← The Nobody Is Clean Challenge
Tier appendix
The challenge grants the tiers and features generally available on the start date, at the capacity limits published then. This page is that record — captured on the day, from each source separately, and content-hashed so a later edit is detectable.
The hash covers the captured facts below — every source, every tier, every feature, every limit and every disagreement — but not the capture timestamp or the operator, so re-running the capture on the same data reproduces the same digest. If any of those facts is ever edited, the hash stops matching.
Do not take our word for it — download the artifact and recompute the digest: take the JSON, keep only schema_version, sources, slug_union, slugs_missing_by_source and disagreements (in that order, dropping captured_at, captured_by and content_hash), serialise it compactly with no spaces, escape < > & as \u003c \u003e \u0026 (Go’s encoding/json default), and take the SHA-256. It must equal the hash above.
Corrected after this snapshot was taken
This snapshot was captured at 2026-08-20T07:23:22Z. Later the same day we audited the Enterprise feature list against the shipped code and corrected three claims the product did not substantiate. The record below is not edited — it is what the plans said at the moment of capture, and its hash still verifies. This notice is added by the page so you can see both.
What you are granted is not reduced by these three corrections. Where the capture and the correction differ, the reading more favourable to you governs — the same rule this page applies to disagreements between our own sources. We are telling you which lines we no longer stand behind so that nothing you were shown is quietly withdrawn.
| Claim as captured | Correction | Why |
|---|---|---|
| Air-gapped mode (zero egress) | REMOVED from the Enterprise plan | An air-gapped mode exists and genuinely suppresses outbound traffic, but in that mode local disk is the only output channel and it is provisioned as an ephemeral volume, so scan results do not survive a restart. We could not stand behind “zero egress” as a delivered capability. (#752) |
| BYOK encryption with key rotation | narrowed to “BYOK encryption — your AWS KMS, GCP KMS or Vault key (on-prem scanners)” | BYOK is real — you supply the key. The rotation half was not: the agent publishes a rotation slot and logs that it is active while nothing re-encrypts under the new key. Naming the three key providers that exist also avoids implying an Azure Key Vault provider we have not built. (#750) |
| Zero-knowledge encryption | scoped to “Zero-knowledge encryption for on-prem scanner findings (opt-in — you hold the key)” | Real for the two customer-hosted scanners, and it is opt-in rather than on by default. It cannot apply to agentless cloud scanning, where the platform necessarily holds and uses your cloud credentials in order to scan on your behalf. (#153) |
Not generally available on the start date — not part of the grant
The capture also lists a feature that did not exist on the start date, and on that date our documentation described further lines that the hosted service did not have. The challenge grants the tiers and features generally available and documented on the start date, and excludes roadmap features not yet generally available; this appendix is the record of what those were. A line that was documented but not generally available does not meet that test. None of the lines below was generally available on the start date, and none is part of the grant. The favourable-reading rule above does not change that: it settles a line that had two true readings on the start date, and these had none. As above, the record is not edited and its hash still verifies. Each documented line is quoted as it read on the start date, with the page it appeared on.
| Claim as captured, or as documented | Correction | Why |
|---|---|---|
| Custom data residency (US, EU, APAC) | EXCLUDED: not generally available on the start date, so not part of the grant | No choice of storage region existed on the start date, and none exists today: the hosted service's databases were and are in Google Cloud us-central1, and no workspace can be stored in the EU or APAC. Residency in those regions is a roadmap feature, and the challenge terms exclude roadmap features not yet generally available. EU and APAC residency remains planned and is not available on any plan. Found and annotated on 2026-09-24. (#597) |
| For organizations that need infrastructure isolation without managing it themselves. You get a dedicated environment with your own encryption keys while EchelonGraph handles operations and maintenance. Documented on the start date: /docs/deployment, section “Dedicated Instance”: one of the “three deployment models to meet different security, compliance, and data residency requirements”, with its data location given in the page's table as “Isolated project for your organization” | EXCLUDED: not generally available on the start date, so not part of the grant | No environment, project or infrastructure dedicated to one customer existed on the start date, and none exists today. The hosted service was, and is, one shared deployment in which each workspace is kept apart by tenant isolation. Found and annotated on 2026-09-24. (#2166) |
| An isolated environment managed by EchelonGraph exclusively for your organization. Dedicated encryption keys and infrastructure separation. Best for regulated industries that need isolation without operational overhead. Documented on the start date: /docs/data-sovereignty, section “Deployment Options”, under “Dedicated Instance” | EXCLUDED: not generally available on the start date, so not part of the grant | The same offer as the row above, on a second page, and the same fact: no environment or infrastructure dedicated to one customer existed on the start date, and none exists today. Found and annotated on 2026-09-24. (#2166) |
| For security-conscious organizations, EchelonGraph offers full control over where your data lives, how it's encrypted, and who can access it — including a fully self-hosted option with zero data egress. Documented on the start date: /docs/data-sovereignty, the opening sentence of “Enterprise Data Control” | EXCLUDED for the hosted service: not generally available there on the start date, so not part of the grant | A hosted workspace had no choice of location on the start date: every workspace's databases were in Google Cloud us-central1, whatever region the workspace was assigned, as the residency row above says. This entry concerns the hosted service only. It does not describe the self-hosted option the same sentence names. Found and annotated on 2026-09-24. (#2166) |
| Automatically enforce data residency requirements per jurisdiction. Documented on the start date: /compare, the “Multi-Region Coverage” card | EXCLUDED: not generally available on the start date, so not part of the grant | On the start date the product could flag some data-residency exposure in your own cloud accounts: low-severity checks noted, for example, a storage bucket in a multi-region and a GCP organisation with no resource-location policy. This entry does not exclude those checks. It excludes what the line says: no rule knew which regions a jurisdiction's law requires, so nothing enforced any jurisdiction's residency requirement, automatically or otherwise. Found and annotated on 2026-09-24. (#2166) |
The current Enterprise feature list is on the plans page.
