Free
For individuals exploring security automation.
- ✓1 workflow
- ✓Phishing Email Triage pre-built
- ✓50 runs / month
- ✓Email support
- ✓Community YAML library
Starter
For teams automating their first workflows.
- ✓Up to 3 workflows
- ✓Phishing Email Triage + Suspicious Login + Malware Hash
- ✓1,000 runs / month
- ✓Email support
- ✓Community YAML library
No credit card required · $299/mo after trial
Team
For SOC teams that need the full workflow suite.
- ✓Up to 10 workflows
- ✓All 5 live demos incl. Phishing URL Reputation
- ✓10,000 runs / month
- ✓Slack + PagerDuty webhooks
- ✓Priority email support
- ✓Custom workflow uploads via /workflows/build
No credit card required · $599/mo after trial
Business
For mature security teams with complex IR chains.
- ✓Unlimited workflows
- ✓Full library incl. Ransomware Containment IR chain
- ✓100,000 runs / month
- ✓SSO + audit log export
- ✓Dedicated onboarding
No credit card required · $999/mo after trial
FROM TEAM & BUSINESS CUSTOMERS
TEAM · $599 / MO
[need testimonial] “Our three analysts used to spend half the day triaging Slack alerts. With the Team plan we wired PagerDuty and Slack into the workflow and the workload dropped by half — without hiring.” — [need name], [need role], [need company]
BUSINESS · $999 / MO
[need testimonial] “We needed SSO, audit-log export, and an incident-response chain we could hand to our auditors without a meeting. The Business plan gave us all three in week one.” — [need name], [need role], [need company]
WHAT SECURITY TEAMS SAY
"We had three analysts and 40,000 endpoints. Every phishing email that required human investigation burned time we didn't have. Now the workflow handles the first response. Analysts step in only when the score hits 70 or above. We have time again — to actually work on the projects that matter, not just process alerts."
"The auditor asked us to show evidence that incidents were handled consistently. Before CipherRun, we'd have spent two weeks reconstructing logs from email chains. With the workflow logs, I exported the evidence package in 20 minutes. The finding wasn't about our incident response — it was about our documentation. CipherRun fixed both."
"We had the runbooks. We had the team. What we didn't have was a way to start responding at 2 AM without a human in the loop. The workflow was the difference between containing this in 12 minutes and explaining to 300 enterprise customers why their data was encrypted. We got the incident report in Slack before we even opened our laptops."
Common questions