Pricing

Choose the exploitation intelligence your workflow needs

Start with public KEV intelligence, add enriched evidence and automation with Pro, or operationalize full telemetry and client-facing delivery with Enterprise.

$0
Free access

Public feed, CVE pages, RSS, and a JSON API key.

$599
Pro monthly

Full enrichment for one organization’s internal use.

$1,189
Annual savings

$5,999 billed yearly instead of monthly.

4
Delivery options

Live feed, RSS, JSON, and Pro API access

Start free. Upgrade when the workflow needs more evidence.

No per-seat matrix. Choose based on the intelligence depth, delivery, and licensing your team needs.

Evaluate KEVIntel

Free

$0 forever

For individuals and teams monitoring public exploited-vulnerability intelligence.

  • Public KEV feed and CVE pages
  • Free JSON API key
  • RSS feed with a registered account
  • Summary CVSS and EPSS fields
  • Aggregate sensor activity counts
  • Anonymized attacker ranks
Start free
Best for security teams

Internal security workflows

Pro

$599/month

Or $5,999/year — save $1,189

For security teams that need enriched exploited-vulnerability intelligence in their workflow.

  • Everything in Free
  • Pro API with full KEV enrichment
  • Confidence scoring and evidence links
  • Exploitation timelines
  • Full CVSS, EPSS, CWE, PoC, and scanner context
  • Sensor-observed summaries where available
  • Full attacker IPs and profiles

MSSP, MDR, and scale

Enterprise

Custom

For providers and larger teams operationalizing exploitation intelligence across systems or clients.

  • Everything in Pro
  • Full proprietary sensor telemetry
  • Attacker intelligence API and CSV export
  • Deployable WAF virtual patches
  • Signed outbound webhooks
  • Client-facing use and redistribution rights
  • Integration support and priority support
Talk to sales

Pro prices are in USD and inclusive of any applicable VAT or sales tax. Create a free account, then subscribe from your dashboard.

Choose by how you will use the intelligence

The licensing boundary is simple: Pro is for one organization’s internal workflows. Client-facing and redistributed intelligence requires Enterprise.

Monitor

Free

Track public exploited-vulnerability intelligence through the feed, RSS, and JSON.

Operationalize

Pro

Bring enriched evidence, confidence, timelines, and attacker profiles into internal VM, SOC, and CTI workflows.

Deliver at scale

Enterprise

Use raw telemetry, webhooks, virtual patches, and client-facing or redistributed intelligence.

Compare intelligence, delivery, and licensing

The important differences are evidence depth, access to proprietary telemetry, automation, and how the intelligence can be used.

Swipe horizontally to compare

Capability Free Pro Enterprise
Public KEV feed, RSS, and JSON Included Included Included
Evidence links and confidence scoring   Included Included
Exploitation timelines   Included Included
CVSS / EPSS / CWE enrichment Summary Full Full
PoC and scanner context   Full Full
Sensor-observed summaries Aggregate Included Included
Attacker Intelligence UI Anonymized Full IPs + profiles Full IPs + profiles
Attacker intelligence API / CSV     Included
Full proprietary sensor telemetry     Included
Deployable WAF rules     Included
Webhooks     Included
Client-facing use / redistribution     Included

Licensing note: Pro is for internal use by a single organization. MSSP, MDR, managed-service, client-reporting, vendor, redistribution, or other third-party use requires Enterprise.

Built for providers and operational teams at scale

Enterprise adds raw telemetry, deployable virtual patch artifacts, signed webhooks, and redistribution options on top of Pro enrichment.

Talk to sales

Raw telemetry

Per-event attacker IPs, request paths, User-Agents, and payload samples where available.

Attacker intelligence

Cross-CVE rankings, per-IP profiles, CSV export, and API delivery.

Virtual patches

Deployable ModSecurity, Cloudflare, and AWS WAF rule exports for active KEVs.

Outbound webhooks

Signed JSON delivery when new exploited vulnerabilities are first attested.

MSSP redistribution

Client-facing exploitation intelligence with licensing options for providers.

Integration support

Priority support for production automation and delivery workflows.

Looking to refer, resell, integrate, or white-label KEVIntel?

Explore partnership options for MSSPs, MDRs, consultancies, technology vendors, systems integrators, and independent consultants.

Explore partnerships →

Pricing questions

Straight answers about access, licensing, taxes, and operational use.

Can I try the API before paying?

Yes. Free includes a JSON API key with public KEV data. Create a free account to evaluate the data before upgrading.

What does Pro add over Free?

Pro adds confidence scoring, evidence links, exploitation timelines, full enrichment, PoC and scanner metadata, sensor-observed summaries where available, and integration-ready API fields for internal security workflows.

Can MSSPs use Pro for client reporting?

No. Pro is licensed for internal use by one organization. MSSP, MDR, managed-service, client-reporting, vendor, redistribution, or other third-party use requires Enterprise.

When should I choose Enterprise?

Choose Enterprise when you need full sensor telemetry, webhooks, deployable virtual patches, attacker intelligence API or CSV access, client-facing use, redistribution rights, or custom integration support.

Do virtual patches replace vendor patches?

No. Virtual patch guidance is a temporary mitigation designed to reduce exposure while remediation is underway. Apply vendor patches and official mitigations as soon as possible.

Are taxes included?

Pro prices are shown in USD and are inclusive of any applicable VAT or sales tax.

Put exploitation evidence into your workflow

Start free to inspect the data. Upgrade to Pro for enriched internal workflows, or talk to us about telemetry and client-facing delivery.

Free of charge for Ukrainian organisations.