What CVE monitoring covers
The real cost of noise, how a scope is built, and what happens between the alert and the fix.
The pillar page on CVE monitoringFour plans, from a personal project to a multi-entity organization. The volume of CVEs is never billed: what varies is the number of tracked components, the size of the team and the degree of automation. If you are still weighing the principle, start with what targeted CVE monitoring covers.
For freelancers and developers who want to secure a personal project with no commitment.
For small IT teams that need to run their cyber monitoring together, and to sort and handle alerts.
For security teams and CISOs who automate monitoring via API and plug TechWatchAlert into their SOC.
For organizations that need contractual commitments, not just features.
No feature is locked behind a higher plan on principle. Technical limits reflect real infrastructure costs.
| BasicFree | Plus€19/month | Pro€39/month | Enterprise€199/month | |
|---|---|---|---|---|
| CVE & EOL alerting | ||||
| CVE alertsProcessed in under 30 s after detection; detection depends on the sync cycle, which runs every few minutes | Unlimited | Unlimited | Unlimited | Unlimited |
| Watchlist itemsTechnologies / components monitored individually | 10 | Unlimited | Unlimited | Unlimited |
| EOL (end-of-life) subscriptionsSoftware with automatic end-of-support tracking | 5 | Unlimited | Unlimited | Unlimited |
| CVSS v4 / EPSS / CISA KEV prioritization | ✓ | ✓ | ✓ | ✓ |
| Custom alert rulesFilters by CVSS, EPSS, vendor, tag | 3 | 25 | Unlimited | Unlimited |
| Collaboration & workflow | ||||
| ProjectsIsolated environments (prod, staging, client A…) | 1 | 5 | Unlimited | Unlimited |
| Members per organization | 1 | 5 included | Unlimited | Unlimited |
| Organizations & RBAC groups | ✕ | ✓ | ✓ | ✓ |
| Case managementPENDING → ANALYZING → RESOLVED workflow, assignment, comments | ✕ | ✓ | ✓ | ✓ |
| @user mentions and threads | ✕ | ✓ | ✓ | ✓ |
| AI assistant | ||||
| Vigie assistantplain-language questions about your estate, explained prioritization | ✓ | ✓ | ✓ | ✓ |
| Analysis tokens per monthreset every month, never billed as overage | 50k | 1M | 2.5M | 10M |
| Workflows built by Vigieyou describe the rule, Vigie builds it | ✕ | ✕ | ✓ | ✓ |
| Integrations & notifications | ||||
| Email notifications (DKIM) | ✓ | ✓ | ✓ | ✓ |
| Slack · Microsoft Teams | ✕ | ✓ | ✓ | ✓ |
| HMAC outbound webhooks | ✕ | 3 | Unlimited | Unlimited |
| REST API v120 endpoints, Bearer authentication, per-plan quotas — how to connect it | ✕ | Read (GET) | Full | Full |
| SIEM exportSplunk, Microsoft Sentinel, ELK, QRadar | ✕ | ✕ | ✓ | ✓ |
| API rate limitRequests per minute, per key | ✕ | 60 req/min | 600 req/min | Custom quote |
| Reporting & compliance | ||||
| Exportable PDF reports | ✕ | 24 months | 48 months | Unlimited |
| Tracking dashboard11 cards: priorities, triage, deadlines, activity | ✓ | ✓ | ✓ | ✓ |
| Audit logsLog of user & API actions | ✕ | 30 days | 2 years | Unlimited |
| CSV / JSON export of alerts | ✓ | ✓ | ✓ | ✓ |
| Security & compliance | ||||
| Hosting in France (Paris) | ✓ | ✓ | ✓ | ✓ |
| Mandatory TOTP 2FA | ✓ | ✓ | ✓ | ✓ |
| OIDC single sign-on | ✕ | ✕ | ✕ | ✓ |
| DPA signed on request | ✕ | ✓ | ✓ | ✓ |
| Support | ||||
| Documentation & public status page | ✓ | ✓ | ✓ | ✓ |
| Support | Community | Email · 24 business hours | Priority · 4h | Dedicated · SLA |
| Onboarding support | ✕ | ✕ | On request | Included |
These are not testimonials: they are typical situations, with each plan's real limits. We will only publish a quote on the day we can name and date it.
