Pay only for the pipelines you protect. Start with a focused deployment, prove the model, and expand enforcement as you grow.



For validating on a focused set of critical pipelines before expanding deployment.
$500
/Pipeline/Year

Up to 25 protected pipelines
Full runtime enforcement
Automated policy generation
Unlimited pipeline discovery
For growing teams ready to protect production pipelines across their CI/CD environment.
$500
/Pipeline/Year

Up to 300 protected pipelines
Everything in Pilot
Notification integrations
Multi-provider CI/CD coverage
For security teams standardizing runtime policy across a growing pipeline estate.
Volume
Pricing
Up to 2,500 protected pipelines
Everything in Startup
Graduated volume pricing
Analytics and reporting
For organizations standardizing across environments and operating models.
Custom
Pricing

Enterprise-scale coverage
Everything in Business
Managed or Self-Hosted
Multi-business-unit deployments
Core protection in every plan:
Team Server
Centralize pipelines, policies, builds, and violations in one operational view for easier security management.
Runtime Sensor
Observe and control build behavior from the Linux kernel using eBPF for deep runtime visibility.
Pipeline Discovery
Discover your CI/CD estate and bring pipeline visibility into one place across teams and environments.
Policy Derivation
Generate least-privilege baselines automatically from real build behavior and refine them before enforcement.
Runtime Enforcement
Block unauthorized operations at execution using kernel-level policy enforcement before they can cause damage.
Violation Triage
Investigate what ran, what was attempted, and how policy responded with the context needed to act.
FAQs are updated regularly based on real customer feedback.

01
Isn’t this what SCA, SAST, and attestation already do?
No. SCA tells you what’s in your build. SAST finds flaws in code. Attestation proves where software came from. Endura controls what that software is allowed to do when it runs, enforcing runtime boundaries in the kernel before unauthorized actions complete. Endura complements these tools rather than replacing them.
02
Does Endura actually block attacks, or just detect them?
Endura is built for prevention, not just detection. Runtime Sensor uses eBPF Linux Security Module hooks to evaluate security-sensitive operations in the kernel and reject unauthorized actions before they execute. Where eBPF LSM is unavailable, Endura can fall back to monitoring and terminate offending processes after detection.
03
How do I enforce least privilege without breaking my builds?
Start by deriving policy from real pipeline behavior, then validate it in observe mode without blocking anything. Once the policy reflects expected behavior, switch to enforce mode to block anything outside the boundary.
04
Will Endura work with my existing CI/CD and Linux environment?
Endura integrates with GitHub Actions, GitLab CI/CD, Jenkins, Bamboo, and TeamCity, while Runtime Sensor supports major Linux distributions on x86_64 and ARM64. Sensors can be installed natively or deployed with Docker, Podman, and Kubernetes.
05
Can Endura be fully self-hosted?
Yes. Enterprise customers can self-host the complete Endura stack, including Team Server and Runtime Sensors, in infrastructure they control. Team Server supports Docker, Podman, and Kubernetes deployments across on-premises and private-cloud environments, with OIDC authentication and granular role, resource, and policy access controls.
Turn pipeline activity into visibility, policy, and action with Endura.

Endura enforces what your pipeline is allowed to do at the kernel level, blocking unauthorized network connections, file access, and process execution as they happen. Let us show you what that looks like on a real build.
