The quote-only era is overTheir pricing is a secret. Ours is on the homepage.

When a vendor hides their price, they're hiding a markup. When they hide their feature list behind a demo, they're hiding a gap. We don't do either.

VikingCloud

How we sell.

  • Public price. Plans listed openly on the homepage. Same rate for everyone — no enterprise upcharge, no quote roulette, no negotiation tax.
  • Self-serve trial. 14 days, full platform, all cloud providers. Cancel from the dashboard.
  • Same product on every paid tier. The only thing that changes between Basic and Pro is the cloud-account count cap — never the features.
  • Enterprise is a real upgrade. Org-level scanning, SAML SSO, dedicated support — capabilities that genuinely require enterprise plumbing, not paywalls on basic features.
The other guys

How they sell.

  • "Contact sales." Three-letter pricing tiers, four-figure floors, and a calendar invite that opens in November. Reported floors of $30K – $100K+/year.
  • Demo gating. Calendar invite → discovery call → SE → quote. Weeks to first scan.
  • Feature paywalls. Attack paths in one tier, vuln scanning in another, K8s in a third. The slide deck is the product.
  • Annual minimums. Multi-year contracts. Custom procurement. Renewal hostage situations.

The complete feature table.

If a row is checked on Basic, it's checked on Basic. The cloud-account count is the only thing that scales between paid tiers.

Feature / capability
Basic
¥19,800 / mo

For solo developers evaluating.

Start trial
Starter
¥49,800 / mo

Small teams · dev / staging / prod.

Start trial
Popular
Pro
¥99,800 / mo

Growing teams · multi-cloud, multi-env.

Start trial
Enterprise
Custom

Orgs · org-level scan · SAML · dedicated.

Contact sales
01Coverage & account limits
Cloud accounts included

AWS Account / GCP Project / Azure Subscription / K8s Cluster — each counts as one.

1Account
3Accounts
7Accounts
Unlimited
AWS · GCP · Azure · Kubernetes

All cloud providers — equal coverage, single console.

Org-level scanning

AWS Organizations · GCP Folders · Azure Management Groups. Auto-discovers child accounts.

Included
14-day free trial

Full platform access. Cancel anytime from the dashboard.

Custom POC
02Asset discovery & inventory
Continuous resource discovery

Every EC2, VM, bucket, IAM role, K8s pod — re-scanned on schedule. No agent. No tag required.

Unified asset inventory across clouds

One filterable table. Filter by provider, type, region, account, tag, exposure.

Resource detail panels

Configuration · tags · attached vulns · related resources · raw provider response.

03Vulnerability & risk detection
VM vulnerability scanning

Snapshot-based, ephemeral. Your VMs are never stopped or modified. Auto-cleanup ~10 min.

Container & K8s image scanning

Layer-by-layer CVE detection across container registries.

Exploit intelligence (EPSS · CISA KEV)

Every CVE enriched with EPSS percentile + CISA Known-Exploited-Vulns flag. Real prioritization.

Secret & credential leak detection

Hard-coded keys, tokens, certs across configs and code. Categorized by source type.

Software inventory & license risk

Permissive · copyleft · restricted classification. Audit-ready license posture.

Supply-chain findings

Dependency-level risks across container images and code repos. Severity-scored.

SBOM & KBOM export

Software Bill of Materials per container image. Kubernetes BOM per cluster. Signed download URLs.

Serverless function scanning

Lambda, Cloud Functions, Azure Functions — supply-chain analysis on the same pipeline as containers and VMs.

Coming soon
Coming soon
Coming soon
Coming soon
04Security checks & misconfigurations
Configuration security checks

Service-by-service evidence across all cloud providers. Filter by service, severity, framework, result.

Per-check evidence & remediation

Why it failed, exactly which resource, exactly which CLI command fixes it.

05Attack path analysis (exposure)
Attack path graph

Multi-step chains visualized: entry point → lateral movement → critical asset.

MITRE ATT&CK technique mapping

Every path tagged with the techniques an adversary would use. Cloud Matrix knowledge base.

Choke-point ranking

The one fix that breaks the most paths. Prioritize remediation by impact, not severity.

Cross-account attack paths

Trust relationships across multiple AWS Orgs / GCP Folders / Azure tenants.

Org-wide
06Compliance & posture
Frameworks shipped at launch

CIS · SOC 2 · ISO 27001 · HIPAA · PCI DSS 4.0 · NIST CSF 2.0 · NIST 800-53 R5.

10Frameworks
10Frameworks
10Frameworks
30+Full registry
Per-control pass/fail evidence

Each control evaluated against your live infrastructure. Exportable for auditors.

Multi-cloud assessment

Run the same framework against AWS, GCP, Azure, K8s — provider-aware control mapping.

FedRAMP · ENS · ISMAP · MITRE ATT&CK

Specialty frameworks (gov / EU / JP) — currently under validation, coming soon.

