Start free. Upgrade when you need the fixes and the evidence.
Monitor up to 5 domains free, continuously. Paid tiers add the exact fix for every finding, faster scan cycles and audit-ready evidence across a larger estate.
Pricing shown in {cur} based on your region. You can switch currency anytime. Pricing shown in {cur}. You can switch currency anytime.
Plans
Free
Continuous Trust Score across your domains.
- Up to 5 domains, 10 monitored endpoints
- Trust Score across email, DNS, certificates and TLS
- Continuous monitoring, rescanned daily
- All findings with a remediation preview
- A value ledger of every issue we caught for you
- Email alerts
Starter
Hourly checks across a small team's domains.
- Up to 5 domains, 25 monitored endpoints
- Hourly monitoring across every trust module
- Plain-language fix explanations for every finding
- Email alerts and a weekly posture digest
- REST API with self-service API keys
Pro
Exact fixes and CT monitoring for any company with a public presence.
- Up to 25 domains, 100 monitored endpoints
- Remediation Center — exact fix, one-click re-verify
- Priority Fix Playbooks — findings become a prioritized fix plan with copy-paste fixes
- Certificate Transparency and subdomain-takeover detection
- DMARC analytics, TLS-RPT and browser security (CSP/NEL) reports
- Cyber-insurance readiness view and signed board report
- Slack & Teams alerts, 1-year history
Growth
For teams running a fleet of domains and services.
- Up to 250 domains, 1,000 monitored endpoints
- Single sign-on (SAML/OIDC) with SCIM provisioning
- Machine-identity inventory — internal agent and cloud CA connectors
- Issued-vs-deployed reconciliation against your own CA (EJBCA, Vault, AD CS, step-ca)
- Post-quantum readiness scoring and CBOM export
- Vanta, Drata, Jira & ServiceNow integrations
- Registrar and blacklist (RBL) monitoring, 2-year history, priority support
Enterprise
Regulated, NIS2-scope and large-portfolio organizations.
- 1,000+ domains, custom packs
- Signed NIS2 evidence and audit export
- eIDAS QWAC/QSealC, OV/EV registry and C2PA verification
- DMARC GeoMap, PagerDuty and n8n alerts
- Custom retention, SLA and procurement support
Prices exclude VAT. Annual billing saves at least 20%. You're billed in the currency you select at checkout.
What's included at each tier
| Capability | Free | Starter | Pro | Growth | Enterprise |
|---|---|---|---|---|---|
| Coverage | |||||
| Active domains | 5 | 5 | 25 | 250 | 1,000+ |
| Monitored endpoints (hosts we actively watch) | 10 | 25 | 100 | 1,000 | 5,000+ |
| Scan frequency | Daily | Hourly | Every 15 min | Every 5 min | Every 5 min |
| History retention | — | 6 months | 1 year | 2 years | Custom |
| Extra active domains | — | Add-on | Add-on | Add-on | Add-on |
| Find problems | |||||
| Trust Score (email, DNS, cert, TLS) | |||||
| Certificate & TLS health with expiry warnings | |||||
| Email spoofing protection checks (SPF, DKIM, DMARC) | |||||
| DNS security & domain registration (DNSSEC, transfer locks) | |||||
| Certificate Transparency monitoring (every cert issued in your name) | — | — | |||
| Forgotten-subdomain & takeover detection | — | — | |||
| Deep subdomain discovery for domains with verified ownership | — | — | — | ||
| DMARC report analytics & encrypted-mail delivery reports (TLS-RPT) | — | — | |||
| Browser security (CSP/NEL) reports for your websites | — | — | |||
| Registrar monitoring & mail blacklist (RBL) checks | — | — | — | ||
| Look-alike domains & takedown workflow | — | — | Add-on | Add-on | Add-on |
| Advanced CT (assurance & reconciliation) | — | — | Add-on | Add-on | |
| Fix them | |||||
| Remediation guidance | Preview | Plain-language explanations | Exact fix + one-click DNS apply & re-verify | Exact fix + one-click DNS apply & re-verify | Exact fix + one-click DNS apply & re-verify |
| Priority Fix Playbooks — prioritized fix plan, quick wins first | — | — | |||
| Alert channels | + Slack & Teams | + Slack & Teams | + PagerDuty & n8n | ||
| Weekly posture digest | |||||
| Value ledger — every issue SkyQon caught, on record | |||||
| Certificate auto-renew agent (ACME; keys stay on your servers) | — | — | Add-on | Add-on | Add-on |
| See everything you own | |||||
| Machine-identity inventory (external + internal certs, SSH keys) | — | — | — | ||
| Internal discovery agent & cloud CA connectors (AWS ACM, EJBCA) | — | — | — | ||
| Post-quantum readiness — HNDL risk scoring, vendor questionnaires & migration roadmap | — | — | — | ||
| Cryptographic bill of materials (CBOM export) | — | — | — | ||
| Prove it | |||||
| Signed NIS2 evidence reports (auditor-verifiable) | — | Add-on | Add-on | Add-on | |
| eIDAS qualified-certificate & OV/EV registry verification — 32 EU/EEA territories | — | Add-on | Add-on | Add-on | |
| Content-provenance (C2PA) signing-certificate monitoring | — | Add-on | Add-on | Add-on | |
| Signed evidence export bundles for auditors | — | Add-on | Add-on | Add-on | |
| Cyber-insurance readiness view (signed, broker-shareable) | — | — | |||
| Signed executive report for the board | — | — | |||
