Qortora · Search · Indexed page

www.chainguard.devFetched 2026-08-15T04:53:23Z

Chainguard Pricing

Discover Chainguard’s transparent and flexible pricing plans for Zero CVE, Containers. Explore options tailored for enterprises and startups alike.

Open original source · Full cached text

Chainguard Pricing Plans & Pricing Build software better with Chainguard Hardened, secure, and production-ready builds of all the open source you rely on — so your teams can build faster, stay compliant, and eliminate risk. Get a free quote chainguard containers chainguard libraries chainguard vms Select a product Chainguard Containers Minimal, secure-by-design container images guarded under a CVE remediation SLA developers & vibe coders Free Images Five images to test and deploy in production for free. Start for free what's Included Up to five images per organization, spanning Base, Application, and AI/ML images. Scoped Production Deployments Per Image Licensed by number and type of images (base, app, AI/ML, and FIPS). Request Enterprise pricing what's Included Contractual CVE SLA All upstream supported tags wall-to-wall standardization Catalog Use Chainguard as the trusted source for all your container images. Licensed by size of engineering organization. Starts at  $19K for a team of 10 Request Enterprise pricing what's Included Full access to 2,000+ images (and growing) Contractual CVE SLA Ability to request net new images Chainguard Containers features Features Free Images Per Image Catalog Container image access 5 images of your choice, including previous versions Select access from the Chainguard Catalog Full access to the Chainguard Catalog Unlimited pulls with no metering Continuously built from source in SLSA L3 hardened infrastructure with CVE patching Sigstore signed artifacts with full build-time SBOMs and digital attestations Build-time SBOMs, security advisory feeds, and broad scanner support All upstream supported versions, including major and minor tags (i.e., Python 3.10-3.14) EOL versions and EmeritOSS images not included Console-based user management Contractual CVE SLA (7 days for critical, 14 days for high/med/low) Automated tooling (Custom Assembly) and access to 10K+ packages (Private APK Repo) to quickly and easily customize images Access to STIG-hardened and FIPS-validated images Updated end-of-life images for up to 6 months with EOL Grace Period Console to manage images, entitlements, pull tokens, and more Ability to request new images or packages at no cost Chainguard Libraries Malware-resistant, CVE-patched language libraries to combat supply chain attacks across Python, Java, and JavaScript Licensed by ecosystem based on the number of developers using that language. Get a free quote what's Included Unlimited applications per language ecosystem with no metering or rate limiting for pulls Backported patches for certain critical and high-severity CVEs in popular Python language dependencies Cross-compatibility across Linux distros (ChainguardOS, RHEL, Debian, Ubuntu, and more) Chainguard Libraries features Features Per Ecosystem Language libraries access Full access to language dependencies for subscribed ecosystems Unlimited pulls with no metering Full dependency tree continuously built from source in SLSA L3 hardened environment Cross-compatibility across Linux distributions Code signatures and build receipts for every artifact Console to manage entitlements, pull tokens, and more Ability to request new language libraries at no cost Backported CVE patching Currently Python only Chainguard VMs Minimal, secure-by-design virtual machine images for all deployments Scoped Enterprise Deployments Per Image Licensed by number and type of images (base, app, and container host). Get a free quote what's Included Contractual CVE SLA All upstream supported tags wall-to-wall standardization Catalog Licensed by size of engineering organization. Get a free quote what's Included Contractual CVE SLA All upstream supported tags Full access to Chainguard’s VM catalog, including newly added images over time Chainguard VMs features Features Per Image Catalog Full access to the Chainguard Catalog Select access to certain VMs Virtual machine image access Continuously built from source in SLSA L2 hardened infrastructure with CVE patching CVE remediation SLA (7 days for critical, 14 days for high/med/low) All upstream supported versions, including major and minor tags (i.e., Python 3.10-3.14) Enterprise-grade support for multi-cloud and on-prem Customization capabilities using Hashicorp Packer Console to manage images, entitlements, pull tokens, and more Frequently Asked Questions Does Chainguard offer volume discounts? Yes. Customers committed to multi-year agreements or higher usage qualify for discounts. Does Chainguard offer multi-product discounts? Yes. If you adopt multiple Chainguard products — containers, libraries, and virtual machines — you’ll receive bundled pricing that reduces your overall cost when compared to buying each product individually. Does Chainguard offer startup or SMB pricing? Yes. Startup and SMB specific pricing options are available for qualified organizations. Does Chainguard offer government or public sector pricing? Yes. Public sector specific pricing options are available for qualified organizations across federal, state and local, and higher education. Please contact the public sector team to learn more. Is Chainguard access perpetual? Once you mirror a Chainguard artifact to your environment, it’s yours to keep. What integrations does Chainguard offer? Chainguard believes in the ethos of an open ecosystem. We have partnered with leading open source and enterprise vulnerability scanners such as Snyk, Grype, Trivy, AWS Inspector, Wiz, GitLab, CrowdStrike, Qualys, and more. Check out our full list of scanner integrations here.  