Engineer
FreeCloud
A private, governed registry for you and a couple of teammates. Scanning and keyless CI publishing on every module, state and plan. Free forever, no card.
Terramantle is priced so teams can begin with a lightweight hosted tier and add governance features when the module workflow actually needs them.
FreeCloud
A private, governed registry for you and a couple of teammates. Scanning and keyless CI publishing on every module, state and plan. Free forever, no card.
£24/org/mo
Bring the team on. Mirror the providers you depend on, sign in with SSO, and get pinged the moment a module or provider drifts.
£89/org/mo
Lock down your provider supply chain. CVE and malware scanning, allow-list gates, and policy that blocks bad modules before they ship — not just flags them.
From £249/org/mo
Run it your way: cloud, self-hosted, or fully air-gapped. Build and GPG-sign your own providers, stream audit to your SIEM, own the entire chain.
The hosted tiers should feel like a continuation of the same workflow, not a separate product that locks you into a totally different operating model.
| Capability | Engineer | Team | Business | Enterprise | Enterprise (Self-Hosted) |
|---|---|---|---|---|---|
| Registry & Artefacts | |||||
Module Registry | ✓ | ✓ | ✓ | ✓ | ✓ |
State BackendTerraform/OpenTofu HTTP state backend with locking | ✓ | ✓ | ✓ | ✓ | ✓ |
Provider RegistryMirror and manage your required providers with allow lists and RBAC | − | ✓ | ✓ | ✓ | ✓ |
Dependency GraphVisualize and manage your module and provider dependencies | ✓ | ✓ | ✓ | ✓ | ✓ |
| Publishing & CI | |||||
CI Trust (GitHub/GitLab)Publish modules from CI with no credentials needed | ✓ | ✓ | ✓ | ✓ | ✓ |
Bot TokensGenerate tokens for automated workflows | 1 | 3 | 10 | Custom | Custom |
Slack & Teams NotificationsAlerts on module deprecations, changes, and security findings | − | ✓ | ✓ | ✓ | ✓ |
| Module Scanning | |||||
Misconfiguration & vulnerability detectionTrivy, KICS, tflint scanning on every publish | ✓ | ✓ | ✓ | ✓ | ✓ |
Secret detectionDetect accidentally leaked secrets in your modules | ✓ | ✓ | ✓ | ✓ | ✓ |
`null_resource` Exploitation Scanning | − | − | − | ✓ | ✓ |
Module version retention | Unlimited | Unlimited | Unlimited | Unlimited | Unlimited |
| State Scanning | |||||
Secret Detection (State Files)Detect leaked secrets in your state files | ✓ | ✓ | ✓ | ✓ | ✓ |
Vulnerability and Misconfiguration DetectionDetect vulnerabilities in your state files | ✓ | ✓ | ✓ | ✓ | ✓ |
Public Endpoint DiscoveryDiscover and alert on publicly accessible endpoints from your state file | − | − | ✓ | ✓ | ✓ |
| Provider Scanning | |||||
Provider ScanningScan provider source code for vulnerabilities and compliance issues | − | − | ✓ | ✓ | ✓ |
CVE DetectionTerraform providers are Go applications susceptible to CVEs like any other software | − | − | ✓ | ✓ | ✓ |
Anti-Malware ScanningScanning with multiple anti-malware solutions | − | − | ✓ | ✓ | ✓ |
Provider Allow-list GatesWhitelist which providers your teams can consume from Terraform and OpenTofu registries | − | − | ✓ | ✓ | ✓ |
Provider Builds & GPG SigningAllow Terramantle to build, publish, and GPG sign providers for supply chain peace of mind | − | − | − | ✓ | ✓ |
SBOM GenerationGenerate Software Bill of Materials for compliance and security | − | − | − | ✓ | ✓ |
| Identity & Access | |||||
UsersExcludes billing and administrative users | 1 | 10 | 50 | 100 | Custom |
OIDC Publishing (GitHub/GitLab) | ✓ | ✓ | ✓ | ✓ | ✓ |
Role-Based Access Control | ✓ | ✓ | ✓ | ✓ | ✓ |
Single Sign-On (OIDC) | − | ✓ | ✓ | ✓ | ✓ |
SCIM Provisioning | − | − | − | ✓ | ✓ |
| Governance & Policy | |||||
OPA Module Policy ReportingView policy compliance results per module version | ✓ | ✓ | ✓ | ✓ | ✓ |
OPA Module Policy EnforcementBlock module consumption when policies fail | − | − | ✓ | ✓ | ✓ |
Synchronous Module Policy EnforcementEnforce policies at publish time with instant CI feedback | − | − | ✓ | ✓ | ✓ |
Module Deprecation | ✓ | ✓ | ✓ | ✓ | ✓ |
Custom Module Approval | − | − | ✓ | ✓ | ✓ |
| Audit & Compliance | |||||
Audit Logs | 7 days | 30 days | 90 days | Custom | Custom |
State Retention | 30 days | 90 days | 365 days | Unlimited | Unlimited |
Audit StreamsStream audit logs to your SIEM or internal monitoring tools | − | − | − | ✓ | ✓ |
Every tier supports module and state scanning, OIDC-based publishing from GitHub and GitLab. Prove CI identity without long-lived credentials. Scale up for webhooks, scanning policies, and air-gap mirroring.
Common questions about migration, OIDC, OpenTofu compatibility, and plan limits.