InvisiRisk Introduces Starter Pricing Tier for Standalone Build Application Firewall

New tier gives teams with existing SCA tools a more economical way to add real-time build-time protection while continuing to use their current software composition analysis platforms.

Houston, TX – InvisiRisk has introduced a new Starter pricing tier for organizations that want to deploy its Build Application Firewall (BAF) while continuing to use existing software composition analysis (SCA) tools.

The new tier provides InvisiRisk’s core Build Application Firewall capabilities separately from the additional SCA, build analysis, compliance, and governance features available in the company’s Pro and Enterprise offerings. Starter is designed for teams that already have SCA technology in place or simply are not looking to consolidate their application security platforms.

InvisiRisk protects CI/CD pipelines and build systems while the build is actually running, adding real-time policy enforcement to help stop build-time tampering, credential and intellectual property exfiltration, suspicious “phone home” behavior, unauthorized network activity, and other malicious activity that traditional security tools often miss.

The Build Application Firewall sits inline with the build process and uses deep packet inspection to observe network activity in real time. Security policies can allow, warn, or block activity based on defined security rules, giving organizations an additional layer of protection against software supply chain attacks, including threats that may not yet be known to traditional vulnerability scanners.

The Starter plan is priced at $2,500 per month, or $2,000 per month when billed annually, and includes 250 build credits per month. There is no per-user pricing. InvisiRisk also offers Pro and Enterprise tiers for organizations that want to combine the BAF with software composition analysis, build analysis, compliance, and governance capabilities.

The updated pricing structure reflects the wide range of security tools already deployed across DevOps and DevSecOps environments. Organizations can use InvisiRisk alongside their existing SCA and application security tools to add visibility and enforcement at a layer that those products typically do not address: what is actually happening while the software build is running.