Skip to content

How much does the ProwlerPro service cost?

  • We charge $0.001 per resource scanned per day.
  • Resource can be scanned multiple times the same day at no additional charge. No matter how many times resources get scanned each day, you will pay $0.001 per resource per day.
  • If your usage costs less than $10/month, we won’t send a bill for that month.


Calculating what you will pay with ProwlerPro is very straightforward, here are some examples:

Resources Scanned per Day Monthly Bill (USD)
300 FREE
400 $12
10,000 $300
500,000 or more CONTACT US

Pricing FAQ

What is included for free in ProwlerPro?

  • You will have full access to all features.
  • We will scan and show results for 10,000 resources per month (ie. 333 resources scanned per day during a month).

How does ProwlerPro pricing work?

  • The first 15 days are free and not taken into account when billing.
  • After 15 days you will be asked to move to a paid account, or stay in the free tier if your number of resources scanned are less than 10,000.

What do we mean by “resource”?

  • ProwlerPro runs checks against your infrastructure. Those checks look for miss-configurations, security bad practices, etc. in your cloud resources (a cloud resource is a virtual machine, a security group, a bucket, a storage volume, etc). Each resource gets scanned in different ways by ProwlerPro every day, so we charge based on number of resources vs number of scans because we think it is the most accurate and fair way to bill. Your ProwlerPro overall costs will depend on your size and cloud usage.

  • We count all resources together no matter if you have one AWS account or multiple accounts scanned.

  • The list of all supported services can be found at the bottom os this page.

What about “ephemeral resources” in the cloud?

  • The cloud is, in some cases, an environment that changes constantly based on business needs. When it comes to counting resources, ProwlerPro does count them everyday based on the findings executed against the infrastructure so the bill will be based on those findings at the time they are executed. It accumulates the number of resources scanned per day to generate the monthly bill.

  • For customers with eventual thousands of ephemeral resources, please reach out to our Sales team to find the best pricing model for you: [email protected].

What happens after 15 days of trial period if I will have more than 10,000 scanned per month?

  • ProwlerPro will show you the number of resources scanned and potential cost everyday. This will show if you will pass the 10,000 resource limit based on your infrastructure.

  • Then you can decide to stay in the free tier with the 10,000 limitation (you won’t see results for new scans once passed that number of scanned resources each month) or move up to the paid tier.

What happens when I cancel my paid subscription?

  • After cancellation you will be in our free plan, and subject to those limits. You will have access to all scan results received during your paid and trial period.

  • You may subscribe again at any time.

Note: we won’t delete your data unless you delete your account.

What happens when I delete my ProwlerPro account? (Paid or free)

  • We stop scanning your account(s).

  • You lose access to your reports and data.

  • We remove all your data.

  • Customer will need to manually remove the ProwlerPro IAM role from the scanned account(s).

What happens if my credit card stops working?

  • We won’t be able to charge you, so you will be downgraded to free tier (Note: we won’t delete your account or data).

  • You may add a valid card again at any time to move back to paid tier.

  • We will keep your data for 3 months grace period if you need time.

I have multiple AWS accounts and thousands of resources, can I have a planned expense or flat rate or a discount?

Can I get a ProwlerPro subscription through the AWS Marketplace?

  • Yes, a ProwlerPro subscription can also be started from AWS Marketplace here. For AWS GovCloud Marketplace please reach out to us at [email protected].

Will I be charged for old ECS Task Definitions or EBS Snapshots?

  • There are several Prowler checks that we exclude from the resource usage count because several customers have many inactive resources, you will not be charged for resources found in the following checks:
    • ECS Task Definitions Checks:
      • ecs_task_definitions_no_environment_secrets (extra768)
    • CloudWatch Log Groups Checks:
      • cloudwatch_log_group_kms_encryption_enabled (extra7164)
      • cloudwatch_log_group_no_secrets_in_logs (extra7203)
      • cloudwatch_log_group_retention_policy_specific_days_enabled (extra7162)
    • Sagemaker Notebooks Checks:
      • sagemaker_notebook_instance_encryption_enabled (extra7112)
      • sagemaker_notebook_instance_root_access_disabled (extra7103)
      • sagemaker_notebook_instance_vpc_settings_configured (extra7104)
      • sagemaker_notebook_instance_without_direct_internet_access_configured (extra7111)
    • EBS Snapshots Checks:
      • ec2_ebs_snapshots_encrypted (extra740)
      • ec2_ebs_public_snapshot (extra72)

List of Supported Services

54 AWS services:

  • accessanalyzer
  • account
  • acm
  • apigateway
  • apigatewayv2
  • appstream
  • autoscaling
  • awslambda
  • backup
  • cloudformation
  • cloudfront
  • cloudtrail
  • cloudwatch
  • codeartifact
  • codebuild
  • config
  • directoryservice
  • drs
  • dynamodb
  • ec2
  • ecr
  • ecs
  • efs
  • eks
  • elb
  • elbv2
  • emr
  • fms
  • glacier
  • glue
  • guardduty
  • iam
  • inspector2
  • kms
  • macie
  • networkfirewall
  • opensearch
  • organizations
  • rds
  • redshift
  • resourceexplorer2
  • route53
  • s3
  • sagemaker
  • secretsmanager
  • securityhub
  • shield
  • sns
  • sqs
  • ssm
  • ssmincidents
  • trustedadvisor
  • vpc
  • workspaces