TTerramantle
Get Started Free
Pricing

Start where your team is. Keep the upgrade path honest.

Terramantle is priced so teams can begin with a lightweight hosted tier and add governance features when the module workflow actually needs them.

For individuals & small teams

Engineer

FreeCloud

A private, governed registry for you and a couple of teammates. Scanning and keyless CI publishing on every module, state and plan. Free forever, no card.

3 Users
Module Registry
State Registry
Plan Registry
CI Trust (GitHub/GitLab)
Dependency Graph
Deprecation Notices
Misconfiguration & Secret Detection
Policy Reporting
Policy Enforcement
Provider Registry
Sign In
For larger sized teams

Business

£89/org/mo

Lock down your provider supply chain. CVE and malware scanning, allow-list gates, and policy that blocks bad modules before they ship — not just flags them.

+ everything in Team
50 users
Provider Scanning & CVE Detection
Anti-Malware Scanning
Provider Allow-list Gates
Public Endpoint Discovery
OPA Policy Enforcement
Audit logs (90 days)
Self-hosted or cloud

Enterprise

From £249/org/mo

Run it your way: cloud, self-hosted, or fully air-gapped. Build and GPG-sign your own providers, stream audit to your SIEM, own the entire chain.

+ everything in Business
Unlimited members
Provider Builds & GPG Signing
SBOM Generation
`null_resource` Exploitation Scanning
SCIM Provisioning
Data Diode Support
Audit Streams (SIEM)
Dedicated instance or self-hosted
Priority SLA and support
Compare plan features

Feature depth comparison matrix.

The hosted tiers should feel like a continuation of the same workflow, not a separate product that locks you into a totally different operating model.

CapabilityEngineerTeamBusinessEnterpriseEnterprise
(Self-Hosted)
Registry & Artefacts
Module Registry
State BackendTerraform/OpenTofu HTTP state backend with locking
Provider RegistryMirror and manage your required providers with allow lists and RBAC
Dependency GraphVisualize and manage your module and provider dependencies
Publishing & CI
CI Trust (GitHub/GitLab)Publish modules from CI with no credentials needed
Bot TokensGenerate tokens for automated workflows
1310CustomCustom
Slack & Teams NotificationsAlerts on module deprecations, changes, and security findings
Module Scanning
Misconfiguration & vulnerability detectionTrivy, KICS, tflint scanning on every publish
Secret detectionDetect accidentally leaked secrets in your modules
`null_resource` Exploitation Scanning
Module version retention
UnlimitedUnlimitedUnlimitedUnlimitedUnlimited
State Scanning
Secret Detection (State Files)Detect leaked secrets in your state files
Vulnerability and Misconfiguration DetectionDetect vulnerabilities in your state files
Public Endpoint DiscoveryDiscover and alert on publicly accessible endpoints from your state file
Provider Scanning
Provider ScanningScan provider source code for vulnerabilities and compliance issues
CVE DetectionTerraform providers are Go applications susceptible to CVEs like any other software
Anti-Malware ScanningScanning with multiple anti-malware solutions
Provider Allow-list GatesWhitelist which providers your teams can consume from Terraform and OpenTofu registries
Provider Builds & GPG SigningAllow Terramantle to build, publish, and GPG sign providers for supply chain peace of mind
SBOM GenerationGenerate Software Bill of Materials for compliance and security
Identity & Access
UsersExcludes billing and administrative users
11050100Custom
OIDC Publishing (GitHub/GitLab)
Role-Based Access Control
Single Sign-On (OIDC)
SCIM Provisioning
Governance & Policy
OPA Module Policy ReportingView policy compliance results per module version
OPA Module Policy EnforcementBlock module consumption when policies fail
Synchronous Module Policy EnforcementEnforce policies at publish time with instant CI feedback
Module Deprecation
Custom Module Approval
Audit & Compliance
Audit Logs
7 days30 days90 daysCustomCustom
State Retention
30 days90 days365 daysUnlimitedUnlimited
Audit StreamsStream audit logs to your SIEM or internal monitoring tools
Pipeline Trust across all tiers

Gain insights with zero effort.

Every tier supports module and state scanning, OIDC-based publishing from GitHub and GitLab. Prove CI identity without long-lived credentials. Scale up for webhooks, scanning policies, and air-gap mirroring.