Pricing

Compare all plans

Cushy runs two ways: self-hosted in your own infrastructure, or hosted by us. It is the same console either way — what differs is where it runs, the quotas, and who carries the operations. Anything not yet decided commercially says so.

HostedWe run it. Sign up, connect a cloud account, and the console fills with your real data.
Trial
Free
no credit card
Start free
  • 1 cloud account connected
  • Live inventory + topology map
  • Cost dashboard
  • Reachability checks
  • Community docs + support
Enterprise
Custom
annual agreement
Contact us
  • Everything in Pro
  • SAML 2.0 SSO + SCIM provisioning
  • RBAC with audit exports
  • Production approval policies
  • Priority support + SLA (S1–S4)
Self-hostedYou run it, in your own infrastructure. Licensed with a signed key verified offline — no phone-home, air-gap friendly.
Free
$0
no licence key required
Talk to us about self-hosting
  • 1 user
  • 1 cloud account
  • 1 Terraform workspace
  • 15 inventory resources
  • 1 Git connection
  • Runs entirely in your own network
  • SSO, SAML and SCIM
  • Application deploy agents
Feature comparison across Self-hosted Free, Self-hosted Licensed and Hosted plans
FeatureSelf-hosted FreeSelf-hosted LicensedHosted
QuotasThe free self-hosted tier runs with no licence key at all, under fixed limits. Licensed and hosted limits are part of the commercial conversation.
Users1Talk to usTalk to us
Cloud accounts connected1Talk to usTalk to us
Terraform workspaces1Talk to usTalk to us
Synced inventory resources15Talk to usTalk to us
Git connections1Talk to usTalk to us
Deploy agentsNot includedTalk to usTalk to us
Identity & accessEverything here is enforced server-side on every request — the console only hides what your role cannot do.
Password sign-inIncludedIncludedIncluded
Multi-factor authentication (TOTP)IncludedIncludedIncluded
Single sign-on (OIDC, your IdP)Not includedIncludedIncluded
SAML 2.0Not includedIncluded1Included1
SCIM 2.0 provisioningNot includedIncludedIncluded
IdP group → role mappingNot includedIncludedIncluded
Custom rolesNot included2Not included2Not included2
More than one organizationNot included3Talk to us3We operate the tenancy3
PlatformEvery plan runs the SAME console — these rows are identical by design, and the notes say exactly where a capability is partial.
Inventory & network topology (all four clouds)IncludedIncludedIncluded
Reachability analysis + live probeIncluded4Included4Included4
Terraform plan → approve → applyIncluded5Included5Included5
Blueprints: catalog, your own, Registry importIncludedIncludedIncluded
Cost analytics & budgets (FOCUS)Included6Included6Included6
Monitoring, alerts & incident timelinesIncluded7Included7Included7
Data catalog & governance findingsIncluded8Included8Included8
AI assistantIncluded9Included9Included9
Deploy agents (build & ship an app repo)Not includedIncludedIncluded
In-console support desk (tickets)Included10Included10Included
OperationsWho runs it, and what that means for licensing, network egress and upgrades.
Offline licence verificationNo licence key neededIncludedSigned key, verified locallyn/a — we run it
Air-gapped / egress-restricted operationIncludedIncludedNot includedInternet service
Org-scoped audit trailIncludedIncludedIncluded
BackupsYours to run11Yours to run11Ours to run
Upgrade cadenceWhen you pull a new imageWhen you pull a new imageContinuously, by us
Support channelDocs + communityTalk to usTalk to us
  1. SAML covers SP-initiated sign-in and single log-out (signed by your organization's own SP key). Encrypted assertions are not supported yet.
  2. Roles today are a fixed set — Viewer, Deployer, SRE · Cloud Admin and Org Admin, plus the organization Owner. Authoring your own role is not shipped on any plan, so no plan claims it.
  3. Cushy is multi-tenant: one self-hosted deployment can carry more than one organization, each provisioned from that deployment's own staff console. On the hosted service the tenancy is ours to operate.
  4. The static analyzer covers all four clouds. The live packet probe — real traffic, with the provider's own execution record as evidence — runs on AWS, Azure and Alibaba Cloud. Google Cloud has no ad-hoc run-command API, so there the verdict stays configuration analysis.
  5. An apply is recorded in the console (state, inventory, GitOps commit) until you explicitly enable real provisioning on a cloud account; then the same saved plan runs as a real OpenTofu apply with short-lived, keyless credentials.
  6. Billing ingestion is live for AWS, Azure and Alibaba Cloud. Google Cloud billing-export ingestion is not enabled yet — that account's cost stays empty rather than estimated.
  7. Per-resource CPU/memory/latency charts read a Prometheus-compatible collector you install on that resource. Alert rules evaluate the platform's own signals and do not need one.
  8. The data catalog classifies metadata only — exposure, encryption and residency, from attributes already synced. It does not count objects, measure bytes, or read any object's content.
  9. The assistant needs a model endpoint. A self-hosted stack can run the bundled local model profile; a hosted organization points at a provider endpoint.
  10. In a self-hosted deployment the ticket queue belongs to your own operators — it is not a channel to Snoweasl. Support from us is arranged with your licence.
  11. Self-hosted state lives in your Postgres volume, so the backup and restore policy is yours. Cushy does not run backups on your behalf.