Every price, out in the open
Three plans, five currencies, listed as annual prices excluding tax. The plans differ in deployment and usage, not features — all 31 frameworks, reports, and SBOM are the same on every plan. Professional and Enterprise put the analysis engine (Agent) inside your network and carry an annual platform fee; Core doesn't.
Billed annually (monthly rate shown, excl. tax)
Core
Cloud only. Code is uploaded to the ForgeHelm cloud for analysis — 50 analyses and 500 AI questions a month. If your source code can't leave the building, see Professional.
- Cloud only — code is uploaded to the ForgeHelm cloud for analysis
- All 31 compliance frameworks
- Compliance summary and eight-axis risk fingerprint
- Governance dashboard
- The same AI assistant — 500 questions/mo
- No platform fee; 50 analyses/mo
- On-premises Agent
- Unlimited analyses
- Unlimited AI questions
Professional
Management platform in the cloud, Agent installed in your network. Unlimited analyses and AI assistant.
+ USD 6,000 / year platform fee (TWD 192,000)
- Hybrid deployment — source code stays on-premises
- Unlimited analyses — your CI can call the API to run them as PR checks
- Unlimited AI assistant; answers are screened for secrets before they're sent
- Platform fee includes Agent deployment and onboarding help
- AI model endpoint can point to the cloud or your own VPC
- Email support, handled on business days
Enterprise
The whole platform in your data center, or in a fully offline, air-gapped environment. Use your own AI model.
+ USD 15,000+ / year platform fee (TWD 480,000)
- Fully on-premises, or air-gapped
- Bring your own model (BYOL) with the AI Deployment Kit — Ollama/vLLM supported
- AI questions and answers never leave your network
- Offline updates delivered on physical media
- Email support; guaranteed response times can be arranged in a separate consulting agreement
Annual Subscription Formula
Annual fee = seat monthly rate × seats × 12 + platform annual fee
Example: Professional, 10 seats (TWD):NT$2,200 × 10 seats × 12 months + NT$192,000 annual platform fee = NT$456,000 total per year (excl. tax)
All prices exclude tax. Taiwan customers pay 5% VAT on top and receive a government uniform invoice; elsewhere, local tax rules apply.
Five-Currency Pricing Reference
| Currency | Core | Pro seat/mo | Pro platform/yr | Ent seat/mo | Ent platform/yr |
|---|---|---|---|---|---|
| USD | $39 | $69 | $6,000 | $119+ | $15,000+ |
| TWD | NT$1,250 | NT$2,200 | NT$192,000 | NT$3,800+ | NT$480,000+ |
| CNY | ¥280 | ¥500 | ¥43,500 | ¥860+ | ¥108,000+ |
| JPY | ¥5,850 | ¥10,350 | ¥900,000 | ¥17,850+ | ¥2,250,000+ |
| EUR | €36 | €64 | €5,580 | €110+ | €13,950+ |
All three plans have the same frameworks, reports, and modules; they differ in deployment, usage limits, and where the AI model runs. Email us to talk through which setup fits your environment.
All prices exclude tax. Taiwan customers pay 5% VAT on top and receive a government uniform invoice; elsewhere, local tax rules apply.
How we relate to other tools
| Product | Typical Pricing | Relationship to ForgeHelm |
|---|---|---|
| GitHub Advanced Security | ~$49/seat/month | Complementary: GHAS does secret scanning and deep vulnerability analysis; ForgeHelm maps those results, along with other evidence, to 31 frameworks and produces the report |
| Snyk Team / Ignite | $25–$105/seat/month | Complementary: Snyk scans packages for vulnerabilities; ForgeHelm adds on-premises deployment and multi-framework compliance mapping |
| SonarQube Enterprise | $40K–$70K/year | Complementary: SonarQube covers code quality; ForgeHelm adds compliance mapping, six-language reports, and per-seat pricing |
| Vanta (GRC) | $7,500+/year platform + seats | Complementary: Vanta manages policies, people, and processes; ForgeHelm supplies code-level compliance evidence that can be exported to a GRC platform |
| Checkmarx | $50K–$120K/year | Different purpose: Checkmarx is a source-code vulnerability scanning (SAST) tool. ForgeHelm does not do that — it maps scan and configuration results to 31 frameworks and produces the evidence auditors ask for. In practice the two usually sit alongside each other. |
Enterprise TCO starting estimate (10 seats)
ForgeHelm Enterprise
- Subscription: $119 × 10 × 12 + $15,000 platform fee = $29,280/year (starting price)
- GPU depreciation (only if you opt for a private AI model): $2,000–$10,000/year
- Open-source model license: $0
Total: about $31,280–$39,280/year (roughly NT$1.0M–1.26M), before tax and consulting hours
The figures above are ForgeHelm's own cost structure, not a price comparison with other tools — ForgeHelm does not replace a source-code vulnerability scanning (SAST) tool, and the two budgets usually coexist rather than compete.
