Simple, predictable pricing

Always know what you'll pay with monthly caps and flat pricing.

Cloud Security Posture Management (CSPM)

Scan your DigitalOcean infrastructure for misconfigurations, prioritize what matters most, and fix issues fast — no agents or third-party tools required.

Talk to an expert to get started!

Free

Starting at

$0/month
  • Standard Rules
  • Guided Remediation
  • Email Notifications
  • Security Advisor - Summarizer

Get started

Basic

Starting at

$5/month
  • Everything in Free Tier
  • Workload Rules
  • Findings Suppression
  • API Integration
  • Security Advisor - Summarizer
  • Security Advisor - Quick fix

Get started

Standard Tier (Coming soon!)

Starting at

$10/month
  • Everything in Basic Tier
  • Rules Management
  • Email Notifications with support for security contacts
  • Custom Notification Integrations
  • Standard Reporting
  • Security Advisor - Summarizer
  • Security Advisor - Quick fix

Get started

Standard Rules: (configuration objects), examples include IAM configuration objects, Volumes, Load Balancers, Firewalls, VPCs, and DOCR repositories.

Workload Rules: (billable resources), examples include Droplets, DOKS worker nodes, Managed Databases, App Platform services, and Spaces buckets.

Frequently asked questions

Does CSPM require software agents or sensors on my workloads?

No. CSPM is agentless in the traditional security sense. It does not install sensors, daemons, or runtime agents on Droplets or Kubernetes nodes. It evaluates supported DigitalOcean resources using configuration and metadata accessed through the platform.

What does CSPM scan?
CSPM scans supported DigitalOcean resources for common misconfigurations and posture risks. CSPM includes two rule categories:

  1. Standard Rules: (configuration objects), examples include IAM configuration objects, Volumes, Load Balancers, Firewalls, VPCs, and DOCR repositories.

  2. Workload Rules: (billable resources), examples include Droplets, DOKS worker nodes, Managed Databases, App Platform services, and Spaces buckets.
What is Security Advisor?

Security Advisor is the AI layer in CSPM that summarizes findings in plain language and highlights what to fix first. Higher tiers can unlock guarded Auto-Fix for eligible findings.

How often does CSPM scan, and will it impact my workloads?

CSPM is manually initiated in the dashboard. Higher tiers increase scan frequency for Workload scans, and Enterprise supports scheduled scans. Because CSPM is agentless, it does not install anything on Droplets or clusters, or other workloads and should not impact application performance.

How do I reduce noise or handle accepted risk?

Paid tiers include findings suppression so teams can mute accepted risk and focus on what matters. Governance enhancements, like suppression audit trail, may be available in higher tiers based on rollout timing.

Is CSPM free?

Every customer can run unlimited Standard Rule scans at no additional cost. Paid tiers unlock Workload Rule scans, higher scan frequency, suppression, and additional Security Advisor capabilities.

Does CSPM support multi-cloud?

Today, CSPM focuses on DigitalOcean resources to provide deep native integration and faster time to value.

What data does CSPM access, and what does DigitalOcean store?

CSPM evaluates configuration state and resource metadata needed to identify misconfigurations and generate findings. It is not designed to read your application data. Scan results and findings are stored to power the product experience, prioritization, and tracking over time.

Does CSPM replace other security tools?

No. CSPM helps reduce risk from misconfiguration and posture gaps. It complements runtime and application-layer tools like WAF, EDR, vulnerability management, and SIEM, giving you visibility that leads to actionable insights.

Is CSPM a fit for AI-native workloads?

Yes. Teams running AI inference, data pipelines, and fast-moving production workloads need guardrails that keep pace. CSPM helps identify access control gaps, exposure risks, and configuration drift, and Security Advisor helps prioritize and accelerate remediation.

Still have questions?

Have a complex setup or additional questions around pricing? Contact our sales team to get more information on DigitalOcean pricing.

Get started for free

Sign up and get $200 in credit for your first 60 days with DigitalOcean.*

*This promotional offer applies to new accounts only.