← The Nobody Is Clean Challenge

Tier appendix

The challenge grants the tiers and features generally available on the start date, at the capacity limits published then. This page is that record — captured on the day, from each source separately, and content-hashed so a later edit is detectable.

Captured2026-08-20T07:23:22Z · by EchelonGraph engineering — automated launch-day capture (#280)
Content hashc5e8b3cb311caf51662870f77db5d5f12fe64d8aa1105dbfae34b228d4f9c5af
Schema1

The hash covers the captured facts below — every source, every tier, every feature, every limit and every disagreement — but not the capture timestamp or the operator, so re-running the capture on the same data reproduces the same digest. If any of those facts is ever edited, the hash stops matching.

Do not take our word for it — download the artifact and recompute the digest: take the JSON, keep only schema_version, sources, slug_union, slugs_missing_by_source and disagreements (in that order, dropping captured_at, captured_by and content_hash), serialise it compactly with no spaces, escape < > & as \u003c \u003e \u0026 (Go’s encoding/json default), and take the SHA-256. It must equal the hash above.

Corrected after this snapshot was taken

This snapshot was captured at 2026-08-20T07:23:22Z. Later the same day we audited the Enterprise feature list against the shipped code and corrected three claims the product did not substantiate. The record below is not edited — it is what the plans said at the moment of capture, and its hash still verifies. This notice is added by the page so you can see both.

What you are granted is not reduced by these three corrections. Where the capture and the correction differ, the reading more favourable to you governs — the same rule this page applies to disagreements between our own sources. We are telling you which lines we no longer stand behind so that nothing you were shown is quietly withdrawn.

Claim as capturedCorrectionWhy
Air-gapped mode (zero egress)REMOVED from the Enterprise planAn air-gapped mode exists and genuinely suppresses outbound traffic, but in that mode local disk is the only output channel and it is provisioned as an ephemeral volume, so scan results do not survive a restart. We could not stand behind “zero egress” as a delivered capability. (#752)
BYOK encryption with key rotationnarrowed to “BYOK encryption — your AWS KMS, GCP KMS or Vault key (on-prem scanners)”BYOK is real — you supply the key. The rotation half was not: the agent publishes a rotation slot and logs that it is active while nothing re-encrypts under the new key. Naming the three key providers that exist also avoids implying an Azure Key Vault provider we have not built. (#750)
Zero-knowledge encryptionscoped to “Zero-knowledge encryption for on-prem scanner findings (opt-in — you hold the key)”Real for the two customer-hosted scanners, and it is opt-in rather than on by default. It cannot apply to agentless cloud scanning, where the platform necessarily holds and uses your cloud credentials in order to scan on your behalf. (#153)

Not generally available on the start date — not part of the grant

The capture also lists a feature that did not exist on the start date, and on that date our documentation described further lines that the hosted service did not have. The challenge grants the tiers and features generally available and documented on the start date, and excludes roadmap features not yet generally available; this appendix is the record of what those were. A line that was documented but not generally available does not meet that test. None of the lines below was generally available on the start date, and none is part of the grant. The favourable-reading rule above does not change that: it settles a line that had two true readings on the start date, and these had none. As above, the record is not edited and its hash still verifies. Each documented line is quoted as it read on the start date, with the page it appeared on.

