing is billed during early access. No credit card required.
Starter
For individuals and small teams evaluating Kubernetes security
No credit card required
- 10 nodes
- 2 clusters
- 5 users
- Vulnerability scanning
- Attack path analysis
- Blast radius analysis
- Graph explorer
- Identity & RBAC analysis
- Slack/webhook alerts
- PDF/JSON reports
- PSS-Baseline compliance
- PSS-Restricted compliance
Team
For teams that need compliance frameworks and room to grow
$3,500 billed annually · GA pricing
Get Started FreeFree during early access · no credit card
- 25 nodes then $10/node
- 5 clusters
- Unlimited users
Everything in Starter, plus:
- CIS Kubernetes compliance
- NSA/CISA compliance
- API access (rate-limited)
- Email support
Pro
For organizations with regulatory compliance and runtime security needs
$7,500 billed annually · GA pricing
Get Started FreeFree during early access · no credit card
- 50 nodes then $8/node
- 15 clusters
- Unlimited users
Everything in Team, plus:
- SOC 2 compliance
- HIPAA Security Rule compliance
- PCI DSS / ISO 27001 control mapping
- Admission control
- SSO/OIDC
- SIEM export
- AI security assistant
- Runtime detection (audit)
- Full API access
- Priority support
Enterprise
For large deployments, MSPs, and teams with custom requirements
- Unlimited nodes
- Unlimited clusters
- Unlimited users
Everything in Pro, plus:
- Custom Rego policies
- Runtime enforcement
- Scheduled reports
- White-label reports
- Dedicated support + SLA
- Multi-tenant / MSP support
Compare Plans
This matrix shows how plans are gated at GA. During early access, every account has every feature below — the tiers only describe what you keep free versus what becomes paid if you outgrow the free-tier limits.
| Starter | Team | Pro | Enterprise | |
|---|---|---|---|---|
| Core Security | ||||
| Vulnerability scanning | ✓ | ✓ | ✓ | ✓ |
| Attack path analysis | ✓ | ✓ | ✓ | ✓ |
| Blast radius analysis | ✓ | ✓ | ✓ | ✓ |
| Graph explorer | ✓ | ✓ | ✓ | ✓ |
| Identity & RBAC analysis | ✓ | ✓ | ✓ | ✓ |
| Slack/webhook alerts | ✓ | ✓ | ✓ | ✓ |
| PDF/JSON reports | ✓ | ✓ | ✓ | ✓ |
| Compliance | ||||
| PSS-Baseline | ✓ | ✓ | ✓ | ✓ |
| PSS-Restricted | ✓ | ✓ | ✓ | ✓ |
| CIS Kubernetes | — | ✓ | ✓ | ✓ |
| NSA/CISA | — | ✓ | ✓ | ✓ |
| SOC 2 | — | — | ✓ | ✓ |
| HIPAA Security Rule | — | — | ✓ | ✓ |
| PCI DSS / ISO 27001 control mapping | — | — | ✓ | ✓ |
| Custom Rego policies | — | — | — | ✓ |
| Platform | ||||
| API access | — | Rate-limited | Full | Full |
| Admission control | — | — | ✓ | ✓ |
| SSO/OIDC | — | — | ✓ | ✓ |
| SIEM export | — | — | ✓ | ✓ |
| AI security assistant | — | — | ✓ | ✓ |
| Runtime detection (audit) | — | — | ✓ | ✓ |
| Runtime enforcement | — | — | — | ✓ |
| Scheduled reports | — | — | — | ✓ |
| White-label reports | — | — | — | ✓ |
| Support | ||||
| Support level | Community | Priority | Dedicated + SLA | |
Frequently Asked Questions
How are nodes counted?
We count the average number of Kubernetes worker nodes reporting to Juliet over the billing period. Control plane nodes and nodes that report for less than two hours are not counted. Node count is measured hourly and averaged across the month.
Is everything really free right now?
Yes. Juliet is in early access: every account gets every feature — attack paths, admission control, runtime detection, all compliance frameworks, SSO — free, with no credit card. The tiers on this page are our published GA pricing so you can plan ahead; nothing is billed until GA.
What happens to my account when pricing goes live?
Accounts created during early access are founding accounts: they keep full-feature access free after GA, within the published free-tier limits (10 nodes, 2 clusters, 5 users). Paid plans will only ever apply if you outgrow those limits. We will give every founding account at least 60 days notice before GA pricing takes effect.
What happens if I exceed my node limit?
During early access, nothing — overage is not billed. At GA: your cluster keeps working, and overage nodes are billed at the per-node rate for your plan ($10/node for Team, $8/node for Pro) at the end of each billing cycle. You can downgrade or cap spending at any time in settings.
How long does setup take?
About five minutes to install the agent via Helm. First scan results appear within 15 minutes. Attack paths, vulnerability findings, and compliance posture populate as the graph builds.
Do you offer annual billing?
Yes, once GA pricing takes effect. Annual plans save 16% compared to monthly billing: Team is $3,500/year ($292/month equivalent) and Pro is $7,500/year ($625/month equivalent). Enterprise is custom. During early access there is nothing to bill.
We manage clusters for multiple clients. Is there a plan for us?
Yes. Juliet's multi-tenant architecture is built for MSPs and platform teams. Each client gets an isolated per-tenant Neo4j graph with its own data, while the operator team has a single management view across all clients. White-label reports are available on Enterprise. Contact us for MSP pricing.
What payment methods do you accept?
Credit card (Visa, Mastercard, Amex) for monthly and annual self-service plans. Enterprise plans can invoice via ACH, wire, or PO with net-30 terms.
Can I cancel or downgrade at any time?
Yes. Cancel or change plans any time in settings. Monthly plans stop billing at the end of the current cycle. Annual plans can be converted to monthly. We do not prorate refunds, but credit applies to remaining months.
Are there volume discounts for large deployments?
Yes. Large deployments move to custom Enterprise pricing with volume discounts, dedicated support, and an SLA. Book a call to discuss.
What data does Juliet store?
A graph representation of your cluster resources: pods, services, RBAC objects, images, SBOMs, and compliance findings. No source code, no customer application data, no application secrets. Data stays in a per-customer dedicated Neo4j instance with tenant isolation enforced on every query.
Can I self-host Juliet on-premises?
Enterprise only. Self-hosted deployments include the full platform (API, workers, Neo4j, admission controller) via Helm. Contact sales for licensing and deployment support.
How does Juliet compare to Falco, Wiz, Snyk, or Prisma Cloud?
We publish feature-by-feature comparison pages for the most common alternatives: vs Falco, vs Wiz, vs Snyk, vs Prisma Cloud, vs Kubescape, vs Trivy, and vs Tetragon.
Do you offer security documentation for the platform itself?
Enterprise customers can request architecture and security documentation under NDA. For current compliance and attestation status, contact sales.
What if I need a custom compliance framework?
Enterprise customers can author custom Rego policies and register them as a framework with its own scoring and reporting. We also take framework requests from paying customers as part of the product roadmap.
Secure your clusters in 5 minutes
Install our agent with a single Helm command. First scan results in under 15 minutes. Every feature included free during early access — no credit card required.