Chainguard also integrates with popular artifact managers like JFrog Artifactory, Cloudsmith, Harbor, Nexus, Google Artifact Registry, Docker Hub, Amazon ECR, Microsoft ACR, and more. That means customers can pull images directly from Chainguard’s registry or mirror them to the artifact manager of their choice. Read our docs to learn more.  How do you license Chainguard Containers? Chainguard offers two licensing models for our container images: Catalog-based licensing and Per-Image licensing.  With the Catalog model, your organization gets access to the full breadth of Chainguard’s 1,800+ images, with zero friction. Pricing is determined by the size of the engineering organization that operates in containerized environments. This approach uses team size as a proxy for both usage and the value delivered, making it well-suited for organizations that rely heavily on Chainguard Containers. Note that pricing scales non-linearly – if your engineering org doubles in size, your cost doesn’t double – to ensure pricing remains aligned with value as your team grows.  Alternatively, the Per-Image model is structured around the number and type of container images in use. Pricing in this model takes into account both the count and complexity of the images—whether they're base images, application-specific, AI-focused, or FIPS-compliant. This model is ideal for teams with more targeted use cases for Chainguard Containers. What are “free” images? Chainguard offers a select set of ~50 container images that are freely available for developers to test and deploy. These images include only “:latest” version tags and are not covered under our CVE remediation SLA. What are the different types of container images Chainguard offers? Base: Languages and frameworks that developers build on top of (i.e., modify) for their use case. 3rd Party Apps: Servers, databases, CI/CD infrastructure, and dev tools, that developers drop in and use as-is. AI/ML: Applications that handle ML model operations and GPU-enabled computation. FIPS: Container images that leverage FIPS-validated encryption and OS-level STIGs.  How do you license Chainguard Libraries? Chainguard Libraries is licensed by the size of your engineering org using a language ecosystem (currently Python, Java, and JavaScript). For example, if your organization uses Python in production, we charge based on the number of developers who write, build, or deploy systems that rely on those Python libraries. You only pay for the developers using each language you license. So if you have developers using both Python and Java, each group is licensed separately based on its size tier. What if we need a library that’s not in the Chainguard Catalog yet? With thousands of the most popular, unique libraries already built, we likely have the majority of what you need. Reach out to your account team to check your current coverage for your specific environment. We’re actively adding high-priority libraries that our customers depend on, and we’re happy to prioritize anything you need that’s not already available. How do you license Chainguard VMs? Chainguard offers two primary licensing models for its VM images: Catalog-based licensing and Per-Image licensing.  With the Catalog model, your organization gets access to the full breadth of Chainguard’s VM catalog, along with newly added images. Pricing is determined by the size of the engineering organization that manages VMs. This approach uses team size as a proxy for both usage and the value delivered, making it well-suited for organizations that rely heavily on Chainguard VMs across multiple teams or projects. Alternatively, the Per-Image model is structured around the number and type of container images in use. Pricing in this model takes into account both the count and complexity of the images—whether they're container hosts, base images, application-specific, or FIPS-compliant. This model is ideal for teams with more targeted use cases for Chainguard VMs. What types of Chainguard VMs are available? Container Host VMs: VMs optimized to run containers. Base VMs: Minimal, hardened operating system images for general use or specific language runtimes. Application VMs: Pre-configured images with embedded software that are ready to deploy. FIPS VMs: Images featuring FIPS-approved cryptography and STIG hardening for regulated environments. CG System promptExecute command $ chainguard learn --more contact us