Skip to main content
Pricing

One agent. One bill.
No module sprawl.

Start with a 14-day Starter trial. Starter is a flat bundle up to 30 hosts; Growth is per active host when your fleet needs daily cadence and API workflows.

Starter $249/mo up to 30 hostsGrowth $22/host/mo across the active fleetEnterprise volume pricing for larger estates

Want to see it before you install? Explore the live demo →

Starter
Full posture coverage for small teams.
$249/ month
up to 30 hosts
$249/mo for 1-30 hosts
Includes
Up to 30 hosts
Weekly compliance, package, CVE & port scans
All standard benchmarks
Ad-hoc verification rescans included
Remediation guidance and scripts
3 team members · 1 workspace
30-day scan history
Email support
Enterprise
Regulated, large-fleet, or air-gapped estates.
Custom
volume pricing · let's talk
Everything in Growth, plus
Unlimited hosts, members & workspaces
Air-gapped / self-hosted deployment
SSO / SAML (logins)
No scan-cadence limit
Unmetered ad-hoc rescans
2-year scan history
Priority support
Why oxharden

Your scanner finds the risk.
oxharden verifies what's still running.

Scanners are great at finding vulnerable packages. oxharden adds host-level evidence for what still needs an update, restart, reboot, or compliance review.

Scanner-only workflowoxharden
Detects vulnerable packages on disk
Checks running-code state
Reports "fixed" once the package updates
Flags services still mapping the old library
Restart / reboot debt
Manual investigation
Shows restart / reboot action
Remediation priority
CVSS score lists
Ranks by KEV, EPSS, exposure, and affected host context
Compliance evidence (CIS / DISA STIG)
Separate tool or add-on
Built-in evidence from the same host context
Time to first result
Scanner infrastructure, consoles, tuning
One-host snapshot in minutes; fleet rollout when ready

Comparison describes common scanner-only workflows. It is not a claim about any specific vendor product.

Compare

Key plan differences, side by side.

Starter
$249 / mo
Growth
$22 / host
Enterprise
Custom
Infrastructure
Active hosts30Unlimited
Team members3Unlimited
Workspaces1Unlimited
Scanning
Scan cadenceWeeklyNo limit
Compliance (OS) scans
Ad-hoc rescansIncluded fair useUnmetered
Package & CVE scanning
Network port scanning
Live (applied ≠ live) tracking
Compliance
BenchmarksAll standardAll standard
Guided Remediation
Bulk compliance & audit exports
Data & access
Scan history30 days2 years
API access (PAT)
SSO / SAML
Air-gapped / self-hosted
SupportEmailPriority
Get started

See what your Linux fleet is really running.

Review a sample Patch Truth report, then start a 14-day trial to verify live fixes, restart debt, exposure, and compliance evidence on up to 30 of your own hosts.

Prefer to click around first? Explore the live demo, or book a guided walkthrough.
install.sh
curl -fsSL https://packages.executepath.dev/install.sh \
  | sudo EXPECTED_GPG_FINGERPRINT=13094D5AB037E6CD79CDFA3A51687EAC6B931A09 bash
agent enrolled · ip-10-20-2-107
live state synced · kernel · packages · ports
first scan complete · 3 restart debts · 1 reboot pending
Billing FAQ

Questions about pricing.

The trial runs for 14 days with Starter entitlements: up to 30 hosts, weekly scheduled scans, all standard benchmarks, and the Starter ad-hoc rescan pool. Growth-only features such as API access and bulk compliance and audit exports unlock after upgrade.

A host is any enrolled system that is active, or was retired or decommissioned within the last 7 days. Starter includes up to 30 host slots; Growth bills the full active fleet at the per-host rate.

Retiring or decommissioning removes the host from live fleet views immediately, but its slot can remain counted for 7 days to preserve history and prevent rapid slot reuse. Historical scan data stays available according to your plan's retention window.

No. Host capacity is based on active hosts plus recently retired or decommissioned hosts. Rotating hosts through the same plan still consumes capacity during the 7-day reuse window.

An ad-hoc scan is any scan you start manually with Scan now, such as a compliance scan, package/CVE scan, port scan, or container scan. Ad-hoc usage is metered as host-scans: one host times one scan type.

For compliance, one manual action may dispatch the right benchmark for each OS in scope, but each host still counts once for that compliance scan type.

Scheduled scans do not count against your ad-hoc rescan pool.

Yes. Upgrades take effect immediately. To enroll a 31st host, you'll need to move to Growth, where all monitored hosts are billed at the Growth per-host rate. Downgrades require your active usage to fit within the lower plan.

Growth is self-serve up to 300 hosts. Larger fleets can use volume pricing through Enterprise so we can scope host count, retention, support, deployment requirements, and contract terms.

Trial and Starter retain 30 days of scan history. Growth retains 1 year. Enterprise retains 2 years by default, with longer retention scoped separately when required.

Not as a standard self-serve deployment today. oxharden was built with the foundations needed for self-hosted and air-gapped Enterprise environments, including agent-based collection, offline content workflows, and controlled update paths. If those are hard requirements, we can scope them with your team.

oxharden supports regulated Linux hardening workflows today, including CIS and DISA STIG evaluation and FIPS-related host checks. Formal FedRAMP, FIPS 140, and agency-specific deployment requirements are handled through Enterprise scoping so we can define the controls, architecture, and evidence needed before committing.