| Full audit-trail export | — | — | — | — | |
| DMARC failure GeoMap | — | — | — | — | |
| DORA supplier-trust evidence | — | — | Add-on | Add-on | Add-on |
| Supplier monitoring — grade the ICT third parties you buy from | — | Add-on | Add-on | Add-on | Add-on |
| Suppliers included with the add-on | — | 25 | 50 | 250 | 1,000 |
| Signed supplier register (Register of Information — PDF / CSV / verifiable) | — | Add-on | Add-on | Add-on | Add-on |
| Run it your way | |||||
| Single sign-on (SAML/OIDC) & SCIM provisioning | — | Add-on | Add-on | ||
| GRC & ticketing integrations (Vanta, Drata, Jira, ServiceNow) | — | — | — | ||
| Two-factor authentication & passkeys | |||||
| REST API & self-service API keys | 60 req/min | 300 req/min | 600 req/min | 6,000 req/min | 12,000 req/min |
| MSP & agency partner program (multi-client, white-label) | — | Add-on | Add-on | Add-on | Add-on |
| Custom retention & SLA | — | — | — | — | |
Monitored endpoints are the billed meter — a host we actively watch, such as api.example.com. Domain counts are fair-use guidance. "Add-on" means available on that plan as a priced add-on.
See everything. Fix what matters. Prove it.
Most tools blur the bad news until you pay. SkyQon does the opposite: every plan — including the free scan — shows you the complete diagnosis. Paid plans turn that diagnosis into a fix, and into evidence you can hand to an auditor.
You see the whole picture
No finding is hidden, blurred or teased — the diagnosis is always fully visible.
- Expiring and misconfigured certificates
- Spoofable domains — SPF, DKIM, DMARC and MTA-STS gaps
- DNS and DNSSEC weaknesses
- Exposed and shadow assets in your zones
- Look-alike domains and impersonation in Certificate Transparency logs
You get the fix
The diagnosis becomes an action plan your team can execute.
- The exact copy-paste fix for every finding
- One-click re-verify once you have applied it
- Priority Fix Playbooks — ranked, quick wins first
- Slack and Teams routing so the right person acts
You can prove it
Auditors and insurers no longer take screenshots as proof. Every SkyQon report is signed at the moment of measurement, so anyone can check it without taking our word for it — or yours.
- Signed NIS2 and DORA evidence reports, mapped to the regulations' own articles — CRA coverage included in the NIS2 pack
- A public verifier anyone can use — no account, and no access to your data
- eIDAS qualified-certificate checks against all 32 EU and EEA trust lists
- Verified fixes — a fix applied from SkyQon, re-measured by a later independent scan, recorded in your evidence report
No blurred-out findings. No fake urgency. You always know exactly where you stand, you choose when to let us fix it — and when someone asks you to prove it, the evidence is already signed and waiting.
Add specialist coverage to any plan
Layer these onto a subscription, or buy the one-time services standalone.
Advanced CT — Assurance & Reconciliation
Independent, recorded evidence that your certificates are really in the public CT logs — and a published view of every log we watch and how fresh each one is. Adds full issuance history including expired certificates, 3-year CT retention, issuance-velocity alerts and a signed issued-vs-deployed reconciliation report. Pairs with Pro or above.
Brand Protection
Look-alike domains, typosquats and homoglyphs surfaced with anti-phishing takedown workflows.
NIS2 Evidence Pack
Audit-ready reporting, evidence history and executive summaries with remediation status. Also unlocks the signed evidence export bundle, eIDAS qualified-certificate verification, OV/EV registry cross-checks and C2PA content-provenance monitoring.
Post-Quantum Roadmap
Cryptographic inventory, quantum risk scoring and an exportable migration roadmap.
Certificate Auto-Renew
Certificates renew themselves — our agent runs ACME on your servers (keys never leave them) and SkyQon proves every renewal happened. Built for the 47-day certificate era.
DORA Supplier Trust
Supplier-readiness trust page, ICT third-party monitoring and audit-ready DORA evidence for financial-sector teams and their vendors.
Supplier Monitoring
Register the ICT suppliers you buy from and grade each one's external trust surface — certificates, DNS and email authentication — re-checked daily, with alerts when a critical supplier slips. Export a signed, verifiable supplier register for your Register of Information. Evidence for your own registry and review process — not a compliance attestation, and neither NIS2 nor DORA mandates continuous supplier scanning.
Also available: extra domains from €5/domain/mo · extra suppliers on any Supplier Monitoring plan · agency sub-accounts · enterprise SSO à la carte on any paid plan · MSP & agency partner program.
Pricing questions, answered
Can I change plans later?
What counts as a domain or endpoint?
Can I buy compliance evidence or SSO without changing plans?
Is the free plan really free?
Where is my data hosted?
Do you offer MSP or partner pricing?
See where you stand in three minutes.
Run a free scan, get a scored report, and decide from there. No card, no agent.