# Features and Pricing Plans

## Talsec's Multi-Layered App and API Protection Model

* **L0 - Detect Attacks**: Check app security state with [**freeRASP**](https://docs.talsec.app/freerasp/freerasp/introduction) & [**Talsec Portal**](https://docs.talsec.app/freerasp/freerasp/data-visualisation-portal) insights
* **L1 - Protect App**: Pass pentests, combat reverse engineering, and comply with regulations with [**RASP+**](https://app.gitbook.com/s/xFHPMAbn16uoDyOtoiaC/product/rasp) and [**AppHardening (Secret Vault, Dynamic TLS Pinning)**](https://app.gitbook.com/s/xFHPMAbn16uoDyOtoiaC/product/app-hardening-suite)
* **L2 - Protect Transactions**: Combat API abuse, bots, web-scraping and MiTM with [**AppiCrypt**](https://app.gitbook.com/s/xFHPMAbn16uoDyOtoiaC/product/appicrypt)
* **L3 - Protect Users: Combat social engineering, phishing, malware with** [**Device Risk Scoring**](https://app.gitbook.com/s/xFHPMAbn16uoDyOtoiaC/product-previews/ai-device-risk-summary-new) **and** [**Malware Detection**](https://app.gitbook.com/s/xFHPMAbn16uoDyOtoiaC/product/malware-detection)

{% embed url="<https://files.gitbook.com/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQ2PxZTOjhquOxcxftTrm%2Fuploads%2FntL0WHKDjcyzSIvvA3cN%2FTalsec-Animation-v4.mp4?alt=media&token=07120857-5d73-45e0-bc50-ebbc924aa12b>" %}

Talsec offers enhanced features and benefits with our RASP+ plans, building on top of our freeRASP offering. Here’s what you can expect:

* **No limitations of freeRASP's** [**Fair Usage Policy**](#plans-comparison): Have an unrestricted number of app downloads<mark style="color:red;">\*</mark> (beyond the 100k cap of freeRASP).
* **No Data Collection to Talsec Database**: Your app's data is sent to your data collection services. You can even disable data collection.
* **FinTech Grade Security**: Experience advanced security features and service-level agreements (SLAs) tailored for the financial technology sector.
* **Bypass Protection:** RASP+ offers enhanced security with app-specific SDK customisation, while freeRASP uses a universal binary that is more susceptible to bypass.&#x20;
* **Enhanced API Protection**: Safeguard your APIs and benefit from risk scoring with our proprietary technology, [**AppiCrypt®**](#appicrypt-r).

For further details, please refer to the [next page](https://docs.talsec.app/freerasp/freerasp/features-and-pricing-plans/the-key-difference-freerasp-vs-rasp).

### AppiCrypt®

One of the most valued commercial features is [AppiCrypt®](https://www.talsec.app/appicrypt) - App Integrity Cryptogram.

It allows easy-to-implement API protection and App Integrity verification on the backend to prevent API abuse:

* Bruteforce attacks
* Botnets
* API abuse by App impersonation
* Session-hijacking
* DDoS

It is a unified solution that works across all mobile platforms without dependency on external web services (i.e., without extra latency, an additional point of failure, and maintenance costs).

### Malware Detection

**Malware Detection** provides active in-app protection against both **known & zero-day malware**, ongoing **malware campaigns**, **counterfeit app clones**, and other **risky and suspicious apps** that could compromise user data or your backend services. It evaluates applications, highlights high‑risk findings, and reports them back to your mobile app for real‑time security decisions and logging.

Combination of robust **on-device Offline Scanning for Suspicious and Risky Apps** with an **optional online App Reputation API** verifying findings against malware DB, allows you to balance privacy, performance, and coverage according to your risk model.

{% hint style="info" %}

#### Online Malware Database by Gen (Norton, Avira)

By teaming up with [Gen](https://www.gendigital.com/), the parent company of Norton and Avast, we bring you an unparalleled malware database. It continuously evolves, drawing top-tier threat intelligence from a massive network of 500 million global users.

