Upgrade to DefectDojo Pro

Pricing

Simple and Transparent Pricing

DefectDojo is customer-first and our pricing model reflects that ethos. Clarity and value are at the heart of what we do. We believe that every company, regardless of size or budget, should have access to the best security tools. That's why we offer both open source and enterprise editions.

Upgrade to DefectDojo Pro

Get 25% Off DefectDojo Pro

For a limited time we're offering a 25% off promotion for DefectDojo Pro. Upgrade by September 30, 2026 to take advantage of this exclusive offer.

With over 200+ supported integrations, teams can triage, deduplicate, and automate findings across their security stack.

DefectDojo Pro makes it even easier for security teams to import, customize, and scale findings across SAST, SCA, IaaS, SOC, and more.


DefectDojo’s pricing model is based on what you store for two reasons:

  1. You can cleanup data and always stay within license when necessary between budget cycles.
  2. It is the metric most closely associated with the cost to deliver services, as our auto-triage functions run over the entirety of your data.

Step 1 of 3

How many Findings do you have?*

What is considered a Finding?

A finding is what a security scanner or security tool reports. It can also be thought of as a ‘vulnerability’ or an ‘alert’. However, DefectDojo does utilize a number of consolidation machine-learning powered algorithms, so it isn’t uncommon for a tool to report 100 findings and DefectDojo turn that into 20 or less Dojo Findings.

Your Details

What is your role?*

What is your Region?*

How do you arrive at final pricing?

Why Upgrade

Everything your team needs to move faster on risk

The free tier gets you started. Pro gets you there. Here's what makes the difference when your security program starts to scale. Not sure if you're ready for Pro? Run through this quick checklist in our blog.

Automation

Use the Rules Engine to auto-triage, tag, and route findings without manual intervention.

Universal Importer

Import and match findings from all your security scans, such as SAST, DAST, SCA and more.

Compliance Reporting

Report on your team's compliance reporting for PCI-DSS, CRA, and ASVS.

Enterprise-Grade Security

Rule-Based Access Controls, like MFA, SSO, LDAP, SAML, and OAuth available right out of the box.

Metrics and Reporting

Customizable reporting views for executives, engineers, and auditors

Jira Integration

Transition from vulnerability detection to remediation with our bi-directional JIRA integration.

#### DefectDojo Features #### Free #### Pro
Core finding import & deduplication
Authentication (username, LDAP, SAML, OAuth)
Role-based access control (RBAC)
REST API & Swagger UI
Manual import & reimport
Basic dashboard & reporting
Automation (Rules Engine)
Tunable deduplication
Background imports
CLI & integrations (Snyk, SonarQube, AWS, etc.)
Universal parser (CSV/JSON)
Customizable dashboards & dark mode
Cloud-hosted option
Multi-factor authentication (MFA)
Premium support & SLAs
SOC & AppSec integration
MCP integration
Tenant isolation & encryption at rest

Trusted by Top Organizations

.svg)

.svg)

.svg)

.svg)

.svg)

Platform

Check out DefectDojo Pro