Billing & plans
Argus has two tiers: Free and Pro, at $49 per month, with no trial. New workspaces start on Free, which never expires, and upgrade whenever they are ready. Everything is managed from the Billing page.
Argus is in closed beta, and every figure on this page is a beta figure. These prices apply to the organizations testing the service today, and they will change. The team has yet to set the final pricing, so the numbers below are working figures under review rather than a published price list.
The beta bar in the console says the same thing: the pricing is work in progress, and what is on screen today is a snapshot, not a promise.
During the beta
No charge reaches a card without a human reviewing it first. Billing is real: the Billing page is the finished product, with real prices, usage meters and the link out to the Wazuh Hub, and usage is metered for real. What the beta adds is a person in front of every bill. Nothing is ever collected automatically, so when a billing cycle closes the invoice is issued and the card on file is charged only after someone at Wazuh has reviewed and approved it. An invoice that looks wrong is corrected before it is collected.
Who can see Billing
Billing is an admin-only surface. Admins (and the workspace owner) see the
Billing entry in the sidebar and manage the plan; members and viewers do not
see the entry at all, and opening /billing directly sends them to the
Overview.
That is deliberate rather than a missing permission: only an admin may change an organization's plan, so the API refuses an upgrade or a cancellation from anyone else. Showing the buttons to a member would offer an action the server denies. If you need a plan change and do not see Billing, ask an admin of your workspace (the Team page lists them). Where a Free limit is reached, the notice on Findings, Scans and Accounts says exactly that instead of offering an upgrade link.
What each tier includes
| Free | Pro | |
|---|---|---|
| Price | $0, forever | $49 per month |
| Cloud accounts | 1 | unlimited |
| Scans | automatic weekly | on-demand + daily schedule |
| Resources per scan | metered, never billed | 25,000 included, then $0.002 each |
| Findings history | kept | kept |
| Compliance frameworks | all frameworks | all frameworks |
Upgrade to Pro
Click Upgrade to Pro on the plan cards. The subscription is billed to the organization's shared payment method, managed centrally in the Wazuh Hub: one card per organization across every Wazuh Labs service, with each service's spend on its own subscription.
- With a card on file, the upgrade completes immediately and everything unlocks at once.
- Without one, Argus links to the Hub to add the card first. The upgrade then completes back in Argus.
No card data is ever handled in the Argus console.
Downgrade back to Free
Switching to Free cancels the subscription, but Pro stays active until the end of the paid billing period. No data is deleted. The Free limits re-apply when the period ends.
The Billing page then shows a pending-cancellation notice naming the day Pro ends, and keeps showing it until the period runs out. Pro remains the current plan the whole time, with every capability. That notice is the scheduled cancellation working, not a failed one: the downgrade registered, and the date is when it takes effect. While it is pending, the Free plan card reads Free from that date rather than offering another downgrade.
Change your mind: Keep Pro
While a cancellation is pending, the Pro card offers Keep Pro. Pressing it lifts the scheduled cancellation: Pro keeps going as before, the notice disappears, and there is nothing more to do. Pressing Upgrade to Pro again does the same thing, so either button keeps you on Pro.
Keep Pro is available to admins, the same as the upgrade and downgrade actions. A sponsored plan is the one exception: a sponsorship runs for an agreed period and is continued from the Wazuh Hub, so Keep Pro does not apply to it.
If a payment fails
A failed payment does not end Pro straight away. The subscription enters a retry period, and the workspace keeps every Pro entitlement while the payment is retried. Pro ends only if the subscription is eventually cancelled.
While a payment is in that retry state, the Billing page shows a payment needs attention line with a link to fix it. The organization's card, its invoices and the failed payment itself live in the Wazuh Hub, which that line and the Payment method and invoices link both point to. Pro stays active the whole time; the line is a heads-up, not a lockout.
Separately, if the very first payment on an upgrade needs your bank's confirmation (for example a 3-D Secure prompt on a European card), the upgrade does not silently claim success. Argus keeps you on Free and says the bank asked to confirm the payment, so you can finish it in the Wazuh Hub.
When Pro does end, nothing is disconnected and nothing is deleted. Accounts connected beyond the Free limit stay connected and keep their history. What stops are the Pro capabilities. Scans are no longer available, and the connect button caps at one account.
What the limits actually gate
The usage tiles on the Billing page show the connected accounts against the plan limit and the scan cadence. Concretely, on Free:
- the connect button stops at 1 account,
- Launch scan and daily schedules are unavailable.
Findings history is not a limit: it is kept on every plan.
Compliance frameworks are not one of the limits: every framework is included on both plans. The account limit and scan availability are enforced server-side. The lock badges in the console make the limits visible.
If your workspace goes quiet
Free workspaces get an automatic weekly scan, and to avoid scanning workspaces nobody is watching, that cadence pauses after a long stretch with no sign-ins:
- After 30 days with nobody logging in, we email the workspace admins that it has gone quiet and that the weekly scans will pause in 15 days.
- After 45 days, the automatic weekly scans pause and we send one more email.
Nothing is deleted and nothing is disconnected: your accounts, findings and history stay exactly as they were. The moment anyone on the workspace logs in, everything clears and the weekly scans resume on their own, with nothing else to switch back on. Pro workspaces are never paused for inactivity.
This cycle's usage and estimated invoice
The Billing page shows what this billing cycle has metered and what it is on track to cost, so an invoice is never a surprise.
Each completed scan covers 25,000 unique resources before anything is added to the bill; unique resources scanned above that threshold in a cycle are extra resource-scans, billed at $0.002 per resource per scan. Only completed scans are metered: a failed or cancelled scan never counts toward the bill. A "resource" is one unique resource a completed scan covers, the same number the scan reports in the console, so the bill is a number you can check for yourself. The page shows:
- Extra resources is the extra resource-scans metered so far this cycle. Most cycles this is zero: a scan has to cross the included-resources threshold before it counts.
- Estimated invoice this cycle is the headline figure, with a line beneath it spelling out how it is made up: the plan's monthly base plus any overage (and the resource count and rate that produced it). On Free the estimate is $0, with no charge.
The estimate is exactly that, an estimate for the cycle so far: it moves as more scans run, and the final invoice is the one the Wazuh Hub issues at cycle end (reviewed by a person during the beta, as above). If you switch to Free, the extra resources metered up to the day Pro ends are billed on that closing invoice; nothing metered afterwards is ever charged. The figures are decided server-side from the same metering the invoice is built on, so what the page quotes and what you are billed cannot drift apart.
On the invoice
The Pro invoice carries the plan's monthly base as one line. When a cycle went over the included resources, a second line, Argus extra resource-scans, sits beside it with the resource count and the per-resource rate that produced the overage, so finance can reconcile the total against the count. A cycle with no overage has only the base line. The overage is metered by us from your completed scans and reported to the same shared payment method the Wazuh Hub manages for your organization, so Argus appears as one more line on the organization's bill rather than a separate one.
Who can change the plan
Upgrades, downgrades, and billing actions are admin-only. See Team & roles.