Pricing
Plans & pricing
Continuous security and platform engineering, priced by the two things you can actually count: cloud accounts and CI/CD pipelines. Every agreement runs for a fixed term and renews only if you say so — no card on file, nothing charges by default.
Essential
$490/mo
- 1 cloud account
- Up to 3 pipelines
- 1 production workload
Then $290/mo per additional cloud account · $95/mo per additional pipeline
Best for: One cloud account that needs findings caught before they ship
Most teams start here
Secure Delivery
$1,450/mo
- 1 cloud account
- Up to 5 pipelines
- Up to 3 production workloads
Then $290/mo per additional cloud account · $95/mo per additional pipeline
Best for: Teams shipping regularly that need security inside the pipeline
Platform
from $2,900/mo
- 2 cloud accounts
- Up to 10 pipelines
- Up to 8 production workloads
Additional accounts and pipelines are quoted with your sizing.
Best for: Multi-account estates that must evidence security, not just do it
Custom & RFP
Custom quotation
- Scoped to your estate
- Scoped to your estate
- Scoped to your estate
Additional accounts and pipelines are quoted with your sizing.
Best for: Regulated estates, multi-team delivery, and formal tenders
Compare every plan
What each tier includes, line by line. Anything marked as a module is available on any tier at the price listed under add-on modules.
Essential
Coverage and sizing
- Cloud accounts included
- 1
- CI/CD pipelines included
- 3
- Production workloads covered
- 1
- Additional cloud account
- +$290/mo
- Additional pipeline
- +$95/mo
Security in the pipeline
- Secret scanning
- ✓Included
- Dependency and SCA scanning
- ✓Included
- Infrastructure-as-code static scanning
- ✓Included
- SAST on pull request
- —Not included
- Policy gates — build fails on critical findings
- —Not included
- Threat modeling per major release
- —Not included
Dynamic and offensive testing
- DAST against staging
- —Not included
- Penetration testing
- —Not included
- Retest after remediation
- —Not included
Infrastructure as code
- IaC baseline built and maintained
- —Not included
- Drift detection and remediation
- —Not included
Cloud operations
- Monthly posture and cost report
- ✓Included
- Architecture and cost review
- —Not included
- Incident response support
- —Not included
Advisory and reporting
- Monthly review call
- —Not included
- Advisory hours included
- —Not included
- Compliance evidence pack
- Available as a module
Support and response
- Support channel
- Email
- Response target
- 2 business days
- Support hours (routine requests)
- Monday–Friday, 09:00–17:00 (UTC)
- 24/7 priority-one incident response
- Available as a module
- Availability target, systems we operate
- —Not included
Commercials
- Term
- 12 months
- Billing
- Invoiced monthly
- Renewal
- By written agreement
- Custom SLA
- —Not included
Secure Delivery
Coverage and sizing
- Cloud accounts included
- 1
- CI/CD pipelines included
- 5
- Production workloads covered
- 3
- Additional cloud account
- +$290/mo
- Additional pipeline
- +$95/mo
Security in the pipeline
- Secret scanning
- ✓Included
- Dependency and SCA scanning
- ✓Included
- Infrastructure-as-code static scanning
- ✓Included
- SAST on pull request
- ✓Included
- Policy gates — build fails on critical findings
- ✓Included
- Threat modeling per major release
- —Not included
Dynamic and offensive testing
- DAST against staging
- Monthly
- Penetration testing
- Available as a module
- Retest after remediation
- —Not included
Infrastructure as code
- IaC baseline built and maintained
- ✓Included
- Drift detection and remediation
- —Not included
Cloud operations
- Monthly posture and cost report
- ✓Included
- Architecture and cost review
- Quarterly
- Incident response support
- —Not included
Advisory and reporting
- Monthly review call
- ✓Included
- Advisory hours included
- —Not included
- Compliance evidence pack
- Available as a module
Support and response
- Support channel
- Named engineer
- Response target
- 1 business day
- Support hours (routine requests)
- Monday–Friday, 09:00–17:00 (UTC)
- 24/7 priority-one incident response
