Pricing

Free covers a side project.

Free

For trying StackClock on a side project.

$0

  • 5 monitored assets
  • 25 packages, checked daily
  • Vulnerability and end-of-life checks
  • Health score
  • Monday digest
Start free

Pro

For freelancers and indie developers.

$8.99/ month

  • 100 monitored assets and 500 packages
  • Manifest and lock-file import
  • Immediate alerts
  • Health score for up to 10 products
  • Calendar feed, API and RSS
  • Public trust page and badge
Try Pro free for 14 days

Team

For teams that share responsibility for a stack.

$11.99/ month per seat

  • Everything in Pro
  • Unlimited assets, packages and members
  • Shared timeline with owners
  • Slack and signed webhooks
  • Roles, audit log and required 2FA
Try Team free for 14 days

Prices in USD. Sales tax or VAT is added at checkout where it applies.

Questions

Before you ask.

Do you store my API keys?

No. For keys, licenses and subscriptions we store metadata only: a name, provider, expiry date, owner and a renewal link. Pasted secrets are detected and rejected.

What if my domain registry hides the expiry date?

We ask the registry via RDAP, or its WHOIS server for TLDs without RDAP (such as .io). If a registry publishes neither, we mark the domain as unknown, never as OK, and ask you for the date.

Can you find the certificates on my subdomains?

Yes. When you add a domain we search public Certificate Transparency logs (crt.sh, with Cert Spotter as a fallback), where every publicly trusted certificate is recorded, and list the hostnames under your domain that have a valid one. Nothing is monitored until you pick which to track, and the search repeats weekly so new subdomains show up. Wildcard certificates hide individual subdomain names, so add those by hand.

Which files can I import?

package.json, requirements.txt, pyproject.toml, go.mod, Gemfile, composer.json, Dockerfiles and docker-compose files, plus lock files (package-lock.json, yarn.lock, pnpm-lock.yaml, poetry.lock, Pipfile.lock, composer.lock, go.sum) for exact versions. Import is on Pro and Team; on Free you add packages by hand.

Where do vulnerability and end-of-life data come from?

Vulnerabilities from OSV.dev, which combines GitHub, PyPI, Go and other advisory databases. Deprecations and latest versions from the npm, PyPI and Go registries themselves. End-of-life dates from endoflife.date. Everything is checked daily and again whenever your stack changes.

Can alerts go to Slack or our own systems?

Yes, on the Team plan. Add a Slack incoming webhook or any https endpoint; webhooks receive signed JSON for reminders, new vendor changes and new vulnerabilities.

Can I use StackClock on my own?

Yes. Every account starts with a personal workspace. Upgrade to Pro for more assets and immediate alerts, or to Team to share a timeline.

Is there a free trial?

Yes: 14 days of Pro or Team. Stripe asks for a card when the trial starts and emails you before it ends; cancel before then and you pay nothing. The Free plan needs no card at all.

Is Team really unlimited?

Yes: no caps on assets, packages, products, members or integrations. A fair-use ceiling (20,000 assets and 20,000 packages per workspace) keeps the daily checks fast; if you need more, write to us and we will raise it.

How is billing handled?

Payments are processed by Stripe. Team plans are billed per seat and viewers are free. You can cancel any time from the billing portal.

Put every deadline on one timeline.

Free for individuals. No credit card needed.