Priced to fund the mission.
Hosted is $250 / month for up to 30,000 users across a maximum of 5 tenants — we run everything. Sponsor is $99 / month, with access to the Maester Cloud private repository, deployment guidance, monthly updates, and new features while subscribed. Cancel any time.
Sponsor ongoing Maester development and run Maester Cloud in your own environment with support from our team.
- Access to Maester Cloud private repository
- Deployment guidance & support
- Monthly updates & new features while subscribed
- Cancel any time
- You self-manage
- Deploy updates to your environment
- Azure configuration & costs
We run the portal. You pick the region. Zero infrastructure for you.
- Everything in Sponsor tier
- Up to 30,000 users across a maximum of 5 tenants
- Hosted portal, 5-year history
- Custom maester.cloud domain
- Supported regions: US, EU & Australia
- First to get the latest Maester Cloud features
- Cancel any time
Have questions, need higher hosted limits, or have custom requirements? Talk to us.
- Higher hosted limits
- Custom requirements
- A plan shaped around your needs
Start hosted or become a sponsor — you can switch between them at any time.
Does Maester Cloud run Maester for me? +
Not in v1. You keep running Maester and Zero Trust Assessment in your own environment — locally, in CI, or on a schedule. Maester Cloud stores, compares, alerts on, and preserves the results you send. A managed daily runner is planned as a future add-on.
How does data residency work? +
You choose an Azure region at setup. All report data — JSON, HTML, and history — is stored and processed in that region and stays there. Billing metadata may live in our central control plane, but security report data stays regional.
What data is actually stored? +
Only the Maester and Zero Trust Assessment results you choose to send. Maester Cloud never reads your Microsoft 365 tenant in v1 — you run the tests and export the output.
How are changes detected? +
Each export is diffed against your previous run for the same tenant, surfacing new failures, fixes, and accepted risks, pinned to a date and run ID across five years of history.
How do alerts reach me? +
Through your own Microsoft 365 shared mailbox, connected at setup. Notifications come from your tenant with a familiar sender identity, not from us.
How long are reports stored? +
Hosted plans include five years of daily report history. Standard hosted plans retain one run per tenant per day; if multiple results arrive the same day, the latest successful submission becomes that day’s archive. Enterprise can discuss custom retention.
How does Maester Cloud authenticate users? +
Portal access is Entra-only after setup. You control access by assigning users to your own Entra app role. V1 treats users as a single access level; granular roles can come later.
How does the subscription support open source? +
Every paid plan helps keep the Maester tests open, maintained, and aligned with CIS, CISA, and evolving standards. You receive a real service while funding better security for the whole community.