- Available as a module
- Availability target, systems we operate
- —Not included
Commercials
- Term
- 12 months
- Billing
- Invoiced monthly
- Renewal
- By written agreement
- Custom SLA
- —Not included
Platform
Coverage and sizing
- Cloud accounts included
- 2
- CI/CD pipelines included
- 10
- Production workloads covered
- 8
- Additional cloud account
- Quoted
- Additional pipeline
- Quoted
Security in the pipeline
- Secret scanning
- ✓Included
- Dependency and SCA scanning
- ✓Included
- Infrastructure-as-code static scanning
- ✓Included
- SAST on pull request
- ✓Included
- Policy gates — build fails on critical findings
- ✓Included
- Threat modeling per major release
- ✓Included
Dynamic and offensive testing
- DAST against staging
- Continuous
- Penetration testing
- Annual, 1 application
- Retest after remediation
- ✓Included
Infrastructure as code
- IaC baseline built and maintained
- ✓Included
- Drift detection and remediation
- ✓Included
Cloud operations
- Monthly posture and cost report
- ✓Included
- Architecture and cost review
- Quarterly
- Incident response support
- ✓Included
Advisory and reporting
- Monthly review call
- ✓Included
- Advisory hours included
- 8 hours/mo
- Compliance evidence pack
- ✓Included
Support and response
- Support channel
- Named engineer + escalation
- Response target
- 4 business hours · 1 hour for P1
- Support hours (routine requests)
- Monday–Friday, 09:00–17:00 (UTC)
- 24/7 priority-one incident response
- ✓Included
- Availability target, systems we operate
- 99.8%
Commercials
- Term
- 12 months
- Billing
- Invoiced monthly
- Renewal
- By written agreement
- Custom SLA
- Where agreed in writing
Custom & RFP
Coverage and sizing
- Cloud accounts included
- Scoped
- CI/CD pipelines included
- Scoped
- Production workloads covered
- Scoped
- Additional cloud account
- Quoted
- Additional pipeline
- Quoted
Security in the pipeline
- Secret scanning
- ✓Included
- Dependency and SCA scanning
- ✓Included
- Infrastructure-as-code static scanning
- ✓Included
- SAST on pull request
- ✓Included
- Policy gates — build fails on critical findings
- ✓Included
- Threat modeling per major release
- ✓Included
Dynamic and offensive testing
- DAST against staging
- Scoped
- Penetration testing
- Scoped
- Retest after remediation
- ✓Included
Infrastructure as code
- IaC baseline built and maintained
- ✓Included
- Drift detection and remediation
- ✓Included
Cloud operations
- Monthly posture and cost report
- ✓Included
- Architecture and cost review
- Scoped
- Incident response support
- ✓Included
Advisory and reporting
- Monthly review call
- ✓Included
- Advisory hours included
- Scoped
- Compliance evidence pack
- ✓Included
Support and response
- Support channel
- Per agreement
- Response target
- Per agreement
- Support hours (routine requests)
- Per agreement
- 24/7 priority-one incident response
- Where agreed in writing
- Availability target, systems we operate
- Where agreed in writing
Commercials
- Term
- Per agreement
- Billing
- Per agreement
- Renewal
- By written agreement
- Custom SLA
- Where agreed in writing
Plan detail
Essential
Continuous security scanning for a single cloud account
Security checks that run on every pull request, plus a monthly report on cloud posture and cost. Suitable for a team running one cloud account that wants findings caught in the pipeline rather than in an audit.
$490/mo
12-month agreement, invoiced monthly · USD · No custom SLA
Then $290/mo per additional cloud account · $95/mo per additional pipeline
Request an Essential quotationSubscriptions are set up by quotation and invoice, not self-serve checkout. We reply within one business day with scope and next steps.
Includes
- Secret scanning on every pull request
- Dependency and software composition (SCA) scanning
- Infrastructure-as-code static scanning
- Monthly cloud posture and cost report
- Email support during business hours, 2 business-day response target
Scope boundary
Essential covers automated scanning and reporting. Hands-on remediation, dynamic testing, and architecture work are available as modules or on a higher tier.
