Billing here is deliberately small: Free, Pay-per-use, or Pro, with the same complete feature set on both paid plans. Pick usage billing or included monthly credits. Stripe handles the payment and may appear as LINK.COM* on your statement; here is how the plans, action credits, changes, and invoices fit together.
Free, Pay-per-use, and Pro
Free is a permanent starter tier. Pay-per-use and Pro unlock the same paid capabilities: Advanced AI, Advisor, reports, imports, collaboration, SSO, REST API, and MCP. Their feature access is identical; the difference is how credits and member capacity are paid for.
| Free | Pay-per-use | Pro | |
|---|---|---|---|
| Price | Free, always | €0 base + €0.01 per successful credit before tax | €19.95 before tax / bundle / month |
| Users | 1 | 10 | 20 with one bundle; +10 per additional bundle |
| Action credits | Not shown | No included credits; monthly cap | 4,000 per bundle each billing period |
| Observations | 10 | Unlimited | Unlimited |
| Evidence storage | 25 MiB | 2 GiB per organization | 2 GiB per organization |
| AI engine | Built-in fallback model | Advanced AI included | Advanced AI included |
Free is a real tier, not a time-bomb trial. It runs indefinitely inside its limits. Pay-per-use has no recurring base fee and bills successful actions monthly. Pro bundles predictable included credits with more team capacity.
Usage billing or included credits
Pay-per-use has a €0 recurring base and costs €0.01 before tax per successful action credit. Stripe invoices usage monthly in arrears. You set a finite monthly cap from 0 to 5,000 credits (2,500 by default), so usage cannot run past the amount you authorized. Failed, cancelled, or released actions are not billed. Pay-per-use supports up to 10 members.
Pro is €19.95 before tax per bundle, per month. Each bundle includes 4,000 action credits. One bundle supports up to 20 members; every additional bundle adds another 10 member slots. Paid evidence storage is a fixed 2 GiB shared by the organization on either paid plan.
One complete enriched observation costs 100 credits, or €1 before tax on Pay-per-use. That single action covers the full draft: description and summary, risk assessment, recommendations, tags and framework mapping, plus duplicate and relation checks. Internal model calls and retries are included. You pay once when the draft completes; saving it does not consume another 100 credits. Creating an observation without AI enrichment uses the same 100-credit action price.
| Successful action | Credits | Pay-per-use price before tax |
|---|---|---|
| Create enriched observation | 100 | €1.00 |
| Reassess risk | 20 | €0.20 |
| Advisor message | 40 | €0.40 |
| Apply Advisor suggestions | 40 | €0.40 |
| Generate report | 200 | €2.00 |
| Revise report | 200 | €2.00 |
| Analyse PDF report | 100 | €1.00 |
| Run OSINT scan | 50 | €0.50 |
Prices apply only when the action succeeds. Failed, cancelled, and released work is not billed.
Advanced AI comes with both paid plans
The AI that drafts your findings, reassesses risk, and runs the advisor chat has a better engine on Pay-per-use and Pro, included with nothing to configure. The managed tier defaults to Anthropic (Claude), chosen for richer, more accurate output, processed in the US under our DPA and Zero Data Retention agreement with no training on your data. Organisations that need EU data residency can switch the managed tier to Mistral (a European, EU-based provider with EU data centres, under a DPA and zero data retention) in one click. Free runs on a built-in fallback model so its included AI features still work; either paid plan switches the organisation to Advanced AI.
If GPT is your house standard, either paid plan can switch the managed tier to OpenAI (GPT-5.6, processed in the US under the same DPA and no- training posture). The provider choice is per organisation and takes one click in Account settings.
If you'd rather run your own provider for data-sovereignty reasons, you can bring your own key (OpenAI, Anthropic, or Mistral) and it takes priority over ours. That's an option, not a requirement. Out of the box, paid access just works.
What changes now, and what waits for renewal
Moving from Pay-per-use to Pro is immediate. Before you confirm, SecurityTrackr asks Stripe for the exact amount due, including accrued Pay-per-use activity, tax, and the new Pro charge. A successful change starts a full Pro bundle with 4,000 credits. Moving from Pro to Pay-per-use is scheduled for renewal, so you retain the Pro period and credits you already paid for.
Pro bundle changes have one extra guard rail: you get one bundle change per billing cycle. Here's how the two directions behave:
- Upgrades apply immediately. Add bundles and they're live now, with the prorated difference billed straight away and proportional action credits granted for the remaining cycle.
- Downgrades wait for renewal. Remove bundles and you keep the current-period credits until the cycle ends; the lower bundle grant takes effect at renewal.
Either way, that's your one Pro bundle change, and the bundle controls lock behind it. The app spells out why:
To prevent accidental charges, SecurityTrackr allows one subscription change per billing cycle. Your next change unlocks at renewal.
A scheduled bundle downgrade can always be called off. Hit Cancel scheduled change on the banner and the pending change clears and the lock lifts, so you can make a different change. Cancelling a pending change isn't counted against you. So the three states you'll ever see are simple:
- Clean. No Pro bundle change this cycle. Adjust bundles freely.
- Locked. You upgraded Pro bundles this cycle. Further bundle changes wait for renewal.
- Pending. You scheduled a Pro bundle downgrade for renewal. Let it ride, or cancel it to unlock.
Who's Stripe, and why does my statement say LINK.COM*?
You buy through Stripe. You get SecurityTrackr. And the line on your card statement reads LINK.COM* SecurityTrac, which can look odd if you weren't expecting it, so here's the why.
Stripe is our merchant of record, selling through its checkout brand, Link. That means Stripe is the company that actually sells you the subscription and takes the payment, while we provide the service behind it. They handle checkout, card processing, invoices, and (the big one) sales tax and VAT compliance across every country we sell into, including the EU B2B reverse-charge when you buy with a VAT number. We'd rather build a security register than run a global tax department, so we don't.
- Your card never touches our servers. Checkout happens on Stripe's own hosted page. The app hands you over and takes you back. We never see or store card details; we only hear back that a payment succeeded.
- The statement line is Link's. Charges appear as LINK.COM* SecurityTrac, with the receipt naming SecurityTrackr ApS as the provider. That's the charge for your SecurityTrackr paid plan or usage.
- Payment method and invoices live with Stripe. Updating a card or pulling past invoices goes through Stripe's billing portal, reachable from your subscription page.
- Stripe tells us what changed. When you pay, renew, or cancel, Stripe notifies the app and we flip your plan to match. Those notifications are the single source of truth for your billing state, so the app always reflects what you actually paid for.
Renewals, cancelling, and your data
At each Pro renewal the cycle rolls over and the change lock clears, so a new billing period is a clean slate for bundle changes and grants a fresh included-credit allowance.
Cancel whenever you like. Pro remains active until the end of the period you've already paid for and can be resumed before then. Pay-per-use cancellation is immediate after SecurityTrackr finishes syncing successful outstanding usage to Stripe for the final invoice. In either case, the organization returns to Free.
Dropping to Free, whether by cancelling or downgrading, doesn't delete anything. Your observations, companies, and evidence stay put. The Free limits just apply going forward, so you can't add past the caps until you're back under them. If a scheduled bundle decrease leaves you above the future member limit, nobody gets kicked out; existing members are grandfathered, and you simply can't invite new ones until your member count is back under the new limit.
