One plan. Flat rate. No metering.
Everything Kysira does, for every request you serve. Start in shadow mode for free — no card, no procurement cycle.
KysiraOne plan. The whole product.
$3,000/month, billed annually
$3,600/month
- Unlimited requests scored — no per-request metering
- Full OWASP coverage: SQLi, XSS, command injection, SSRF, path traversal, prompt injection, credential stuffing
- All three deployment models: reverse proxy, sidecar, or Envoy ext_proc filter
- Shadow mode and fail-open architecture by default
- Control plane with per-request verdicts, scores, and reasons
- License keys per environment or per cluster
- Role-based team access, registry access, and agent certificates
- Support from the engineers who build the proxy
Flat rate. No metering.
$3,600 per month, or $36,000 paid annually — two months free. Every attack class, every deployment model, and unlimited request volume are in the plan. We don't charge you more for being attacked more.
- Start in shadow mode. Score and log every request without blocking anything, for as long as you want, before you enforce.
- No procurement gate. Create an account, get a license key, run the container. Talk to us when you're ready to buy, not before.
- Self-hosted stays self-hosted. Run entirely inside your own infrastructure and request data never leaves your environment.
What you get out of the box
There is no feature gate and no add-on tier. Every deployment model, every attack class, and the full control plane ship with the product.
Questions about the bill
Flat rate, no metering, no procurement gate. Here is what that means in practice.
What does Kysira cost?
One plan, flat rate: $3,600 per month, or $36,000 paid annually — two months free. Unlimited request volume, every attack class, and every deployment model are included. We don't meter requests, so being attacked more doesn't cost you more.
Can I try it before I pay?
Yes. Create an account, get a license key, and run the container in shadow mode — scoring and logging every request without blocking anything. You can review exactly what Kysira would have killed on your own traffic before any money changes hands.
Does my request data leave my infrastructure?
Only if you want it to. If you run Kysira entirely inside your own infrastructure without connecting to the Kysira control plane, request data stays in your environment and is never transmitted to us. Connecting the control plane sends security telemetry — request metadata, scores, decisions, and latencies — so it can be displayed in your dashboard.
See an attack die in 40 milliseconds.
The fastest way to understand Kysira is to watch it work. No account, no sales call — the live monitor is open to anyone.