- SAST, DAST, or penetration testing
- Hands-on remediation of findings
- Incident response support
- Third-party tooling licences
Term and cancellation: The agreement runs for its stated term and does not renew automatically. Notice periods and early-termination terms are set out in the Subscription Terms.
Subscription terms · Terms · Refund & cancellation
Scope boundary and terms
Scope boundary
Essential covers automated scanning and reporting. Hands-on remediation, dynamic testing, and architecture work are available as modules or on a higher tier.
- SAST, DAST, or penetration testing
- Hands-on remediation of findings
- Incident response support
- Third-party tooling licences
Term and cancellation: The agreement runs for its stated term and does not renew automatically. Notice periods and early-termination terms are set out in the Subscription Terms.
Subscription terms · Terms · Refund & cancellation
Most teams start here
Secure Delivery
DevSecOps across your pipelines, with the build gated on findings
Security built into the delivery pipeline rather than bolted on afterwards: static and dynamic analysis, policy gates that fail a build on critical findings, and an infrastructure-as-code baseline we maintain. Includes a monthly review call and a quarterly architecture and cost review.
$1,450/mo
12-month agreement, invoiced monthly · USD · No custom SLA
Then $290/mo per additional cloud account · $95/mo per additional pipeline
Includes
- Everything in Essential
- Static application security testing (SAST) on every pull request
- Dynamic testing (DAST) against staging, monthly
- Policy gates — builds fail on critical findings
- Infrastructure-as-code baseline built and maintained
- Quarterly architecture and cost review, monthly review call
- Named engineer, 1 business-day response target
Scope boundary
Secure Delivery covers continuous security engineering across the agreed pipelines. Penetration testing, incident response, and migration work attach as modules.
- Penetration testing (available as a module or on Platform)
- 24/7 or out-of-hours incident coverage
- Custom SLA — available where agreed in writing
- Third-party tooling licences
Term and cancellation: The agreement runs for its stated term and does not renew automatically. Notice periods and early-termination terms are set out in the Subscription Terms.
Subscription terms · Terms · Refund & cancellation
Scope boundary and terms
Scope boundary
Secure Delivery covers continuous security engineering across the agreed pipelines. Penetration testing, incident response, and migration work attach as modules.
- Penetration testing (available as a module or on Platform)
- 24/7 or out-of-hours incident coverage
- Custom SLA — available where agreed in writing
- Third-party tooling licences
Term and cancellation: The agreement runs for its stated term and does not renew automatically. Notice periods and early-termination terms are set out in the Subscription Terms.
Subscription terms · Terms · Refund & cancellation
Platform
Multi-account platform security with annual penetration testing
For estates spanning several cloud accounts, where security has to be evidenced as well as practised. Adds penetration testing delivered by our team, threat modeling on major releases, drift detection and remediation, incident response support, and a compliance evidence pack kept current.
from $2,900/mo
12-month agreement, invoiced monthly · USD · SLA terms where agreed in writing
Additional accounts and pipelines are quoted with your sizing.
Request a Platform sizingSubscriptions are set up by quotation and invoice, not self-serve checkout. We reply within one business day with scope and next steps.
Includes
- Everything in Secure Delivery
- Annual penetration test of one in-scope application, with written report and retest
- Threat modeling ahead of every major release
- Infrastructure-as-code drift detection and remediation
- 24/7 priority-one incident response, with a one-hour response target
- 99.8% monthly availability target for the systems we operate under the agreement
- Compliance evidence pack kept current for questionnaires and due diligence
- 8 advisory hours per month
- Named engineer with escalation path, 4 business-hour response target
Scope boundary
Platform is sized to your estate in a short scoping conversation, so the monthly figure reflects your actual account and pipeline count rather than a bracket.
- Guaranteed certification or audit outcomes
- Unlimited advisory hours beyond the included allowance
- Third-party tooling licences
- Service credits — the availability figure is a target, not a warranty, unless your agreement says otherwise
Term and cancellation: The agreement runs for its stated term and does not renew automatically. Notice periods, escalation, and early-termination terms are set out in the Subscription Terms and your agreement.