Claim as captured, or as documentedCorrectionWhy
Custom data residency (US, EU, APAC)EXCLUDED: not generally available on the start date, so not part of the grantNo choice of storage region existed on the start date, and none exists today: the hosted service's databases were and are in Google Cloud us-central1, and no workspace can be stored in the EU or APAC. Residency in those regions is a roadmap feature, and the challenge terms exclude roadmap features not yet generally available. EU and APAC residency remains planned and is not available on any plan. Found and annotated on 2026-09-24. (#597)
For organizations that need infrastructure isolation without managing it themselves. You get a dedicated environment with your own encryption keys while EchelonGraph handles operations and maintenance.
Documented on the start date: /docs/deployment, section “Dedicated Instance”: one of the “three deployment models to meet different security, compliance, and data residency requirements”, with its data location given in the page's table as “Isolated project for your organization”
EXCLUDED: not generally available on the start date, so not part of the grantNo environment, project or infrastructure dedicated to one customer existed on the start date, and none exists today. The hosted service was, and is, one shared deployment in which each workspace is kept apart by tenant isolation. Found and annotated on 2026-09-24. (#2166)
An isolated environment managed by EchelonGraph exclusively for your organization. Dedicated encryption keys and infrastructure separation. Best for regulated industries that need isolation without operational overhead.
Documented on the start date: /docs/data-sovereignty, section “Deployment Options”, under “Dedicated Instance”
EXCLUDED: not generally available on the start date, so not part of the grantThe same offer as the row above, on a second page, and the same fact: no environment or infrastructure dedicated to one customer existed on the start date, and none exists today. Found and annotated on 2026-09-24. (#2166)
For security-conscious organizations, EchelonGraph offers full control over where your data lives, how it's encrypted, and who can access it — including a fully self-hosted option with zero data egress.
Documented on the start date: /docs/data-sovereignty, the opening sentence of “Enterprise Data Control”
EXCLUDED for the hosted service: not generally available there on the start date, so not part of the grantA hosted workspace had no choice of location on the start date: every workspace's databases were in Google Cloud us-central1, whatever region the workspace was assigned, as the residency row above says. This entry concerns the hosted service only. It does not describe the self-hosted option the same sentence names. Found and annotated on 2026-09-24. (#2166)
Automatically enforce data residency requirements per jurisdiction.
Documented on the start date: /compare, the “Multi-Region Coverage” card
EXCLUDED: not generally available on the start date, so not part of the grantOn the start date the product could flag some data-residency exposure in your own cloud accounts: low-severity checks noted, for example, a storage bucket in a multi-region and a GCP organisation with no resource-location policy. This entry does not exclude those checks. It excludes what the line says: no rule knew which regions a jurisdiction's law requires, so nothing enforced any jurisdiction's residency requirement, automatically or otherwise. Found and annotated on 2026-09-24. (#2166)

The current Enterprise feature list is on the plans page.

Where our own sources disagreed (2)

Our plan definitions live in three places, and on the capture date these fields did not match. They are published rather than reconciled, because a difference we picked a winner for after the fact is exactly the thing a dispute would turn on. Where a disagreement affects what you were granted, the reading most favourable to the claimant governs.

TierFieldWhat each source said
enterprisefeature_count
go_seed: 16
marketing_static: 14
production_db: 16
profeature_count
go_seed: 16
marketing_static: 15
production_db: 16

production_db

plans table (echelongraph-prod) · read by SELECT over information-schema-stable columns