Where our own sources disagreed (2)
Our plan definitions live in three places, and on the capture date these fields did not match. They are published rather than reconciled, because a difference we picked a winner for after the fact is exactly the thing a dispute would turn on. Where a disagreement affects what you were granted, the reading most favourable to the claimant governs.
| Tier | Field | What each source said |
|---|---|---|
| enterprise | feature_count | go_seed: 16marketing_static: 14production_db: 16 |
| pro | feature_count | go_seed: 16marketing_static: 15production_db: 16 |
production_db
plans table (echelongraph-prod) · read by SELECT over information-schema-stable columns
freeFree ($0 / year)- 3 users included
- Up to 500 cloud assets
- 3 cloud accounts (AWS, GCP, Azure)
- Tier 1 agentless cloud scanning
- CIS v2.0 + SOC 2 compliance
- 3D blast radius visualization
- 90-day data retention
- Executive summary reports
- Community support
rowsassets: 500cloud_accounts: 3max_assets: 500max_cloud_accounts: 3max_scans_per_day: 2max_users: 3retention: 90 daysretention_days: 90scans_per_day: 2users: 3enterprise$150,000 / year- 500 users included
- 1,000 normalised units included
- 500 cloud accounts included
- All 3 scanning tiers (incl. runtime eBPF)
- 330 compliance frameworks scored + custom frameworks
- Zero-knowledge encryption
- BYOK encryption with key rotation
- 730-day data retention + archive
- SAML/OIDC/LDAP SSO + SCIM 2.0
- Self-hosted / on-prem deployment
- Air-gapped mode (zero egress)
- Helm chart for Kubernetes
- Dedicated Customer Success Manager
- SLA guarantee (99.9% uptime)
- Custom data residency (US, EU, APAC)
- Phone + video support
unitsassets: 1,000 unitscloud_accounts: 500max_assets: 1000max_cloud_accounts: 500max_scans_per_day: -1max_users: 500retention: 730 days + archiveretention_days: 730scans_per_day: Unlimitedusers: 500team$12,000 / yearnot generally available- Up to 10 users
- Up to 2,500 cloud assets
- 10 cloud accounts
- Tier 1 + Tier 2 scanning
- Container image scanning
- Kubernetes misconfiguration detection
- MITRE ATT&CK technique tagging
- SOC 2, HIPAA, ISO 27001, PCI DSS
- 180-day data retention
- Blast radius analysis
- All report types
- Webhook integrations
- Email support (48-hour response)
rowsassets: 2,500cloud_accounts: 10max_assets: 2500max_cloud_accounts: 10max_scans_per_day: 10max_users: 10retention: 180 daysretention_days: 180scans_per_day: 10users: 10pro$30,000 / yearnot generally available- Up to 50 users
- Up to 25,000 cloud assets
- 50 cloud accounts
- Tier 1 + Tier 2 full scanning
- Container image CVE scanning + SBOM
- Kubernetes security auditing (CIS, RBAC, NetPol)
- MITRE ATT&CK mapping + attack path analysis
- PCI DSS v4.0 control mapping
- BYOK encryption (AES-256-GCM)
- 330 compliance frameworks scored
- 365-day data retention
- Drift detection + auto-resolve
- All report types (PDF, CSV, JSON)
- SAML/OIDC SSO
- Webhook integrations (Slack, PagerDuty, Jira)
- Priority support (4-hour response)
rowsassets: 25,000cloud_accounts: 50max_assets: 25000max_cloud_accounts: 50max_scans_per_day: 100max_users: 50retention: 365 daysretention_days: 365scans_per_day: 100users: 50go_seed
core-backend/internal/signup/store.go (seedPlans) · read by go/ast walk of the plans composite literal · bf742708e295
freeFree ($0 / year)- 3 users included
- Up to 500 cloud assets
- 3 cloud accounts (AWS, GCP, Azure)
- Tier 1 agentless cloud scanning
- CIS v2.0 + SOC 2 compliance
- 3D blast radius visualization
- 90-day data retention
- Executive summary reports
- Community support
500cloud_accounts: 3max_assets: 500max_cloud_accounts: 3max_scans_per_day: 2max_users: 3retention: 90 daysretention_days: 90scans_per_day: 2users: 3enterprise$150,000 / year- 500 users included
- 1,000 normalised units included
