Mend.io product pricing

The Mend application security platform

Mend Renovate

Automated dependency updates

Mend SCA

Automated detection, prioritization and remediation for open source packages

Mend Container

Automated detection, prioritization and remediation for container-based applications

Mend SAST

Automated detection, prioritization and remediation for custom code

Mend Renovate

Automated dependency updates

Starting at

$25,000

100 developers • per year

Get a demo
Dedicated support
Automated dependency updates
Full-scale automation
Merge confidence
Smart merge control

Mend SCA

Automated detection, prioritization and remediation for open source packages

Starting at

$18,000

25 developers • per year

Get a demo
Open source vulnerability & license management with custom policies
Detection, blocking, and alerting of malicious open source packages
Includes Mend Renovate for automated remediation
Dashboards, alerts, reporting and SBOM management
IDE, repo, pipeline and issue tracker integrations
Pre-built and custom policies
Reachability path analysis
Containers support

Mend Container

Automated detection, prioritization and remediation for container-based applications

Starting at

$15,000

100 developers • per year

Get a demo
Container-specific open source vulnerabilities and remediations
Advanced prioritization based on CVE reachability analysis
Secrets detection
Runtime analysis information
Kubernetes integration
Pricing applies as an SCA add-on

Mend SAST

Automated detection, prioritization and remediation for custom code

Starting at

$18,000

25 developers • per year

Get a demo
Custom code source vulnerability management
Dashboards, alerts and reports
Source code repo, pipeline and issue tracker integrations
Pre-built and custom policies
Automated remediation

Mend.io is trusted by

FAQ

What is a contributing developer?

“Contributing Developer” means any employee or contractor who during the term of the agreement accesses or uses the Mend application or any engineer, developer or other person that writes, develops or modifies the Customer’s, or Customer’s affiliate’s, code being scanned or monitored by the Mend application. For the avoidance of doubt, the same individual will not be counted more than once even if acting in two separate roles such as a developer and platform user.

Why are you pricing per contributing developer?

Mend.io automates and manages open source components throughout the Software Development Life Cycle (SDLC). Therefore, pricing based on the number of Contributing Developers best reflects the impact of our solution, without limiting you on factors such as size of code or number of scans.

Is pricing per user available?

No. The number of portal users does not reflect the work that is actually being performed in order to support these developers. We find that many organizations can even manage their open source usage with a limited number of portal users, for example by leveraging our APIs and consuming our data outside the web portal.

Does the above pricing include all vulnerability sources?

Yes. The Mend.io offering includes the full extent of our database, which supports over 200 programming languages. We aggregate vulnerabilities from the NVD, dozens of security advisories, and popular open source projects issue trackers to make sure you’re always covered.

Are there additional fees per GB?

No. We take pride in offering transparent, simple, and predictable pricing. We price per Contributing Developer since we know managers have better visibility into the growth of their headcount rather than the size of their software or lines of code.