Simple, transparent pricing
Free visibility forever. Every paid plan starts with a 30-day free trial — full enforcement, no credit card required. After the trial, pay per device per month. Cancel anytime.
- ✓ Unlimited devices
- ✓ Flow visibility (macOS + Linux)
- ✓ Command operator dashboard
- ✓ Device inventory & topology
- ✓ Prometheus metrics
- ✓ Grafana dashboards
- ✓ Community knowledge base
- — Enforcement (Team/Pro)
- — L7 firewall
- — Honeyport decoys
- — Email support
- Everything in Free, plus:
- ✓ L3/L4 enforcement
- ✓ Policy-as-code (JSON + CLI)
- ✓ Email support
- ✓ Up to 50 devices
- — L7 firewall
- — Honeyport decoys
- — Webhook automation
- — Terraform provider
- — Policy snapshots & rollback
- — Process-level enforcement
- — JIT access + MFA
- Everything in Team, plus:
- ✓ Full L3/L4 enforcement
- ✓ L7 firewall (TLS, URL, SNI)
- ✓ Honeyport decoy listeners + alerts
- ✓ Policy-as-code (JSON + CLI)
- ✓ Terraform provider
- ✓ Webhook automation
- ✓ Policy snapshots & rollback
- ✓ Standard email support
- — Process-level enforcement
- — JIT access + MFA
- — MSSP multi-tenancy
- — Threat intelligence feeds
- Everything in Pro, plus:
- ✓ Process-level enforcement (kernel probes)
- ✓ JIT access with MFA (TOTP, Duo, OIDC, RADIUS)
- ✓ MSSP multi-tenancy (parent/child accounts)
- ✓ STIX/TAXII threat intelligence feeds
- ✓ Premium support planning
- ✓ Priority support queue planning
- ✓ Quarterly reporting planning
- ✓ Guided onboarding
- ✓ Custom integrations
Frequently Asked Questions
Is the free tier really free? What's the catch?
No catch. The free tier includes unlimited devices with full flow visibility, Command dashboard, Prometheus metrics, and Grafana dashboards — forever. Enforcement and advanced security controls (L3/L4/L7 filtering, process-level enforcement, JIT access) require a Team, Pro, or Enterprise plan. We want you to see the value of full network visibility before you pay for enforcement.
Is there a free trial for the paid plans?
Yes. Team and Pro plans include a 30-day free trial with full enforcement — no credit card required. Deploy the Core, enroll your devices, and test L3/L4/L7 enforcement, honeyports, and policy-as-code for 30 days. After the trial, enforcement gracefully degrades to visibility-only mode. You can purchase a license at any time during or after the trial to keep enforcement active.
What counts as a "device" for Team and Pro pricing?
A device is any endpoint running the PacketSpear Node agent — a Linux server, a macOS laptop, or any machine enrolled in PacketSpear. You're only billed for devices with enforcement enabled. Visibility-only devices on the free tier don't count toward your paid device count. Team plans are capped at 50 devices; Pro and Enterprise have no device limit.
Can I switch between plans?
Yes. You can start with Free, upgrade to Team for enforcement on up to 50 devices, or go to Pro for unlimited devices with honeyports and webhooks. Enterprise adds advanced controls and SLA support. Downgrading removes enforcement capabilities but preserves visibility. Your data stays on your infrastructure throughout.
Does PacketSpear send my network data to a cloud?
No. PacketSpear is self-hosted. Your flow data, policies, device inventory, and audit logs stay on your own PostgreSQL database. The only external communication is an optional entitlement check that transmits an anonymous install ID, software version, and device count — no flow data, device names, IPs, or topology ever leaves your infrastructure.
What happens if my plan changes?
Enforcement features gracefully degrade to visibility-only mode. Your flow monitoring, Command dashboard, and metrics continue to work. No traffic is ever dropped due to plan state — only enforcement actions are disabled. You'll never lose visibility.
Does PacketSpear work on macOS?
Yes. PacketSpear Node runs on macOS with full flow visibility — collecting flow data, reporting heartbeats, and appearing in Command. Enforcement on macOS uses the native Network Extension framework (same feature set as Linux and Windows). In environments where kernel extensions aren't available, enforcement safely degrades to visibility mode — no kernel panics, no broken networking.
Which platforms does PacketSpear support?
PacketSpear runs on Linux, Windows (day zero), and macOS. All platforms receive the same feature set — L3/L4/L7 enforcement, process-level kernel probes, and JIT access — delivered through each platform's native security frameworks. Feature parity across every endpoint is core to our architecture. iOS and Android support is on the roadmap.
How does support work?
Free tier: Self-service knowledge base. Pro tier: Email support planning. Enterprise tier: priority support queue planning. Response targets remain draft/private-beta planning items until legal and business review is complete.