Pricing

Pay for the gate, not the gigabytes.

Every tier ships rustdoc builds, crate site hosting, SBOMs, OIDC SSO, quarantine, static file registries, and the gated crates.io mirror, all hosted in the EU. The paid tiers buy room and, on Compliance and up, the policy engine itself.

  • Free

    €0

    free, no card required

    For open source communities and first trials.

    • 3 public registries, 1 private
    • Crates or static files, unlimited packages and members
    • 5 GB public + 2 GB private storage
    • 100 GB public + 10 GB private transfer / month
    Start free
  • Team

    €49

    per month

    For engineering orgs gating what they publish and what they consume.

    • Unlimited registries
    • 250 GB storage
    • 1 TB transfer / month
    • Metered overage, builds never break at a cap
    Start free
  • Enterprise

    Custom

    quoted per deployment

    For regulated and air-gapped environments.

    • Everything in Compliance
    • Physical isolation
    • Self-hosted or on-premise
    • SCIM, air-gap distribution, SLA
    Talk to us

Every feature, every plan

FeatureFreeTeamComplianceEnterprise
Registries and quotas
Public registries3UnlimitedUnlimitedUnlimited
Private registries1UnlimitedUnlimitedUnlimited
Cargo registries and static file registries
Packages and membersUnlimitedUnlimitedUnlimitedUnlimited
Storage5 GB public + 2 GB private250 GB1 TBCustom
Transfer per month100 GB public + 10 GB private1 TB5 TBCustom
Max crate file size10 MB100 MB100 MBCustom
OverageFair use€0.10/GB storage, €50/TB transfer€0.10/GB storage, €50/TB transferCustom
Usage dashboard: meters, and who pulled what
Publishing and policy
Cargo sparse index and scoped tokens
Static files over plain HTTP, resolved by semver
Version archives: a whole file version as one zip or tar.gz
Trusted publishing, tokenless from CI
Per-client read grants with semver ranges
Scratchpads: throwaway copies of a registry for testing a publish125UnlimitedUnlimited
Predefined policy gates
Quarantine on failed gates
Held versions, with owner approvals and per-version waivers
Publish-time rejection on provenance, license, or publisher
Yank and unyank
Policy dry-run against the versions you already hold
Custom policies on the full engine
Custom facts from CI, tarball extractors, and rules over them
Keyless CI attestations, m-of-n promotion
Dependencies
crates.io mirror, gated by your rules
Full catalog, or a subset imported from your Cargo.lock
Predefined admission gates: advisories, yanked upstream, cooldown, license, new publisher
Custom admission rules and org-wide pins
Air-gapped mirror sync
Docs and distribution
Rustdoc built on publish
Docs served from their own subdomain
Build features honored from Cargo.toml metadata
Crate website hosting
CycloneDX SBOMs and license reports
Security and compliance
OIDC SSO
Sign in with GitHub, GitLab, or Google
RustSec advisory alerts on crates and dependencies
Malicious crate reporting and takedown
Tamper-evident audit log
Audit log retention30 days90 daysUnlimitedUnlimited
Audit log export
Coordinated vulnerability disclosure channel
SCIM provisioning
Deployment and support
DeploymentSharedSharedSharedPhysically isolated, self-hosted, or on-premise
Air-gap distribution
SupportCommunityEmailPriorityDedicated, with SLA

Quotas on Free are hard limits, split between public and private registries so an open source project is never throttled by someone else's trial. Paid tiers meter overage instead of stopping builds. Dependency mirror traffic counts toward monthly transfer.

Running a large open source project? Talk to us, hosting the commons is part of the point.

First cargo publish in five minutes.