Pricing
Compare all plans
Cushy runs two ways: self-hosted in your own infrastructure, or hosted by us. It is the same console either way — what differs is where it runs, the quotas, and who carries the operations. Anything not yet decided commercially says so.
HostedWe run it. Sign up, connect a cloud account, and the console fills with your real data.
Trial
Free
no credit card
Start free- 1 cloud account connected
- Live inventory + topology map
- Cost dashboard
- Reachability checks
- Community docs + support
Most popularPro
Let's talk
priced per org
Talk to us about Pro- Everything in Trial
- All four clouds, unlimited accounts
- Terraform engine: plan → approve → apply
- FinOps: FOCUS costs, budgets, anomalies
- Monitoring, alerts + incident timelines
- API tokens + pipelines
Enterprise
Custom
annual agreement
Contact us- Everything in Pro
- SAML 2.0 SSO + SCIM provisioning
- RBAC with audit exports
- Production approval policies
- Priority support + SLA (S1–S4)
Self-hostedYou run it, in your own infrastructure. Licensed with a signed key verified offline — no phone-home, air-gap friendly.
Free
$0
no licence key required
Talk to us about self-hosting- 1 user
- 1 cloud account
- 1 Terraform workspace
- 15 inventory resources
- 1 Git connection
- Runs entirely in your own network
- SSO, SAML and SCIM
- Application deploy agents
Lifts every quotaLicensed
Talk to us
signed licence key
Contact sales- Everything in Free, quotas lifted
- More users, workspaces and cloud accounts
- Unlimited inventory
- SSO: OIDC, SAML 2.0 + SCIM provisioning
- More than one organization in your deployment
- Application deploy agents
- Support from the team that builds it
| Feature | Self-hosted Free | Self-hosted Licensed | Hosted |
|---|---|---|---|
| QuotasThe free self-hosted tier runs with no licence key at all, under fixed limits. Licensed and hosted limits are part of the commercial conversation. | |||
| Users | 1 | Talk to us | Talk to us |
| Cloud accounts connected | 1 | Talk to us | Talk to us |
| Terraform workspaces | 1 | Talk to us | Talk to us |
| Synced inventory resources | 15 | Talk to us | Talk to us |
| Git connections | 1 | Talk to us | Talk to us |
| Deploy agents | Not included | Talk to us | Talk to us |
| Identity & accessEverything here is enforced server-side on every request — the console only hides what your role cannot do. | |||
| Password sign-in | Included | Included | Included |
| Multi-factor authentication (TOTP) | Included | Included | Included |
| Single sign-on (OIDC, your IdP) | Not included | Included | Included |
| SAML 2.0 | Not included | Included1 | Included1 |
| SCIM 2.0 provisioning | Not included | Included | Included |
| IdP group → role mapping | Not included | Included | Included |
| Custom roles | Not included2 | Not included2 | Not included2 |
| More than one organization | Not included3 | Talk to us3 | We operate the tenancy3 |
| PlatformEvery plan runs the SAME console — these rows are identical by design, and the notes say exactly where a capability is partial. | |||
| Inventory & network topology (all four clouds) | Included | Included | Included |
| Reachability analysis + live probe | Included4 | Included4 | Included4 |
| Terraform plan → approve → apply | Included5 | Included5 | Included5 |
| Blueprints: catalog, your own, Registry import | Included | Included | Included |
| Cost analytics & budgets (FOCUS) | Included6 | Included6 | Included6 |
| Monitoring, alerts & incident timelines | Included7 | Included7 | Included7 |
| Data catalog & governance findings | Included8 | Included8 | Included8 |
| AI assistant | Included9 | Included9 | Included9 |
| Deploy agents (build & ship an app repo) | Not included | Included | Included |
| In-console support desk (tickets) | Included10 | Included10 | Included |
| OperationsWho runs it, and what that means for licensing, network egress and upgrades. | |||
| Offline licence verification | No licence key needed | IncludedSigned key, verified locally | n/a — we run it |
| Air-gapped / egress-restricted operation | Included | Included | Not includedInternet service |
| Org-scoped audit trail | Included | Included | Included |
| Backups | Yours to run11 | Yours to run11 | Ours to run |
| Upgrade cadence | When you pull a new image | When you pull a new image | Continuously, by us |
| Support channel | Docs + community | Talk to us | Talk to us |
- SAML covers SP-initiated sign-in and single log-out (signed by your organization's own SP key). Encrypted assertions are not supported yet.
- Roles today are a fixed set — Viewer, Deployer, SRE · Cloud Admin and Org Admin, plus the organization Owner. Authoring your own role is not shipped on any plan, so no plan claims it.
- Cushy is multi-tenant: one self-hosted deployment can carry more than one organization, each provisioned from that deployment's own staff console. On the hosted service the tenancy is ours to operate.
- The static analyzer covers all four clouds. The live packet probe — real traffic, with the provider's own execution record as evidence — runs on AWS, Azure and Alibaba Cloud. Google Cloud has no ad-hoc run-command API, so there the verdict stays configuration analysis.
- An apply is recorded in the console (state, inventory, GitOps commit) until you explicitly enable real provisioning on a cloud account; then the same saved plan runs as a real OpenTofu apply with short-lived, keyless credentials.
- Billing ingestion is live for AWS, Azure and Alibaba Cloud. Google Cloud billing-export ingestion is not enabled yet — that account's cost stays empty rather than estimated.
- Per-resource CPU/memory/latency charts read a Prometheus-compatible collector you install on that resource. Alert rules evaluate the platform's own signals and do not need one.
- The data catalog classifies metadata only — exposure, encryption and residency, from attributes already synced. It does not count objects, measure bytes, or read any object's content.
- The assistant needs a model endpoint. A self-hosted stack can run the bundled local model profile; a hosted organization points at a provider endpoint.
- In a self-hosted deployment the ticket queue belongs to your own operators — it is not a channel to Snoweasl. Support from us is arranged with your licence.
- Self-hosted state lives in your Postgres volume, so the backup and restore policy is yours. Cushy does not run backups on your behalf.