Coming soon
Coming soon
Coming soon
Coming soon
07AI · Viking Analyst
Viking Analyst chat

Conversational AI that reads your real environment. Not generic Stack Overflow advice.

AI scan briefings

"What changed since last scan, in plain English" — auto-generated after every scan.

AI-curated issues

Thousands of raw findings → ranked, deduped issues. Curator agent runs after every scan.

Executive summaries

Board-ready risk summary, generated from your data. Export-ready.

08Team & workflow
Issue assignment to team members

Assign curated issues to a person. Track ownership across the queue.

Multi-seat team accounts

Invite teammates · role-based permissions · per-account access.

PDF report export

Overview report — pass to security review, leadership, or auditor.

09How we treat your access
Fully agentless architecture

Zero software installed in your infrastructure. Ever. We connect to provider APIs.

Read-only credentials

We request and recommend read-only IAM. We can never modify your resources.

Ephemeral VM scanning

Snapshot · scan on a temp instance · auto-cleanup. ~10 min. Your VMs never stop.

10Support & enterprise capabilities
Support channel

Where you get help when you need it.

Community Slack
Email
Priority email
Dedicated
Single Sign-On (SAML)

Okta · Azure AD · Google Workspace · any SAML 2.0 IdP.

Included
Custom contract & procurement

DPA, security review, MSA — your paper or ours.

Included
Annual billing discount

Pay yearly, get ~17% off (2 months free).

Negotiated
Under the hood

Eight capability layers. One console.

VikingCloud composes industry-standard scan foundations, our proprietary attack-path graph, and a growing multi-agent AI layer into a single platform — so the depth shows up in the UI, not in your onboarding spreadsheet.

Layer 01 / Discovery

Continuous resource discovery

Provider-native APIs enumerate every asset across AWS · GCP · Azure · Kubernetes. Read-only credentials, zero footprint on your side, no agents.

→ Powers the Assets page
Layer 02 / Checks

Configuration security checks

Hundreds of misconfiguration checks across all cloud providers, mapped to CIS, AWS Foundational Security, and provider-specific best practices.

→ Powers the Checks page
Layer 03 / Vulnerabilities

Vulnerability & supply chain

Snapshot-based VM scanning, layer-by-layer container CVE detection, and dependency-level supply-chain analysis — enriched with EPSS percentile and CISA Known-Exploited-Vulns flags for real-world prioritization.

→ Powers the Risks page
Layer 04 / Noise reduction

Curated issues

Thousands of raw findings collapse into a ranked, deduped issue queue. Same vulnerability across 80 hosts? One issue, 80 affected resources. Spend your day on what matters, not on triage.

→ Powers the Issues page
Layer 05 / AI Briefings

AI scan briefings

Every scan ends with a plain-English brief — what changed, what's now exposed, what improved — auto-generated from your real data and signed off in seconds, not hours.

→ Auto-generated post-scan
Layer 06 / AI Chat

Viking Analyst

Conversational AI that reads your real environment. "Show me publicly exposed databases." "Which IAM role has the most risk?" Grounded answers, cited from your scans — not generic Stack Overflow advice.

→ Powers Chat · grounded LLM
Layer 07 / Graph

Attack path engine

Custom graph algorithm over your inventory, findings, and IAM. Identifies multi-step chains and ranks choke points — the single fix that breaks the most paths.

→ Powers the Exposure page
Layer 08 / Frameworks

Compliance registry

30+ frameworks with provider-specific control mappings. Each control runs against your scanned inventory — real evidence per control, audit-ready, exportable.

→ Powers the Posture page
Compliance

Audit evidence, per control.

Ten frameworks ship live today, evaluated against your live cloud — not a checklist on a slide. Specialty frameworks (FedRAMP, ENS, ISMAP, MITRE ATT&CK Framework) are currently under validation — coming soon.

CIS AWS v3.062 controlsAWSLive
CIS Azure v3.0159 controlsAzureLive
CIS GCP v2.084 controlsGCPLive
CIS K8s v1.12131 controlsKubernetesLive
SOC 2 Type II27 criteriaAWS · GCP · AzureLive
ISO 27001:202292 controlsAWS · GCP · Azure · KubernetesLive
HIPAA Security Rule21–34 controlsAWS · GCP · AzureLive
PCI DSS v4.01,669 reqsAWS · GCP · Azure · KubernetesLive
NIST CSF 2.078 controlsAWSLive
NIST 800-53 R5288 controlsAWSLive
FedRAMP 20x KSI Low11 indicatorsAWS · GCP · AzureComing soon
ENS RD 311/202284–188 controlsAWS · GCP · AzureComing soon
MITRE ATT&CK Framework46 techniquesAWS · GCP · AzureComing soon
ISMAP (Japan Government)126 controlsAWS · GCP · AzureComing soon
+ more on the roadmapDORA · NIS2 · CMMCComing soon
Price locked through March 2027

You've read 60 feature rows.

Either you're our buyer, or you're our competitor doing research. Either way — welcome. Connect read-only credentials and watch the scan run.