CommunityfreeFree ($0 / year)
  • 3 users included
  • Up to 500 cloud assets
  • 3 cloud accounts (AWS, GCP, Azure)
  • Tier 1 agentless cloud scanning
  • CIS v2.0 + SOC 2 compliance
  • 3D blast radius visualization
  • 90-day data retention
  • Executive summary reports
  • Community support
Capacity limits recorded
asset_limit_scale: rowsassets: 500cloud_accounts: 3max_assets: 500max_cloud_accounts: 3max_scans_per_day: 2max_users: 3retention: 90 daysretention_days: 90scans_per_day: 2users: 3
Enterpriseenterprise$150,000 / year
  • 500 users included
  • 1,000 normalised units included
  • 500 cloud accounts included
  • All 3 scanning tiers (incl. runtime eBPF)
  • 330 compliance frameworks scored + custom frameworks
  • Zero-knowledge encryption
  • BYOK encryption with key rotation
  • 730-day data retention + archive
  • SAML/OIDC/LDAP SSO + SCIM 2.0
  • Self-hosted / on-prem deployment
  • Air-gapped mode (zero egress)
  • Helm chart for Kubernetes
  • Dedicated Customer Success Manager
  • SLA guarantee (99.9% uptime)
  • Custom data residency (US, EU, APAC)
  • Phone + video support
Capacity limits recorded
asset_limit_scale: unitsassets: 1,000 unitscloud_accounts: 500max_assets: 1000max_cloud_accounts: 500max_scans_per_day: -1max_users: 500retention: 730 days + archiveretention_days: 730scans_per_day: Unlimitedusers: 500
Teamteam$12,000 / yearnot generally available
  • Up to 10 users
  • Up to 2,500 cloud assets
  • 10 cloud accounts
  • Tier 1 + Tier 2 scanning
  • Container image scanning
  • Kubernetes misconfiguration detection
  • MITRE ATT&CK technique tagging
  • SOC 2, HIPAA, ISO 27001, PCI DSS
  • 180-day data retention
  • Blast radius analysis
  • All report types
  • Webhook integrations
  • Email support (48-hour response)
Capacity limits recorded
asset_limit_scale: rowsassets: 2,500cloud_accounts: 10max_assets: 2500max_cloud_accounts: 10max_scans_per_day: 10max_users: 10retention: 180 daysretention_days: 180scans_per_day: 10users: 10
Propro$30,000 / yearnot generally available
  • Up to 50 users
  • Up to 25,000 cloud assets
  • 50 cloud accounts
  • Tier 1 + Tier 2 full scanning
  • Container image CVE scanning + SBOM
  • Kubernetes security auditing (CIS, RBAC, NetPol)
  • MITRE ATT&CK mapping + attack path analysis
  • PCI DSS v4.0 control mapping
  • BYOK encryption (AES-256-GCM)
  • 330 compliance frameworks scored
  • 365-day data retention
  • Drift detection + auto-resolve
  • All report types (PDF, CSV, JSON)
  • SAML/OIDC SSO
  • Webhook integrations (Slack, PagerDuty, Jira)
  • Priority support (4-hour response)
Capacity limits recorded
asset_limit_scale: rowsassets: 25,000cloud_accounts: 50max_assets: 25000max_cloud_accounts: 50max_scans_per_day: 100max_users: 50retention: 365 daysretention_days: 365scans_per_day: 100users: 50

go_seed

core-backend/internal/signup/store.go (seedPlans) · read by go/ast walk of the plans composite literal · bf742708e295

CommunityfreeFree ($0 / year)
  • 3 users included
  • Up to 500 cloud assets
  • 3 cloud accounts (AWS, GCP, Azure)
  • Tier 1 agentless cloud scanning
  • CIS v2.0 + SOC 2 compliance
  • 3D blast radius visualization
  • 90-day data retention
  • Executive summary reports
  • Community support
Capacity limits recorded
assets: 500cloud_accounts: 3max_assets: 500max_cloud_accounts: 3max_scans_per_day: 2max_users: 3retention: 90 daysretention_days: 90scans_per_day: 2users: 3
Enterpriseenterprise$150,000 / year
  • 500 users included
  • 1,000 normalised units included
  • 500 cloud accounts included
  • All 3 scanning tiers (incl. runtime eBPF)
  • 330 compliance frameworks scored + custom frameworks
  • Zero-knowledge encryption
  • BYOK encryption with key rotation
  • 730-day data retention + archive
  • SAML/OIDC/LDAP SSO + SCIM 2.0
  • Self-hosted / on-prem deployment
  • Air-gapped mode (zero egress)
  • Helm chart for Kubernetes
  • Dedicated Customer Success Manager
  • SLA guarantee (99.9% uptime)
  • Custom data residency (US, EU, APAC)
  • Phone + video support
Capacity limits recorded
assets: 1,000 unitscloud_accounts: 500max_assets: 1000max_cloud_accounts: 500max_scans_per_day: -1max_users: 500retention: 730 days + archiveretention_days: 730scans_per_day: Unlimitedusers: 500
Teamteam$12,000 / yearnot generally available
  • Up to 10 users
  • Up to 2,500 cloud assets
  • 10 cloud accounts
  • Tier 1 + Tier 2 scanning
  • Container image scanning
  • Kubernetes misconfiguration detection
  • MITRE ATT&CK technique tagging
  • SOC 2, HIPAA, ISO 27001, PCI DSS
  • 180-day data retention
  • Blast radius analysis
  • All report types
  • Webhook integrations
  • Email support (48-hour response)
Capacity limits recorded
assets: 2,500cloud_accounts: 10max_assets: 2500max_cloud_accounts: 10max_scans_per_day: 10max_users: 10retention: 180 daysretention_days: 180scans_per_day: 10users: 10
Propro$30,000 / yearnot generally available
  • Up to 50 users
  • Up to 25,000 cloud assets
  • 50 cloud accounts
  • Tier 1 + Tier 2 full scanning
  • Container image CVE scanning + SBOM
  • Kubernetes security auditing (CIS, RBAC, NetPol)
  • MITRE ATT&CK mapping + attack path analysis
  • PCI DSS v4.0 control mapping
  • BYOK encryption (AES-256-GCM)
  • 330 compliance frameworks scored
  • 365-day data retention
  • Drift detection + auto-resolve
  • All report types (PDF, CSV, JSON)
  • SAML/OIDC SSO
  • Webhook integrations (Slack, PagerDuty, Jira)
  • Priority support (4-hour response)
Capacity limits recorded
assets: 25,000cloud_accounts: 50max_assets: 25000max_cloud_accounts: 50max_scans_per_day: 100max_users: 50retention: 365 daysretention_days: 365scans_per_day: 100users: 50