<img src="https://3557356308-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQ2PxZTOjhquOxcxftTrm%2Fuploads%2FGLFWKOovAwrdc3ViwZX5%2FGen-Family-Lockup-Horizontal-Stacked-Light-RGB-Web.png?alt=media&#x26;token=7bfa9ec7-746c-4445-b11a-63e1155b60dd" alt="" data-size="original">
{% endhint %}

## Plans Comparison

freeRASP is freemium software, i.e. there is a [**Fair Usage Policy (FUP)**](https://docs.talsec.app/freerasp/terms-of-service/fair-usage-policy-fup) that imposes some limitations on free usage.&#x20;

{% hint style="success" %}
You can try freeRASP and then upgrade easily to an enterprise service.

Learn more about commercial features at [talsec.app](https://talsec.app/?utm_source=docs-portal).
{% endhint %}

#### [**Get your price** ](https://www.talsec.app/#price?utm_source=docs-portal)**for premium products.**&#x20;

<table data-full-width="true"><thead><tr><th></th><th width="149">freeRASP</th><th>RASP+ Starter</th><th>Full App Safety Suite Starter</th><th>Full App Safety Suite Business</th></tr></thead><tbody><tr><td></td><td></td><td><a href="https://billing.talsec.app/subscribe/fa3bdfc849c29caa6433c690b1e73bbbe46b3ce66296f261a014a7821ce3dfea/S.L1"><strong>Subscribe</strong></a></td><td><a href="https://billing.talsec.app/subscribe/fa3bdfc849c29caa6433c690b1e73bbbc20acdea99041b50a4c7041e98514d64/S.L2L3"><strong>Subscribe</strong></a></td><td><a href="https://www.talsec.app/#price?utm_source=docs-portal"><strong>Get your price</strong></a></td></tr><tr><td>Best fit for</td><td>Low value apps and educational purpose</td><td>Try RASP+ and perform Penetration testing</td><td>Try advanced resilience and protection of App and APIs</td><td>Production usage</td></tr><tr><td>App Shielding SDK</td><td><strong>freeRASP SDK</strong> is a free, easy-to-integrate runtime threat detection solution for small businesses and projects, supporting up to 100,000 device downloads. It helps you quickly grasp the main features, experiment, and try integrating Talsec SDKs.<br><br>While it is a good threat detection tool, freeRASP’s limited resilience against bypasses and limited telemetry data collection make it unsuitable for commercial use in production, especially in regulated or privacy-sensitive domains.</td><td><p><strong>RASP+ SDK</strong> delivers banking-grade security designed for professional, regulated, or high-risk apps needing maximum hardening.<br><br>RASP+ is built to pass rigorous penetration tests, ensuring real-time detection and mitigation of attacks. </p><p></p><p>It guarantees compliance and robust defense.</p></td><td><strong>RASP+ SDK</strong> delivers banking-grade security designed for professional, regulated, or high-risk apps needing maximum hardening. <br><br><strong>Its customizable SDKs include advanced threat prevention like AppiCrypt for API and Transaction Integrity protection.</strong> ✅<br><br>RASP+ is built to pass rigorous penetration tests, ensuring real-time detection and mitigation of attacks. <br><br>It guarantees compliance and robust defense.</td><td><strong>RASP+ SDK</strong> delivers banking-grade security designed for professional, regulated, or high-risk apps needing maximum hardening. <br><br>Its customizable SDKs include advanced threat prevention like AppiCrypt for API and Transaction Integrity protection. <br><br>RASP+ is built to pass rigorous penetration tests, ensuring real-time detection and mitigation of attacks. <br><br><strong>With strict privacy (no data sent to Talsec)</strong> ✅, it guarantees compliance and robust defense.