Pricing

Free to start. Then it scales with accounts.

The number is on this page because that is where a price belongs. There is no demo to sit through and no form to fill in first.

Free
$0

Up to 3 AWS accounts, monitored continuously. Not a trial, and not a reduced catalogue — the same checks, the same score.

Start free
Metered
$40 / account / month

Above 3 accounts, billed on what you actually monitor. No seat count, no minimum, no annual commitment to unlock a feature.

Start free, add accounts later

Prices shown are provisional and will be confirmed before general availability.

Included everywhere

Including SSO.

Charging extra for the control that keeps an organisation’s accounts safe is the practice this category gets criticised for. It is in the free tier.

  • Every check we collect — the free tier is not a reduced catalogue
  • Well-Architected scorecard, all five pillars
  • The ranked queue, and API-driven completion
  • SSO / SAML and SCIM
  • Role-based access and signed access logs
  • The secure baseline templates
  • Cost reporting from CUR 2.0
The metered tier adds
  • Unlimited AWS accounts
  • Scheduled reports and email alerts
  • Full snapshot history and rule backfill
  • Priority support from the team that wrote the rules

Questions

Do I have to talk to sales to get started?

No. Create an account, deploy one CloudFormation stack, and you are scanning. There is no demo gate, no qualification call, and no form standing between you and the product. Sales exists for procurement and enterprise questions, not as the way in.

Is the free tier a crippled version?

No. The free tier collects the same checks, scores the same five pillars, and includes SSO. The limit is the number of AWS accounts monitored, not the depth of what you see in them.

Do I need an AWS support plan?

No — that is much of the point. We read ungated APIs and run our own rules. If you happen to have a support plan we will read Trusted Advisor too, as a cross-check, but nothing requires it.

Will this cost me money on my own AWS bill?

Reading your posture does not. AWS Config recording and Security Hub do bill, and they are what most of the Security Hub controls depend on — so we ship those as a separate, clearly-labelled second stack rather than switching them on inside the first one. That decision stays yours and stays explicit.

What access does StationChief have to my data?

Configuration metadata only. The audit role is SecurityAudit plus ViewOnlyAccess with an explicit Deny on data-plane reads — no s3:GetObject, no record reads, no secret values, and no writes anywhere. The template is published.

Can I cancel?

Yes, at any time, in the app. Delete the CloudFormation stack and our access is gone the same minute — the role lives in your account, not ours.

Something not answered here? Email us — but you don’t need to in order to start.

Start on the free tier.

No card, no demo, no sales call.