Skip to content

Hermes Codex β€” Commercial Pricing & Enterprise Plans

πŸ›‘οΈ Transparent Subscriptions & Certified Audits

Section titled β€œπŸ›‘οΈ Transparent Subscriptions & Certified Audits”

Choose between flexible monthly/annual SaaS tiers or turnkey, one-shot diagnostic audit packs tailored for executive committee and board reporting without recurring commitment.

Monthly billing
Annual billing Save ~17%

Community

COMMUNITY

Understand the cyber world. Public intelligence, macro-observatory, and open research.

0 € /mo
Free forever
  • βœ“ Full access to 1,498+ intelligence & DFIR documents
  • βœ“ Threat Observatory macro-telemetry & stats
  • βœ“ Public CVE, KEV & EPSS intelligence lookups
  • βœ“ Forensic Autopsies & Historical Replays (read-only)
  • βœ“ Basic in-browser SBOM assessment
  • βœ“ Public STIX 2.1 bundles under Open Data license
Start Free Assessment →
Recommended

Professional

PRO

Understand your environment. Sovereign stack monitoring, risk trajectories, and decision directives.

158 € /mo
1900 € billed annually
  • βœ“ Everything in Community, plus:
  • βœ“ Sovereign "My Stack" persistent inventory (Zero-Upload)
  • βœ“ Personalized Daily Brief filtered on your exact stack
  • βœ“ Risk Trajectory & Velocity (Ξ”risk / Ξ”t) inflection monitoring
  • βœ“ Automated Webhooks (Slack, Teams, Discord, REST)
  • βœ“ Hermes Decision Engine prescriptive T0/T1 directives
  • βœ“ Falsifiable Forward Forecasts & Brier calibration
Try Professional →
For Teams & SOC

Team

TEAM

Operate with Hermes. Multi-stack workspaces, CLI daemon, Security Delta, and AI security.

658 € /mo
7900 € billed annually
  • βœ“ Everything in Professional, plus:
  • βœ“ Multi-stack workspaces & shared team inventories
  • βœ“ Automated CLI daemon for CI/CD runners & crontabs
  • βœ“ Security Delta transversal architecture comparator
  • βœ“ Agentic Security: Blast Radius & Death Simulator
  • βœ“ Decision Chain audit trail with team sign-off
  • βœ“ Priority technical support & implementation advice
Get Team Workspace →
Custom Governance

Enterprise

ENTERPRISE

Integrate Hermes. Dedicated pipelines, private TAXII feeds, custom scoring, and 99.9% SLA.

Custom quote
Tailored enterprise agreement
  • βœ“ Everything in Team, plus:
  • βœ“ Dedicated TAXII 2.1 collections and private CTI feeds
  • βœ“ Custom Hermes Threat Score (HTS) weighting aligned with internal risk policies
  • βœ“ Self-hosted / air-gapped on-premise Knowledge Graph and Software Intel deployment
  • βœ“ Tailored AI Agent Threat Models for sovereign LLM clusters and tools
  • βœ“ Chorus Pro public invoicing, security questionnaire reviews, and customized DPA
  • βœ“ Designated cyber threat intelligence lead analyst support & 99.9% SLA
Schedule Architecture Review →
✦ NO SUBSCRIPTION REQUIRED

Certified One-Shot Audit Packs

Fixed-price, turnkey diagnostic deliverables without recurring subscription. Ideal for French & European procurement orders (PO, virement SEPA, Chorus Pro).

Pack Audit NIS2 Express

490 € HT

Complete organizational and technical readiness diagnostic certified for Executive Committees and Boards.

Official Deliverable 30-page executive PDF report with gap analysis, legal disclaimers, and 90-day actionable remediation roadmap.
  • βœ“ Assisted self-assessment across all 10 core NIS2 operational domains
  • βœ“ Formal categorization: Essential Entity (EE) vs Important Entity (EI)
  • βœ“ Benchmark against ANSSI national transposition requirements
  • βœ“ Prioritized Top 5 critical compliance gaps and estimated remediation efforts
  • βœ“ Ready-to-present executive slides for Executive Committee / Board
  • βœ“ Delivered with formal audit signature and timestamp
Order NIS2 Express Audit →

Pack Audit SBOM & Supply-Chain

990 € HT

Comprehensive supply-chain risk evaluation for critical applications and client deliverables.

Official Deliverable Detailed technical report with Attack Path analysis, CISA KEV prioritization, and mitigation blueprint.
  • βœ“ Multi-SBOM consolidation up to 10 application repositories / microservices
  • βœ“ Zero-server privacy assurance: all parsing validated locally before compilation
  • βœ“ Exhaustive cross-referencing with CISA KEV, EPSS weaponization trends, and NVD
  • βœ“ Perimeter-to-Crown-Jewels attack trajectory identification
  • βœ“ Actionable remediation table with recommended clean target versions
  • βœ“ Compliance certificate verifying zero known exploited vulnerabilities for client procurement
Order SBOM Audit Pack →

Pack Audit Architecture Agent IA

1490 € HT

Specialized threat model and defense-in-depth review for agentic workflows, MCP tools, and sovereign LLMs.

