Skip to content

Pricing

Start free. 10K device checks a month, no card.

One device check is your app asking us to confirm a request came from real hardware. Pro is $99 for 250K checks. Business is $899 for 2.5M. Overage gets cheaper as you scale. Move the calculator below to find your cheapest plan.

Plans

One clear comparison

Free

$0

10,000 device checks / month

  • Works with every TPM chip vendor out of the box
  • All built-in strictness policies
  • Dashboard, live event feed, per-account ban list
  • Community support
Start free
Most popular

Pro

$99 / month

250,000 included · $1.50 / 1K overage

  • Everything in Free
  • Customer-authored acceptance policies
  • Email support · < 24h response
Start free, upgrade in-app

Business

$899 / month

2,500,000 included · $0.75 / 1K overage

  • Everything in Pro
  • Uptime + latency SLA
  • Priority email + Slack channel support
Talk to sales

Enterprise

Custom

Annual commit · volume pricing

  • Everything in Business
  • SOC 2 audit packet (in progress)
  • Old API versions keep working 90 days after we change them
  • Single-tenant deployment available
  • Named CSM · on-call escalation path
Contact sales

Calculator

Find your cheapest plan

Slide the inputs to your real numbers. The calculator picks the cheapest tier that covers your volume, shows the bill math, and estimates what you save versus the fake signups you absorb today (industry baseline: about $2 for every 1,000 that slip past a CAPTCHA).

From 100 to 1,000,000 (log scale)

Includes step-up + re-attest cadence (default 1.2)

% of attempted signups that are currently bots / fakes

Effective attestations / month

60,000

50,000 signups × 1.2 att/user

Your monthly Root Herald bill

$99.00

$99 base — 60,000 attestations ≤ 250,000 included

Recommended tier

Most popular

Pro

Pro covers your volume at the lowest total cost.

Projected savings vs CAPTCHA solver farms

At your current abuse rate, solver-farm cost is below the platform fee. The win is structural — once fakes can't bypass, attackers stop trying.

Feature matrix

Every feature, every tier

FeatureFreeProBusinessEnterprise
Volume
Included device checks / month10K250K2.5MCustom
Overage price (per 1K)$1.50$0.75Volume
Hard quota cutoff
Platform
Works with every TPM chip vendor
Built-in strictness policies
Write your own strictness policies
Deployment
Default (rootherald.io)
Single-tenant deployment
Support & SLA
Community / docs
Email support< 24hPriorityNamed CSM
Shared Slack channel
Uptime + latency SLA
SOC 2 audit packet (in progress)
Old API versions keep working after a change90 days90 days90 days90 days

Comparison

What you'd otherwise pay

Different tools, different failure modes. Here's the honest read: cost, user friction, and what eventually defeats each.

ApproachCostUser frictionDefeated by
CAPTCHA solver farms (Turnstile / hCaptcha bypass)$1–$3 per 1,000 solves to attackerVisible challenge to real usersDefeated by solver farms within hours
Fingerprinting (FingerprintJS Pro) + anti-detect browsers$200/mo for 100K + $30–60/mo anti-detect licenseSilent · but blocks legitimate privacy-conscious usersDefeated by GoLogin, Multilogin, AdsPower, Kameleo + residential proxies
KYC (Persona, Sumsub, Onfido)$0.50 – $3 per check + PII handling costGovernment ID + selfie: kills signup conversionDoesn't bind to device; valid ID + valid selfie still abusable at scale
Root Herald Shield$0 for 10K · $99 for 250K · $899 for 2.5MSilent · invisible to users · no PIICheap attacks (bots, cloud VMs, emulators) blocked outright; serious attacks now cost ~$30 of real hardware per device — and show up as a detectable cluster

FAQ

Pricing FAQ

What counts as a device check?

One metered unit per attestation check that reaches appraisal — the point where we actually evaluate the device evidence against a policy. That includes signup checks, step-up re-attests, and periodic posture re-checks. The eventual verdict doesn't change the bill: a pass, a warning, and a contraindicated (failed) verdict each count as one check, because each one did the work.

Requests rejected before appraisal are not billed: an invalid API key (401), an unknown policy (422), a malformed request (400), or an over-quota request (429) never reaches the verifier, so it never meters.

Do retries count?

Each challenge nonce is single-use, so retrying the same nonce can't be billed twice: a consumed or expired nonce is rejected rather than re-metered. Retries with a fresh nonce (e.g., the user got logged out and re-attested) count separately, which matches reality, since each is a separate device check with a separate cryptographic verdict.

What happens when I hit my Free-tier quota?

The Free tier has a hard quota cutoff. Once you hit 10,000 device checks in a calendar month, the API returns HTTP 429 quota_exceeded, and the quota resets at the start of the next calendar month. Paid tiers do not cut off; they bill overage at the per-1K rate listed.

You can upgrade in-app at any moment. The change applies immediately; the calendar-month quota resets and overage billing kicks in from that moment forward.

What if I need a self-hosted / on-prem deployment?

Enterprise tier only. We'll ship you a single-tenant container stack that stays current with the latest chip-maker trust roots and keeps your token-signing keys safe. Pricing is on a per-deployment basis; talk to sales.