Plan Comparison
| Feature | Core | Professional | Enterprise |
|---|---|---|---|
| Deployment | Cloud only (SaaS) | Hybrid | On-prem / Air-gap |
| Compliance frameworks | All 31 | All 31 | All 31 |
| Analyses per month | 50 | Unlimited | Unlimited |
| SBOM | ✓ | ✓ | ✓ |
| AI ChatBot | 500 questions/mo | Unlimited | Unlimited (bring your own model) |
| Report languages | 6 | 6 | 6 |
| Tech stack migration | ✓ | ✓ | ✓ |
| Support | Email (business days) | Email (business days) | Email (business days) |
| Audit log export (CSV/API) | ✓ | ✓ | ✓ |
| Data quality analysis | ✓ | ✓ | ✓ |
Enterprise Procurement FAQ
What does the PoC process look like?
A scoped two-week proof of concept (PoC): you pick a representative repository, and we set up the Agent inside your network, run a compliance scan, and deliver the report. Code stays in your environment the entire time. Details and fees are explained when you apply.
Can we pay monthly instead of annually?
Listed prices are annual. Where monthly billing is offered, seat fees typically run about 20% higher than annual. Enterprise is usually an annual contract with custom payment terms.
What does the security review process involve?
We provide architecture documentation, data flow diagrams, a penetration test summary, and the role-based access control (RBAC) specification; standard vendor security questionnaires can usually be returned within five business days. The sub-processor list is available on request by email.
Is the platform fee separate from seat fees?
Yes. The platform fee covers deploying the Agent inside your network and getting it running; features don't vary by plan, and Core has no platform fee. Implementation consulting — turning audit requirements into rules and documenting them — is billed separately by the hour.
Can we expand seats mid-contract?
Yes. Seats added during the contract term are prorated for the remaining period; seat reductions take effect at the next renewal.
How is support provided?
Support runs over email, answered on business days. If you need guaranteed response times or dedicated staffing, we can set that out in a consulting agreement.
Is there a free plan?
Yes. The free tier is free forever, no credit card: 1 seat, 3 analyses a month, 20 AI questions, with code upload, analysis and online viewing of the full report and scores. Online self-service sign-up is not open yet; until it is, contact us and we will walk you through it live. Upgrade to a paid plan when you need report export, higher volume, or the analysis engine inside your own network.
Free tier, demo, or PoC — which should I choose?
If you want to try it yourself and your code can be scanned in the cloud, start with the free tier. If you want to understand the product in 30 minutes, book a demo and we'll walk you through it. If source code can't leave your network, you need to validate in your own environment, or you're going through procurement, request a two-week proof of concept (PoC).
What counts as a "seat", and can seats be reassigned?
A seat is one account that can sign in to the platform, regardless of role — if someone needs to log in to read a report, that's a seat. Seats can be reassigned during the contract term: deactivate the original account and assign the seat to a new team member, with the total unchanged. There is no separate, cheaper read-only seat at present.
How many projects can one subscription cover?
There is no limit on projects. A single tenant can hold as many projects as you need, each scanned and reported on separately. If you are a systems integrator or consultancy and want to serve several client organisations from one subscription, write to us first so we can confirm the licensing.
We only need one of the frameworks. Is that cheaper?
No — and it isn't more expensive either. Frameworks are not a licensing dimension: every scan on every plan evaluates all 24, with nothing to select up front and no module to buy separately.
Public-sector specifications say "source code testing" or "Fortify or equivalent". Does ForgeHelm qualify?
It depends on what that clause actually requires, and we would rather be specific than vague. ForgeHelm produces code-level compliance reports: a framework coverage matrix, findings pinned to file and line, an SBOM, and an audit trail of scans and exports — all usable as attachments to an acceptance record for an outsourced system. The 31 built-in frameworks include ISO 27001, NIST CSF, CIS Controls, OWASP Top 10 and Taiwan's Personal Data Protection Act, but not Taiwan's Cyber Security Management Act itself, CNS 27001, or the Government Configuration Baseline (GCB). If the specification calls for a deep vulnerability scanning (SAST) tool or a test report issued by an accredited laboratory, that is not ForgeHelm's role. Send us the clauses and we will tell you point by point which ones we meet and which we do not.
Ready to start?
Book a 30-minute demo, or request a two-week proof of concept (PoC).