Official Deliverable Security architecture audit report, trust boundaries matrix, and prompt injection mitigation blueprint.
  • βœ“ Trust boundary mapping across LLM, memory, RAG repositories, MCP, and database tools
  • βœ“ Formal evaluation of indirect prompt injection and tool poisoning vectors
  • βœ“ Privilege boundary check: tool execution permissions and secrets handling
  • βœ“ Hermes Agent Security Score (HASS) certification
  • βœ“ Concrete code guardrails and dual-LLM architectural blueprints
  • βœ“ 1-hour consultation with a Hermes Codex AI security architect
Order AI Agent Audit Pack →
β„Ή All prices are in EUR excluding applicable VAT (HT). Invoicing available via Purchase Order, SEPA wire, and Chorus Pro.
πŸ“Š Detailed Technical Matrix (50+ Capabilities Compared) Expand Matrix β–Ύ

Exhaustive comparison of telemetry ingestion, sovereign local computing, forward trajectories, and decision-automation capabilities.

Capability & Feature Community Professional Team Enterprise
1. Intelligence, Telemetry & CTI Feeds
1,498+ DFIR dossiers, CTI briefs & methodologies βœ“ βœ“ βœ“ βœ“
Threat Observatory global macro-telemetry & stats βœ“ βœ“ βœ“ βœ“
Public CVE, CISA KEV & real-time EPSS velocity βœ“ βœ“ βœ“ βœ“
Canonical Observation Model (OBS-*) traceability βœ“ βœ“ βœ“ βœ“
STIX 2.1 & TAXII 2.1 Feeds Public static Filtered exports Full TAXII client Dedicated TAXII Server
Public Daily Threat Brief βœ“ βœ“ βœ“ βœ“
Personalized Daily Brief filtered on your stack β€” βœ“ βœ“ βœ“
SIEM Connectors (Sentinel, OpenCTI, MISP) β€” Client snippets βœ“ Bi-directional sync
2. Analysis & Sovereign Perimeter
Client-side SBOM parser (CycloneDX / SPDX) βœ“ βœ“ βœ“ βœ“
Zero-Upload sovereign privacy guarantee βœ“ βœ“ βœ“ βœ“
Persistent "My Stack" inventory β€” 1 local stack Unlimited multi-stacks Full enterprise tenant
Instant Demo Presets (Cloud, AI Agent, Acme Corp) βœ“ βœ“ βœ“ βœ“
NIS 2 compliance gap diagnostics Preview βœ“ βœ“ βœ“
Supply chain graph & deep dependency traversal Direct Depth 3 Full recursive Custom ontology
Security Delta transversal comparator β€” β€” βœ“ βœ“
Webhook dispatcher (Slack/Teams/Discord/REST) β€” Browser CLI Daemon Enterprise Bus / Kafka
3. Temporal Trajectories & Predictions
Historical Replay & Time Machine Sample events βœ“ βœ“ βœ“
Risk Trajectory Engine & velocity inflection β€” βœ“ βœ“ βœ“
Vulnerability Genome (16 chromosomes) Read-only βœ“ βœ“ βœ“
Falsifiable Forward Forecasts Public selection βœ“ βœ“ βœ“
Historical Calibration & public Brier Score βœ“ βœ“ βœ“ βœ“
Snapshot Differential (T0 vs T1) β€” βœ“ βœ“ βœ“
Forensic Autopsies (Incident Anatomy) 10 autopsies All 35+ All + Custom Dedicated autopsy
Agent Death Simulator & cascade breakdown β€” β€” βœ“ βœ“
4. Decisions & Remediations
Decision Chain prescriptive engine Generic guides βœ“ βœ“ βœ“
T0 containment & T1 root-cause action plans Generic βœ“ βœ“ βœ“
Decision sign-off history & team audit trail β€” Local Shared team Certified ledger
Export formats (JSON, CSV, Markdown, STIX) JSON / MD βœ“ βœ“ Custom schemas
Standalone CLI daemon (`hermes-stack`) β€” β€” βœ“ βœ“
CI/CD Gate Integration (build breaker on risk) β€” β€” βœ“ βœ“
SOC Ticketing Sync (Jira, ServiceNow) β€” β€” β€” βœ“
5. AI & Agentic Security
Agent Blast Radius analyzer β€” βœ“ βœ“ βœ“
MITRE ATLAS threat matrix mapping βœ“ βœ“ βœ“ βœ“
Model Context Protocol (MCP) tool audit β€” β€” βœ“ βœ“
Agentic Security Score (0-100 benchmark) β€” βœ“ βœ“ βœ“
6. Governance, Deployment & Support
Sovereign static hosting (100% EU) βœ“ βœ“ βœ“ βœ“
Air-gapped / Sovereign on-premise deployment β€” β€” β€” βœ“
Procurement billing (PO, Chorus Pro, SEPA wire) β€” β€” βœ“ βœ“
Technical support & SLA guarantee Community 48h email 12h ouvrΓ© 1h 24/7 dΓ©diΓ©
Dedicated CTI analyst & custom ontology β€” β€” β€” βœ“
SSO / SAML enterprise authentication β€” β€” β€” βœ“

