Always know what you'll pay with monthly caps and flat pricing.
Scan your DigitalOcean infrastructure for misconfigurations, prioritize what matters most, and fix issues fast — no agents or third-party tools required.
Talk to an expert to get started!
Starting at
$0/monthStarting at
$5/monthStarting at
$10/monthStandard Rules: (configuration objects), examples include IAM configuration objects, Volumes, Load Balancers, Firewalls, VPCs, and DOCR repositories.
Workload Rules: (billable resources), examples include Droplets, DOKS worker nodes, Managed Databases, App Platform services, and Spaces buckets.
No. CSPM is agentless in the traditional security sense. It does not install sensors, daemons, or runtime agents on Droplets or Kubernetes nodes. It evaluates supported DigitalOcean resources using configuration and metadata accessed through the platform.
Security Advisor is the AI layer in CSPM that summarizes findings in plain language and highlights what to fix first. Higher tiers can unlock guarded Auto-Fix for eligible findings.
CSPM is manually initiated in the dashboard. Higher tiers increase scan frequency for Workload scans, and Enterprise supports scheduled scans. Because CSPM is agentless, it does not install anything on Droplets or clusters, or other workloads and should not impact application performance.
Paid tiers include findings suppression so teams can mute accepted risk and focus on what matters. Governance enhancements, like suppression audit trail, may be available in higher tiers based on rollout timing.
Every customer can run unlimited Standard Rule scans at no additional cost. Paid tiers unlock Workload Rule scans, higher scan frequency, suppression, and additional Security Advisor capabilities.
Today, CSPM focuses on DigitalOcean resources to provide deep native integration and faster time to value.
CSPM evaluates configuration state and resource metadata needed to identify misconfigurations and generate findings. It is not designed to read your application data. Scan results and findings are stored to power the product experience, prioritization, and tracking over time.
No. CSPM helps reduce risk from misconfiguration and posture gaps. It complements runtime and application-layer tools like WAF, EDR, vulnerability management, and SIEM, giving you visibility that leads to actionable insights.
Yes. Teams running AI inference, data pipelines, and fast-moving production workloads need guardrails that keep pace. CSPM helps identify access control gaps, exposure risks, and configuration drift, and Security Advisor helps prioritize and accelerate remediation.
Have a complex setup or additional questions around pricing? Contact our sales team to get more information on DigitalOcean pricing.
Sign up and get $200 in credit for your first 60 days with DigitalOcean.*
*This promotional offer applies to new accounts only.