Fight AI with AI: DefectDojo Pro Is Now $100 a Month Plus 15 Cents per Finding

The build versus buy math changed this year. Enterprise-grade vulnerability management has always been priced for enterprises, and everyone else made do. A team with a small budget had one affordable option: stand up the free Community Edition, find servers for it, and give someone the job of keeping it running. Now that same team is also told an AI agent could do the triage for them, if they pay for the tokens. Neither path is as cheap as it looks. We wanted to offer a third one that is.
Starting today, DefectDojo Pro costs $100 a month plus 15 cents for every finding we process. There is no seat count or application count, and no quote or sales call between you and a running instance. Sign up, connect your scanners, and pay for what you use.
Fight AI with AI. The other side already is.
In April, Anthropic announced Claude Mythos Preview and reported that it had found thousands of high- and critical-severity vulnerabilities, including some in every major operating system and web browser. Engineers with no security training asked it for a remote code execution exploit overnight and had a working one by morning. Anthropic's own advice to defenders was to drive down the time it takes to deploy security fixes.
That capability will not stay with one company. Whatever model an attacker is running next year will find bugs faster than your team can read the reports about them, and the only response that scales is to fix everything, quickly. That takes a system that knows which of your findings are real, which are duplicates, and which are already being exploited in the wild, followed by an AI that can open the pull request.
What the Price Covers
The $100 platform fee gets you a DefectDojo Pro cloud instance with the full Pro feature set: deduplication across every scanner in your stack, EPSS and CISA KEV enrichment, risk-based prioritization, the Triage Engine, scheduled Connectors to tools like Wiz, Snyk, Tenable and CrowdStrike, SSO and granular RBAC, SLA enforcement with breach alerting, and reporting an assessor will accept. Nothing is held back for a higher tier.
The 15 cents is charged per finding processed, meaning each finding a scanner hands us that we ingest, deduplicate, enrich and track. Findings below the minimum severity you set are dropped before they are counted, so a noisy scanner does not run up your bill. You also set a monthly spend limit during sign-up, and your instance holds you to it.
Sensei, DefectDojo's AI, is billed only when you use it. A remediation pull request is $15 and a threat model is $30. Nothing for AI is baked into the base fee, so you never pay for capacity you did not touch.
Cheaper Than Running It Yourself
Community Edition is free and stays free. Running it in production is not. Add up a database, application and worker nodes, backups, upgrades, and the hours an engineer spends on all of that instead of fixing vulnerabilities, and $100 a month is less than most teams spend on the infrastructure alone. Pro also does what Community Edition does not: cross-scanner deduplication, threat intelligence enrichment, prioritization, Connectors, SSO and Sensei. We priced Pro so the paid edition is the cheaper way to run DefectDojo. We believe it is now the lowest-cost way to run an enterprise-grade vulnerability management program, and we set the price there on purpose.
Cheaper Than Doing It With Only AI
There is a newer kind of build: point a frontier model at your scanner output and let it triage. Price that before you commit to it. One finding, with enough surrounding code and history for a model to reason about, runs to thousands or tens of thousands of tokens. That buys you one finding, read once, with none of the deduplication, tracking, SLA clock or audit trail around it. Fifteen cents buys all of that for the finding, and Sensei is there when you want AI to write the fix.
Pre-Pay for a Year and Save 48% or More
If you know your volume, commit to a year and pre-pay. Savings start at 48% against pay as you go and grow with volume. Annual plans also include an allowance of Sensei usage, so remediation pull requests, repository scanning and threat models come with the plan instead of as a per-use charge. Talk to us and we will size the plan to your findings volume.
How to Start
Go to cloud.defectdojo.com, choose Pay As You Go, set your spend limit, and check out with a card. We provision your instance from there. If you would rather pre-pay for a year and take the discount, choose Pre-Pay & Save on the same screen and we will be in touch.
Winning the Asymmetrical Battle
DefectDojo exists because practitioners built it. It started in the OWASP community more than ten years ago, written by people who were drowning in scanner output and needed a way out, and every version since has been shaped by users telling us plainly what is broken and what they need next.
This pricing carries the same idea further.
Security teams are fighting in an asymmetrical battle. Often those with the most risk are rarely the ones with the biggest budgets, and the attackers picking up models like Mythos, will not check your headcount before they attack.
We want the tooling the largest security programs run, from cross-stack deduplication to prioritization to AI remediation, in the hands of every team that has findings to fix. Every team that closes its real vulnerabilities faster shrinks the attack surface the rest of us share.
Arming as many security teams with the best of breed tooling is our goal with a $100 entry price. If this pricing works for you, I want to know. If it does not, I want to hear that even more.
Greg