Free for evaluation. Pro when you go to production.
The CLI is open-source and free forever. The hosted cloud is free up to the small-environment caps and scales from there with one obvious paid tier.
deadband CLI
MIT Licensed · No account required · Air-gap capable
- 8-protocol ICS/OT network discovery
- 3,600+ CISA advisory matching with KEV + EPSS enrichment
- Embedded web UI + 5 output formats (text, CSV, JSON, HTML, SARIF)
- Passive PCAP analysis + device baseline drift
- Air-gap capable · No telemetry · No license key
Hosted cloud
Run the agent on your network; we host the dashboard, advisories, and history.
Free
For evaluation, homelabs, and small environments. Hosted dashboard, no credit card.
- Hosted at app.deadband.org — no infra to manage
- 1 agent, 10 assets, 30-day history
- 20 scans/day · 1 concurrent
- All 8 protocols + CISA advisory matching
- KEV + EPSS enrichment
- Email support (best-effort)
Pro
Production scanning for one or more sites. Send logs to your own SIEM, manage limits per workspace, audit every action.
- 10 agents, 500 assets, 180-day history
- 200 scans/day · 5 concurrent
- Recurring scheduled scans
- Per-org log shipping (Axiom, more soon)
- Audit log + advisory triage workflow
- Priority email support (24h)
Enterprise
Multi-site rollouts, custom limits, dedicated support. Contact us if you have a fleet of OT networks and want a partner who actually understands ICS.
- 100+ agents, 100K+ assets, indefinite retention
- 2,000+ scans/day · 25+ concurrent
- Custom per-org limits override
- SSO + SCIM (roadmap)
- Dedicated Slack/Teams channel
- Compliance support (NIST CSF, IEC 62443, NERC CIP)
Common questions
The short answers to the questions we hear most.
Why pay when the CLI is open source?
You don't have to. The CLI is and will remain MIT-licensed; everything we ship in the binary works without an account. You pay for the hosted cloud — multi-site dashboards, scheduled scans, history, advisory triage workflow, and audit log — when running it yourself stops being the simplest option.
What's the difference between the CLI and the cloud agent?
The CLI is a self-contained scanner: you run it on a host, it produces reports. The cloud agent is a small Go binary that runs on your network, talks to app.deadband.org, executes scans on demand, and streams findings into the hosted dashboard. Same probe code underneath; different operating model.
Can I run this air-gapped?
The CLI yes — it works fully offline after the initial advisory DB update. The hosted cloud needs outbound HTTPS from the agent to app.deadband.org, so it's not for fully air-gapped environments; pick the CLI for those.
What counts as an asset?
Each unique device the agent identifies on your network. A ControlLogix chassis with five I/O cards is six assets (five modules + the controller). A standalone Modbus PLC is one. We dedupe by serial + vendor + model so re-scanning the same device doesn't double-count.
What happens at the asset cap?
New findings are rejected with a clear error and the agent backs off until you free space or upgrade. Your existing assets keep updating, and the dashboard keeps working — you just can't ingest new ones until you're under the cap. No silent dropping.
Do you offer volume pricing?
Yes — Enterprise pricing is custom and scales with sites + retention. Contact sales.
Early-access partners
Now acceptingFree Pro for early customers in exchange for monthly feedback. Not for everyone, but if you have a real OT environment and want to shape the product, talk to us.
Try it now. Pay if it earns it.
Sign up for the free tier in 30 seconds, or download the CLI and skip the account altogether.
