Single binary, host-priced, no agent. Every tier ships with the complete check catalogue and every remediation playbook — no paywalled features. You pay for the host count, the support level and the integrations you actually use.
For consultants and one-person blue teams.
For internal blue teams + small MSSPs.
For multi-tenant managed-security shops.
For regulated estates with bespoke requirements.
Every Obexum subscription gets the full audit catalogue. Higher tiers add scale, integrations and support.
569 forensic checks — ADCS ESC1-15, Kerberos, ACL, GPO, persistence, privesc, UAC bypass, hardening baselines. Every tier, day one.
Every fix Obexum knows how to render is available to every tier. No "Pro-only" remediations.
Branded HTML, print-to-PDF, JSON, SARIF, Markdown. Engagement directories ship in every tier.
No. Obexum runs from a jump-box and connects to the target via SSH or WinRM with the credentials you already use.
Only if you opt into the SaaS portal (Team+) for cloud-side history. Solo + on-prem Enterprise are 100% local.
One host = one named target you scan, regardless of frequency. A DC counts as one host even if scanned hourly.
14 days, no credit card. Keep every artifact you generate. No telemetry. Convert with one form.
Yes. Subscriptions are month-to-month or annual. Cancellation stops renewal — you keep all engagements.
Yes — 50% off Team for verified non-profits and accredited education institutions. Contact us.