Pricing

Contrast CVE Shield
Your Mythos shield to detect, monitor and prevent exploitation of AI-accelerated attacks

FREE

$0

No credit card required

CVE Shield exploitability monitoring on two applications.

Start free
  • 2 applications (unlimited hosts)* *Usage limits apply
  • CVE Shield runtime monitoring: CVE exploitation detection and reachability
  • Runtime SCA with dependency tree
  • Dynamic scoring to prioritize fixes
  • 14-day rolling history
  • Single user
  • Community support

PRO

(to be released soon)

$750 / month

Billed annually

Full runtime blocking and monitoring for growing teams.

Start pro
  • 8 applications (unlimited hosts)* *Usage limits apply
  • CVE Shield active blocking + runtime monitoring
  • Block CVE exploitation at runtime before the fix ships
  • Runtime SCA with dependency tree
  • Dynamic scoring to prioritize fixes
  • 90-day rolling history
  • Up to 5 users
  • Email support

Enterprise

Talk to sales for a quote

Enterprise-scale coverage with SSO, SLA guarantees, and dedicated support.

Talk to sales
  • Full ADR production monitoring and blocking for CVEs and custom code vulnerabilities
  • SIEM and ticketing integrations
  • Compliance reporting
  • Enterprise access controls: RBAC, SAML SSO
  • 1-year rolling history
  • Unlimited users
  • Standard support

Frequently asked questions

  • No, the opposite. AI-accelerated attacks are surfacing and weaponizing CVEs faster than any team can triage. CVE Shield works at runtime, inside the live application, so it shows you which CVEs an attacker can actually reach and exploit rather than every flaw that exists in your code. Your team spends its time on what's genuinely exploitable, and CVE Shield blocks attempts before a patch ships.
  • CVE Shield provides runtime protection by identifying which CVEs are reachable and exploitable within your live application. By monitoring execution in real-time, it allows your team to block attack attempts before a patch is deployed, effectively reducing the window of vulnerability.
  • The Free tier is a functional starting point, not a trial. You can monitor up to 2 applications in production, see real exploitation attempts as they happen, and keep a 14-day rolling history, all in observation mode. Upgrade when your team needs blocking, more applications, or SIEM and compliance integrations.
  • We describe plans in applications and meter them in services. A service is an independently deployable runtime component that handles a specific business capability and forms part of an application (e.g., billing, shipping). A typical application is made up of several services. Free covers about 2 applications, up to 12 services. Pro covers about 8 applications, up to 50 services.
  • Plans are metered by services. For Free, you get up to 12 services across 2 applications. For Pro, up to 50 services across 8 applications.
  • Observation mode (available in the Free tier) provides visibility into exploitation attempts, including the CVE, route, and source IP. Blocking mode (Pro and Enterprise) stops these attempts at runtime, preventing potential breaches before they succeed.
  • Free covers up to 2 applications at no cost and needs no credit card. Pro is a flat annual price, starting at $750/month billed annually ($9,000/year), and will be available soon. Enterprise moves to annual consumption pricing based on production hosts with a custom quote from sales.
  • Plans are metered by the number of services. A service is an independently deployable runtime component. The Free tier includes up to 12 services across 2 applications, while the Pro tier offers up to 50 services across 8 applications.
  • Yes. You can start on Free and upgrade to Pro when it becomes available, and coverage for new applications takes effect once the agent is reporting. Enterprise is handled with our sales team.
  • No. CVE Shield uses the Contrast ADR agent, which is installed once. It provides automated protection for all covered CVEs without requiring manual code changes or application restarts after the initial setup.
  • At launch, CVE Shield supports Java applications. Additional runtimes, including .NET and Python, are planned for upcoming phases to provide broader coverage across your technology stack.
  • User data is hosted on an AWS instance in the United States of America (regardless of the user’s location). Contrast uses sub-processors which may be located in additional jurisdictions.  A list of these sub-processors can be found here: https://www.contrastsecurity.com/privacy-sub-processors-listing