Subscription terms · Terms · Refund & cancellation
Scope boundary and terms
Scope boundary
Platform is sized to your estate in a short scoping conversation, so the monthly figure reflects your actual account and pipeline count rather than a bracket.
- Guaranteed certification or audit outcomes
- Unlimited advisory hours beyond the included allowance
- Third-party tooling licences
- Service credits — the availability figure is a target, not a warranty, unless your agreement says otherwise
Term and cancellation: The agreement runs for its stated term and does not renew automatically. Notice periods, escalation, and early-termination terms are set out in the Subscription Terms and your agreement.
Subscription terms · Terms · Refund & cancellation
Custom & RFP
Sized to a formal requirement, a regulated estate, or a tender
For estates beyond the shape of the published tiers, regulated environments, multi-team delivery, and formal procurement. We respond to requests for proposal, run a sizing workshop, and return a written proposal with scope, milestones, and pricing.
Custom quotation
Term and billing schedule defined in the agreement · USD · SLA terms where agreed in writing
Additional accounts and pipelines are quoted with your sizing.
Start an RFP or sizing requestSubscriptions are set up by quotation and invoice, not self-serve checkout. We reply within one business day with scope and next steps.
Includes
- Response to a formal request for proposal or tender
- Sizing workshop covering accounts, pipelines, workloads, and frameworks in scope
- Dedicated engagement lead
- Security and privacy design reviews for in-scope systems
- SLA terms where expressly agreed in writing
- Procurement-ready documentation on request
Scope boundary
Scope, deliverables, frameworks, and any SLA terms are defined in your written proposal and agreement.
- Guaranteed certification or audit outcomes
- Unlimited change requests outside change control
Term and cancellation: Notice periods, wind-down, and termination rights are defined in your agreement and the Subscription Terms.
Subscription terms · Terms · Refund & cancellation
Scope boundary and terms
Scope boundary
Scope, deliverables, frameworks, and any SLA terms are defined in your written proposal and agreement.
- Guaranteed certification or audit outcomes
- Unlimited change requests outside change control
Term and cancellation: Notice periods, wind-down, and termination rights are defined in your agreement and the Subscription Terms.
Subscription terms · Terms · Refund & cancellation
Add-on modules
Attach any module to any tier, or buy a project module on its own. Recurring modules are invoiced with your subscription; project modules are quoted against a statement of work.
Recurring
DAST expansion
+$180/mo per application
Dynamic testing extended to an additional target application beyond the one included in your tier.
- Authenticated dynamic scanning of one additional application
- Findings triaged and raised in your tracker
- Coverage reported in your monthly report
Compliance evidence pack
+$450/mo
Evidence for customer security questionnaires and due diligence, kept current as your systems change. Included on Platform.
- Control descriptions mapped to the frameworks you nominate
- Evidence refreshed as systems and processes change
- Support answering inbound customer security questionnaires
- Describes documented practice only — not a certification or attestation
Advisory hours
$1,650 per 10-hour block
A block of senior engineering time for design reviews, planning, or hands-on help outside your tier's allowance.
- Senior cloud and security engineering time
- Design reviews, planning sessions, or hands-on remediation
- Usage reported monthly
24/7 incident response
Quoted per scope
Round-the-clock cover for priority-one incidents on Essential and Secure Delivery, where agreed in writing. Included as standard on Platform.
- 24/7 cover for priority-one incidents on the agreed systems
- Out-of-hours contact route separate from standard support
- Response target and escalation contacts named on both sides
- Routine requests continue to follow standard support hours
- Timezone overlap with your own working hours where agreed
Projects
Cloud architecture assessment
$4,900
An independent, fixed-scope review of your cloud estate producing a risk register and a prioritized roadmap. Stands alone or scopes a subscription.