- 500 cloud accounts included
- All 3 scanning tiers (incl. runtime eBPF)
- 330 compliance frameworks scored + custom frameworks
- Zero-knowledge encryption
- BYOK encryption with key rotation
- 730-day data retention + archive
- SAML/OIDC/LDAP SSO + SCIM 2.0
- Self-hosted / on-prem deployment
- Air-gapped mode (zero egress)
- Helm chart for Kubernetes
- Dedicated Customer Success Manager
- SLA guarantee (99.9% uptime)
- Custom data residency (US, EU, APAC)
- Phone + video support
1,000 unitscloud_accounts: 500max_assets: 1000max_cloud_accounts: 500max_scans_per_day: -1max_users: 500retention: 730 days + archiveretention_days: 730scans_per_day: Unlimitedusers: 500team$12,000 / yearnot generally available- Up to 10 users
- Up to 2,500 cloud assets
- 10 cloud accounts
- Tier 1 + Tier 2 scanning
- Container image scanning
- Kubernetes misconfiguration detection
- MITRE ATT&CK technique tagging
- SOC 2, HIPAA, ISO 27001, PCI DSS
- 180-day data retention
- Blast radius analysis
- All report types
- Webhook integrations
- Email support (48-hour response)
2,500cloud_accounts: 10max_assets: 2500max_cloud_accounts: 10max_scans_per_day: 10max_users: 10retention: 180 daysretention_days: 180scans_per_day: 10users: 10pro$30,000 / yearnot generally available- Up to 50 users
- Up to 25,000 cloud assets
- 50 cloud accounts
- Tier 1 + Tier 2 full scanning
- Container image CVE scanning + SBOM
- Kubernetes security auditing (CIS, RBAC, NetPol)
- MITRE ATT&CK mapping + attack path analysis
- PCI DSS v4.0 control mapping
- BYOK encryption (AES-256-GCM)
- 330 compliance frameworks scored
- 365-day data retention
- Drift detection + auto-resolve
- All report types (PDF, CSV, JSON)
- SAML/OIDC SSO
- Webhook integrations (Slack, PagerDuty, Jira)
- Priority support (4-hour response)
25,000cloud_accounts: 50max_assets: 25000max_cloud_accounts: 50max_scans_per_day: 100max_users: 50retention: 365 daysretention_days: 365scans_per_day: 100users: 50marketing_static
marketing-site/lib/plans.ts (STATIC_PLANS) · read by literal extraction of the STATIC_PLANS array · aa7f02a770ba
enterpriseCustom (as this source states it)- Included capacity — see your plan
- All 3 scanning tiers (incl. runtime eBPF)
- Full compliance framework catalogue + custom frameworks
- Zero-knowledge encryption
- BYOK encryption with key rotation
- 730-day data retention + archive
- SAML/OIDC/LDAP SSO + SCIM 2.0
- Self-hosted / on-prem deployment
- Air-gapped mode (zero egress)
- Helm chart for Kubernetes
- Dedicated Customer Success Manager
- SLA guarantee (99.9% uptime)
- Custom data residency (US, EU, APAC)
- Phone + video support
free$0 (as this source states it)- 3 users included
- Up to 500 cloud assets
- 3 cloud accounts (AWS, GCP, Azure)
- Tier 1 agentless cloud scanning
- CIS v2.0 + SOC 2 compliance
- 3D blast radius visualization
- 90-day data retention
- Executive summary reports
- Community support
proCustom (as this source states it)- Up to 50 users
- Up to 25,000 cloud assets
- 50 cloud accounts
- Tier 1 + Tier 2 full scanning
- Container image CVE scanning + SBOM
- Kubernetes security auditing (CIS, RBAC, NetPol)
- MITRE ATT&CK mapping + attack path analysis
- PCI DSS v4.0 control mapping
- BYOK encryption (AES-256-GCM)
- All 300+ compliance frameworks
- 365-day data retention
- Drift detection + auto-resolve
- SAML/OIDC SSO
- Webhook integrations (Slack, PagerDuty, Jira)
- Priority support (4-hour response)
teamCustom (as this source states it)- Up to 10 users
- Up to 2,500 cloud assets
- 10 cloud accounts
- Tier 1 + Tier 2 scanning
- Container image scanning
- Kubernetes misconfiguration detection
- MITRE ATT&CK technique tagging
- SOC 2, HIPAA, ISO 27001, PCI DSS
- 180-day data retention
- Blast radius analysis
- All report types
- Webhook integrations
- Email support (48-hour response)