Node, PostgreSQL, Redis, a few appliances. The free plan is enough: ten tracked components, email notifications. What it prevents: discovering a critical CVE on a project delivered six months earlier.
The Plus plan opens up sharing: alerts land in a channel, everyone picks up their own, the PENDING → RESOLVED cycle keeps the record, and the monthly report goes to the client without re-keying.
Mixed estate: Windows, Linux, appliances. The Pro plan is used mainly as an API: alerts flow into the SIEM, and a CI job blocks deployment as long as a critical CVE remains open.
For organizations whose requirements go beyond the Pro plan: high volumes, stronger sovereignty, deep integration with your information system, specific contractual commitments. Our team builds the scope with you.
Beyond the included quotas, add only what you need. Usage-based billing, no tiers.
Beyond the 5 seats included in Plus. Granular roles (viewer, editor, admin, owner), mandatory 2FA.
For IT service companies or agencies that bill monitoring to their end clients. Full isolation, per-project branding.
Alert history & PDF reports extended to 7 years. Designed for your retention and traceability obligations.
A shared Slack channel with the product team, and priority on your tickets. We have no night-time on-call: as long as it doesn't exist, we don't sell it.
Can't find your answer? Write to us: we reply within 24 business hours.
Yes, upgrade or downgrade on the fly from your settings. Billing is calculated on a daily prorated basis via Paddle. No data is ever lost on a downgrade: only features beyond the lower plan's limits become read-only.
No. A work email is enough to create an account. Only paid plans ask for a card or a SEPA mandate at upgrade time.
An item = one technology monitored at a specific version (e.g. [email protected], postgresql@16). An EOL subscription = one piece of software whose end of life you track (e.g. CentOS 7, PHP 8.1). From the Plus plan up, both counters are unlimited.
The Plus plan opens the GET endpoints of API v1: alerts, matched CVEs, inventory, projects, statistics. Writing (creating items, workflow actions, organization management) and unlimited webhooks are reserved for the Pro plan. Every key can be revoked and is logged. The steps are on the getting started page.
Not on the published plans. A “private cloud” Enterprise edition is available on quote: deployment in your VPC (AWS, OVH, Scaleway, Outscale), managed updates, contractual support. Minimum 30 users, annual commitment. Contact us.
Your inventory is used only to filter the CVE feed. Hosting in France (Paris region), AES-256 encryption at rest, TLS 1.3 in transit, no subprocessor outside the EU. No data is resold or used to train a model. The details, subprocessors included, are in the privacy policy; the feeds we aggregate are listed on the sources page. Data processing agreement (DPA) available to sign from the Plus plan up.
Yes. −50% on Plus and Pro for French nonprofits (loi 1901 associations), academic CERTs, research labs and higher-education institutions. Send your request to [email protected] with supporting documents. The Basic plan is recommended for individual students.
Purchase-order (PO) billing, 30-day payment terms, Chorus Pro-compatible PDF invoice. Multi-year framework agreement possible. Write to [email protected].
A price can't be judged on its own: judge it against what other tools do, and against what you actually expect from it.
The real cost of noise, how a scope is built, and what happens between the alert and the fix.
The pillar page on CVE monitoringStack targeting, prioritization, data freshness, real price, hosting. Method and date shown.
The 2026 comparisonOpenCVE, Cyberwatch, CVEDetails: what each does better than us, said plainly.
All comparisonsThe seven vulnerability feeds, their licenses, their publication delays and their gaps.
The sources we aggregateFree plan, no credit card
Ten components are enough to check whether the filtering delivers on your stack. You'll change plans when the answer is yes.
Account ready in two minutes, no card required.
Already signed up? Sign in · A question? Write to us