- Discovery workshop (up to 4 hours)
- Architecture and cloud posture review
- Risk register ranked by likelihood and impact
- Prioritized roadmap with sequencing and rough effort estimates
- Written findings report and a follow-up review call
IaC baseline build
from $3,900
A landing zone and reusable infrastructure-as-code modules built to your standards, then maintained under a subscription.
- Landing zone design covering accounts, networking, identity, and logging
- Reusable modules with tests and documentation
- Pipeline wiring for plan, review, and apply
- Handover session with your engineers
Penetration test
Quoted per application
Application or infrastructure penetration testing delivered by our team, with a written report and a retest once fixes land.
- Scoping against the target application or environment
- Manual testing alongside tooling
- Written report with findings ranked by severity and impact
- Remediation guidance and a retest of fixed findings
Migration wave
Quoted per wave
A planned migration of a defined set of workloads, run as a wave with rollback criteria agreed before cutover.
- Workload discovery and dependency mapping
- Target design and migration runbook
- Cutover with agreed rollback criteria
- Post-migration validation and documentation
Re-architecture sprint
Quoted per scope
A time-boxed engagement to redesign a system that has outgrown its shape, delivered as a design plus a sequenced execution plan.
- Current-state analysis and constraint mapping
- Target architecture with trade-offs written down
- Sequenced execution plan with effort estimates
- Proof of concept for the highest-risk change where in scope
Custom sizing and RFP responses
Estates beyond the published tiers, regulated environments, multi-team delivery, and formal tenders are sized individually. Send us the requirement and we respond with scope, milestones, and pricing in writing.
Tell us, and the first reply is substantive
- Cloud accounts and CI/CD pipelines in scope
- Production workloads and their environments
- Frameworks you are held to, if any
- Target dates, tender deadlines, or board milestones
- Whether you need a formal proposal document or a working session first
What you get back
- A sizing workshop covering the estate and the constraints
- A written proposal with scope, milestones, and pricing
- Procurement-ready documentation on request
- SLA terms where expressly agreed in writing
Billing currency: USD. Taxes may apply and are shown on your quotation. Subscriptions run for a fixed term, are invoiced against a written agreement, and do not renew automatically — see the Subscription Terms. Card payments, where offered for a fixed-price project module, appear on your statement as FARQADCLOUD.COM. No physical goods are shipped. Support: support@farqadcloud.com · Monday–Friday, 09:00–17:00 (UTC).
Frequently asked questions
- How is a plan priced?
- Each tier includes a set number of cloud accounts and CI/CD pipelines. Beyond that, Essential and Secure Delivery meter at $290 per month for an additional cloud account and $95 per month for an additional pipeline, so you can work out your own figure before contacting us. Platform is sized in a short scoping conversation, because estates at that size vary too much for a bracket to be honest.
- Do these subscriptions renew automatically?
- No. Each agreement runs for its stated term — 12 months by default — and renewal requires written agreement from both sides. We do not keep a card on file and nothing charges by default. The full terms are in the Subscription Terms.
- How does buying work?
- You receive a written quotation and service agreement setting out the tier, unit counts, and any modules. Once approved, we invoice monthly against it. Taxes, if any, appear on the quotation. Registration and tax documents your procurement team needs are available on request from order@farqadcloud.com.
- Can we change our unit counts mid-term?
- Yes. Accounts and pipelines can be added at the published meter rate from the start of the next billing month. Reductions take effect at the next renewal point or as your agreement states, so we can staff the work reliably.
- Where should we start if the scope isn't clear?
- Start with a cloud architecture assessment. It is a standalone fixed-price engagement that produces a risk register and a prioritized roadmap, and its findings become the sizing input for a subscription — so nothing is wasted whichever way you go afterwards.
- Do you work in our timezone?
- Standard support hours are Monday–Friday, 09:00–17:00 (UTC). Extended or overlapping coverage is available as a module and is written into your agreement.
- Who owns the code and IP we pay for?
- Upon full payment you receive, by default, a licence to use the deliverables for your business; an ownership transfer is available and, when agreed, is written into the agreement. Your own pre-existing materials always remain yours, as do ours.