πŸ’¬ Frequently Asked Questions

What do I get with Hermes Codex?

Hermes is not an alert-spamming scanner. You get a comprehensive Cyber Risk Intelligence engine: 1,498+ DFIR dossiers, real-time KEV/EPSS correlation, exploit trajectory tracking, and a prescriptive decision engine that turns observations into immediate containment (T0) and lasting root-cause remediations (T1).

Who is each tier designed for?

Community (€0) is designed for researchers and students. Professional (€190/mo) is tailored for solo CISOs and lead SecOps managing their personal perimeter. Team (€790/mo) empowers SOC and engineering teams to coordinate and enforce risk gates in CI/CD. Enterprise serves regulated entities requiring air-gapped deployments or private dedicated TAXII feeds.

What fundamentally changes when I subscribe?

In Community, you observe the world's threat landscape. With Professional or Team, Hermes operates in active sovereign mode: your Daily Brief, trajectory inflections, and webhook alerts are strictly filtered against your exact technology stack, eliminating 98% of irrelevant CTI noise.

What happens to my confidential SBOM & stack data?

Absolute sovereignty guarantee: all SBOM parsing, vulnerability mapping, and risk computations execute 100% locally in your browser or local CLI runner. No component inventory, repository code, or architecture manifest is uploaded to our servers.

Can I test all capabilities before subscribing?

Yes, immediately with no credit card required. Head over to "My Stack" or the "SBOM Analyzer" and click any of our 3 Instant Demo Presets (Cloud & Microservices, AI Agent & Python, Acme Corp) to experience the full risk trajectory and webhook dispatcher flow.


πŸ” How Hermes Codex Differs from Legacy Scanners

Section titled β€œπŸ” How Hermes Codex Differs from Legacy Scanners”

Legacy software scanners flood teams with thousands of theoretical CVEs, burning hundreds of engineering hours on vulnerabilities that are neither weaponized nor reachable. Hermes Codex applies multi-source threat intelligence, exploit maturity tracking, and graph-based attack path modeling to isolate true risk.

Zero-Server Privacy by Design

Your SBOM files, dependency graphs, and code repositories never leave your workstation. Unlike conventional SaaS platforms that ingest your intellectual property into remote databases, Hermes Codex compiles all findings client-side in WebAssembly/JavaScript.

Hermes Threat Score (HTS vs CVSS)

CVSS evaluates theoretical severity in isolation. The Hermes Threat Score (HTS) incorporates active CISA KEV exploitation, real-time EPSS weaponization velocity, and component exposure to compute operational risk.

Epistemic Rigor & Provenance

Every finding is strictly categorized:

βœ“ FACT ⚑ INFERENCE β–² PREDICTION

No speculative AI hallucinations presented as ground truth.

Agentic AI Threat Modeling

Evaluate risks unique to autonomous AI agents, tool poisoning, MCP protocol abuse, memory exfiltration, and indirect prompt injection through our dedicated AgentThreat Studio.


Can we pay via Purchase Order (PO) and SEPA wire transfer?

Yes. Both Business and Enterprise annual subscriptions, as well as all One-Shot Audit Packs, can be invoiced via corporate Purchase Orders, French public procurement (Chorus Pro), or international SEPA wire transfers with standard net-30 payment terms.

What is the deliverable for One-Shot Audit Packs?

One-Shot Audit Packs produce a comprehensive, publication-grade executive PDF dossier signed and stamped by Hermes Codex. It includes executive summaries for non-technical executives, prioritized technical remediation tables, attack trajectory graphs, and 30/60/90-day roadmaps.

Is my data shared with third-party AI models?

No. Your architecture details, dependency manifests, and responses stay strictly inside your local browser runtime. Hermes Codex does not train models on customer inventories and does not relay proprietary SBOMs to external APIs.

πŸ”’ Data Provenance & Verification ● VERIFIED ARTIFACT
Authoritative Source Hermes Commercial Governance & Pricing Engine v1.0
Harvested Date 2026-09-14
Certified Confidence High
Extraction Method Deterministic pricing rules and formal enterprise procurement packaging