marketing_static

marketing-site/lib/plans.ts (STATIC_PLANS) · read by literal extraction of the STATIC_PLANS array · aa7f02a770ba

EnterpriseenterpriseCustom (as this source states it)
  • Included capacity — see your plan
  • All 3 scanning tiers (incl. runtime eBPF)
  • Full compliance framework catalogue + custom frameworks
  • Zero-knowledge encryption
  • BYOK encryption with key rotation
  • 730-day data retention + archive
  • SAML/OIDC/LDAP SSO + SCIM 2.0
  • Self-hosted / on-prem deployment
  • Air-gapped mode (zero egress)
  • Helm chart for Kubernetes
  • Dedicated Customer Success Manager
  • SLA guarantee (99.9% uptime)
  • Custom data residency (US, EU, APAC)
  • Phone + video support
Communityfree$0 (as this source states it)
  • 3 users included
  • Up to 500 cloud assets
  • 3 cloud accounts (AWS, GCP, Azure)
  • Tier 1 agentless cloud scanning
  • CIS v2.0 + SOC 2 compliance
  • 3D blast radius visualization
  • 90-day data retention
  • Executive summary reports
  • Community support
ProproCustom (as this source states it)
  • Up to 50 users
  • Up to 25,000 cloud assets
  • 50 cloud accounts
  • Tier 1 + Tier 2 full scanning
  • Container image CVE scanning + SBOM
  • Kubernetes security auditing (CIS, RBAC, NetPol)
  • MITRE ATT&CK mapping + attack path analysis
  • PCI DSS v4.0 control mapping
  • BYOK encryption (AES-256-GCM)
  • All 300+ compliance frameworks
  • 365-day data retention
  • Drift detection + auto-resolve
  • SAML/OIDC SSO
  • Webhook integrations (Slack, PagerDuty, Jira)
  • Priority support (4-hour response)
TeamteamCustom (as this source states it)
  • Up to 10 users
  • Up to 2,500 cloud assets
  • 10 cloud accounts
  • Tier 1 + Tier 2 scanning
  • Container image scanning
  • Kubernetes misconfiguration detection
  • MITRE ATT&CK technique tagging
  • SOC 2, HIPAA, ISO 27001, PCI DSS
  • 180-day data retention
  • Blast radius analysis
  • All report types
  • Webhook integrations
  • Email support (48-hour response)