Pricing

One Platform, Every Capability

No per-seat fees. No throughput limits. No feature gates. Every CoreLink deployment includes the full platform -- PAM, IAM, IGA, Compliance, and SecOps -- from day one.

How we license

The entire platform, not a patchwork of add-ons

Most identity security vendors charge per user, per connection, or per feature module -- forcing you to choose which parts of your infrastructure to protect and which to leave exposed. CoreLink works differently.

When you deploy CoreLink, you get secrets management, privileged sessions, identity governance, compliance reporting, SIEM integration, UEBA behavioral analytics, git secret scanning, device posture, and everything in between. There is no "upgrade to unlock" and no metering surprises. Your team scales freely, your integrations grow without penalty, and every capability is available the moment you need it.

Pricing is based on a flat agreement scoped to your organization -- not on how many people log in or how many secrets you store. We structure every engagement around predictable cost so you can plan ahead without spreadsheet gymnastics.

Every deployment includes the full platform, so you are never forced to buy a second tool when your needs grow. Start with secrets management today, and when your compliance team asks for access reviews next quarter, it is already there -- no new procurement, no new integration, no new vendor.

What you are actually comparing

"I only need PAM" -- but what does your PAM actually include?

When vendors sell you "PAM," they sell you one piece. When CoreLink gives you PAM, you get the full stack -- and the other pillars cost you nothing extra.

Typical vendor PAM
  • Password vaulting
  • Session recording (basic)
  • Secrets management separate product
  • Dynamic DB credentials separate product
  • Certificate authority separate product
  • TLS discovery separate product
  • HSM integration enterprise add-on
  • Command interception enterprise tier
  • Compliance reporting
  • UEBA / anomaly detection
  • Access reviews
  • Git secret scanning
6 add-ons to reach parity. Each with its own contract, integration, and support channel.

The question is not "why pay for all five pillars." It is "why pay six vendors to get what one platform includes by default" -- and still have gaps between them.

The consolidation question

"Why would I put all my eggs in one basket?"

It is a fair question. Here is why the multi-vendor approach creates more risk than it eliminates -- and how CoreLink is designed to remove the concerns that make you ask it.

Multi-vendor has its own single points of failure

Your Okta-to-CyberArk SCIM sync is a single integration maintained by nobody's core team. When it breaks at 2 AM, identities drift, sessions fail, and your on-call scrambles across three vendor support lines. Every integration seam is an unmonitored single point of failure.

Correlated intelligence that separate tools cannot deliver

A suspicious login (IAM) followed by an unusual secret access (PAM) followed by a failed compliance check (IGA) is a breach pattern. Separate tools see three unrelated events. CoreLink sees one incident -- because the data lives in a single hash-chained audit trail.

99.9% SLA with degraded-mode offline access

If CoreLink is unreachable, cached credentials and session policies remain available locally. Your team does not lose production access during an outage. Multi-vendor stacks offer no such guarantee -- if one vendor's API goes down, every downstream integration breaks.

Full data export -- you can leave any time

Every secret, audit log, policy, and session recording is exportable via API in standard formats. If you ever decide to leave, your data leaves with you. That is a stronger exit guarantee than most "best-of-breed" vendors offer, where your data is trapped in proprietary formats.

One policy engine eliminates drift

With four vendors, you write the same access rule four times in four policy languages and hope they stay in sync. CoreLink enforces each rule once across sessions, secrets, and identity lifecycle. No cross-vendor integration tax, no policy drift.

Self-hosted option -- your infrastructure, your control Under development

Deploy CoreLink on your own infrastructure when vendor dependency is the concern. Same platform, same capabilities, running in your data center or private cloud. You control the uptime, the updates, and the data -- not us.

PAM
Unlimited secrets, sessions, and credentials SSH and RDP session recording and brokering Multi-KMS: AWS, Azure, GCP, Vault, SafeNet Luna HSM, Thales HSM HSM support (PKCS#11 v2.40) Dynamic database credentials TLS certificate discovery and expiry tracking Transit Agent for air-gapped networks LDAP secret rotation with Active Directory unicodePwd support Rotation policy templates with configurable retry Infrastructure credential rotation for platform-managed connections PostgreSQL rootless rotation (no superuser required) Kubernetes secrets operator for native K8s integration Transparent sessions client agent (config-driven TCP proxy) RDP credential injection via .rdp file download and Windows CredSSP
IAM
Unlimited users and service accounts AD, Okta, Workday, SCIM, SAP, ServiceNow, Salesforce, Jira, Slack, PagerDuty NHI registry and A2A agent protocol Device posture checks at session initiation Identity graph and correlation engine SPIFFE JWT-SVID issuance for workload identity Identity graph BFS traversal and escalation path finding Privilege discovery with risk scoring (0-100) Constrained CAs with X.509 Name Constraints (RFC 5280)
IGA
Access reviews, approvals, and governance workflows Self-service portal and access request catalogs Role mining and micro certifications SoD policies, simulation, and remediation workflows
Compliance
SOC 2, HIPAA, PCI-DSS compliance reporting ISPM posture scoring with configurable risk weights Built-in support ticketing with SLA tracking Break-glass emergency access with N-of-M quorum unsealing Data residency controls with per-tenant geographic enforcement Adaptive overload protection with progressive load shedding Usage metering with tier-based limits and billing API
SecOps
SIEM integration: syslog/CEF to Splunk, QRadar, Sentinel UEBA behavioral analytics and peer anomaly detection Git secret scanning across GitHub, GitLab, and Bitbucket Event bus and webhook delivery CI/CD secrets injection (GitHub Actions, GitLab CI, Jenkins)
Developer
MCP server for AI assistant integration (metadata only) Five pillars: PAM, IAM, IGA, Compliance, SecOps
How you deploy

No rip-and-replace required

CoreLink integrates with your existing identity providers and secret stores during transition -- you never go dark.

1

Connect

Run CoreLink alongside your existing tools. Sync identities from Okta or AD. Import secrets from Vault or AWS Secrets Manager.

2

Extend

Enable new capabilities your current stack does not cover -- session recording, compliance reporting, UEBA, access reviews.

3

Consolidate

As vendor contracts expire, migrate remaining workloads at your own pace. One platform, one policy engine, one audit trail.

Pricing calculator

See what you could save

Estimate what your organization could save by consolidating identity security into a single platform.

Business size
Industry
Commitment
Capabilities needed

Typical Multi-Vendor Cost
  • PAM$24,000
  • IAM$14,400
  • IGA$18,000
  • Compliance$9,000
  • SecOps$18,000
Total (1 year)
$83,400
$6,950/mo
Multi-vendor estimates are based on published list pricing from vendor websites and Gartner Peer Insights, 2025-2026. Actual costs vary by negotiated discount, deployment size, and contract terms. CoreLink pricing is indicative and not a binding quote -- your actual price will be determined during a scoping conversation with our team. Contact [email protected] for a formal proposal.
Platform trust

Built for regulated environments

SOC 2 Type II
Audit in progress
99.9% Uptime SLA
Degraded-mode offline access
Data Residency
US, EU, or self-hosted
BAA Available
HIPAA-covered entities
AES-256-GCM + TLS 1.3
Encryption at rest and in transit
Full API Data Export
No vendor lock-in

Join the design partner program

Work directly with our engineering team to shape the platform. Design partners get priority support, direct roadmap input, and preferred pricing.

Apply for early access

Request a Custom Quote

Reach out to our team to discuss deployment options, volume, and a pricing structure that fits your environment.