Aqua Security pricing guide details
Pricing Overview
Aqua Security publishes no prices, but it does publish how it charges, which is more than most vendors in its category manage. Its pricing page lists three commercial packages and gives the billing basis for two of them: Dev Security is priced by the number of code repositories, and Cloud Security by the number of workloads — EC2 instances, Fargate containers, Lambda functions and the like. The Aqua Platform, which spans both, is quote-only with no basis stated.
Separately, Aqua maintains Trivy, an open-source vulnerability scanner that is free and can be used without any commercial relationship. Many teams run Trivy on its own, and it is not a trial of the platform.
All commercial engagement runs through a trial request or a demo. There is no self-service purchase.
Plan Comparison
| Package | How it is priced | What it covers | How to buy |
|---|---|---|---|
| Trivy | Free, open source | Vulnerability scanning, usable independently of the platform | Download |
| Dev Security | By number of code repositories | Code repository discovery and scanning, container image vulnerability and risk scanning, Dynamic Threat Analysis in a sandbox, open-source health scoring, infrastructure-as-code scanning | Request a trial |
| Cloud Security | By number of workloads | Auto-discovery, inventory and risk assessment across cloud accounts, agentless workload scanning, support for AWS, Azure, GCP, Oracle and Alibaba, hundreds of configuration checks | Request a trial |
| Aqua Platform | Not published | End-to-end visibility across the software lifecycle, risk-based prioritisation, contextualised risk scoring, compliance and custom reporting, role-based access control | Get a demo |
The two published bases are genuinely different units, and which one dominates your bill depends on your shape as an engineering organisation rather than your size.
What the Pricing Basis Means for Cost
Repository count is stable; workload count is not. A team with 200 repositories has 200 repositories next quarter. A team running Fargate and Lambda may see workload counts move by an order of magnitude within a day, and a per-workload basis makes that variability a billing question. Establish how workloads are counted — peak, average, or concurrent — before signing.
The two bases can pull in opposite directions. A small team with a large sprawling cloud estate pays more for Cloud Security than its headcount suggests. A large engineering organisation with many repositories and a consolidated runtime pays more for Dev Security. Neither is inferable from the other.
Trivy changes the evaluation, not the price. Because the open-source scanner is genuinely free and independently usable, you can establish whether Aqua's scanning suits your pipeline before entering a sales process at all.
What We Cannot Tell You
We hold no source containing an Aqua price. Earlier versions of this page stated annual starting figures for Cloud Security and the Platform, along with per-team cost estimates derived from them. None of those figures appeared in any source we hold, and all have been removed rather than re-sourced. Deliberately, they are not repeated here even to correct them: a wrong figure in print gets quoted onward whatever caveat sits beside it. The basis above is what Aqua actually publishes.