</td></tr><tr><td><a data-footnote-ref href="#user-content-fn-1">Resilience to Reverse Engineering and bypass</a></td><td>limited</td><td>advanced ✅</td><td>advanced ✅</td><td>advanced ✅</td></tr><tr><td><a data-footnote-ref href="#user-content-fn-2">SDK obfuscation</a></td><td>limited<br>(same for all users)</td><td>advanced (individual per build) ✅</td><td>advanced (individual per build) ✅</td><td>advanced (individual per build) ✅</td></tr><tr><td><p><a data-footnote-ref href="#user-content-fn-3">Root &#x26; jailbreak protections</a></p><ul><li>su, Magisk, Dopamine, KernelSU, HideMyApplist, Shamiko</li></ul></td><td>basic</td><td>advanced ✅</td><td>advanced ✅</td><td>advanced ✅</td></tr><tr><td><p>Runtime reverse engineering controls</p><ul><li>Debugger</li><li>Emulator / Simulator</li><li>Hooking and reversing frameworks (e.g. Frida, Magisk, XPosed, Cydia Substrate and more)</li><li></li></ul></td><td>basic</td><td>advanced ✅</td><td>advanced ✅</td><td>advanced ✅</td></tr><tr><td><p>Runtime integrity controls</p><ul><li>Tampering protection</li><li>Repackaging / Cloning protection</li><li>Device binding protection</li><li>Unofficial store detection</li></ul></td><td>basic</td><td>advanced ✅</td><td>advanced ✅</td><td>advanced ✅</td></tr><tr><td><p>Device OS security status check</p><ul><li>HW security module </li><li>Screen lock </li><li>Google Play Services availability</li><li>Huawei Mobile Services availability</li><li>Last security patch update</li><li>System VPN </li><li>Developer mode, ADB</li></ul></td><td>yes </td><td>yes</td><td>yes</td><td>yes</td></tr><tr><td><p></p><p>Anti-Spoofing &#x26; Misuse detection</p><p></p><ul><li><a data-footnote-ref href="#user-content-fn-4">Unsecure WiFi Detection</a></li><li><a data-footnote-ref href="#user-content-fn-5">Location Spoofing</a></li><li><a data-footnote-ref href="#user-content-fn-6">Time Spoofing</a></li><li><a data-footnote-ref href="#user-content-fn-7">Multi-instance detection</a></li></ul></td><td>yes</td><td>yes</td><td>yes</td><td>yes</td></tr><tr><td><p>Screen Capture protection</p><ul><li>Block Screen Capture, Mirroring, Sharing</li><li>Detect Screenshot, Screen Recording<br></li></ul></td><td>yes</td><td>yes</td><td>yes</td><td>yes</td></tr><tr><td><p>UI protection</p><ul><li>Overlay protection</li><li>Accessibility services misuse protection</li></ul></td><td>no</td><td>yes ✅</td><td>yes ✅</td><td>yes ✅</td></tr><tr><td>Penetration Test Ready</td><td>can be bypassed by professional</td><td>designed to sustain pentesting ✅</td><td>designed to sustain pentesting ✅</td><td>designed to sustain pentesting ✅</td></tr><tr><td><strong>App Hardening Suite</strong></td><td></td><td></td><td></td><td></td></tr><tr><td><p><a href="https://app.gitbook.com/s/xFHPMAbn16uoDyOtoiaC/product/app-hardening-suite#about-secret-vault">Secret Vault</a> for Strings Protection</p><ul><li>Protect secrets in your code, third-party API keys, tokens, encryption keys, config files</li><li>On-the-fly key provisioning and rotation</li></ul></td><td>no</td><td>no</td><td>yes ✅</td><td>yes ✅</td></tr><tr><td><p><a href="https://app.gitbook.com/s/xFHPMAbn16uoDyOtoiaC/product/app-hardening-suite#about-dynamic-tls-pinning">Dynamic TLS Certificate Pinning</a></p><ul><li>Strong MitM and DNS spoofing protection</li><li>Decoupled certificate and app lifecycle</li><li>Pins never stored in app</li></ul></td><td>no</td><td>no</td><td>yes ✅</td><td>yes ✅</td></tr><tr><td><strong>AppiCrypt® - App Integrity Cryptogram</strong></td><td></td><td></td><td></td><td></td></tr><tr><td><p><a href="https://app.gitbook.com/s/xFHPMAbn16uoDyOtoiaC/product/appicrypt">AppiCrypt® for Mobile</a></p><ul><li>API protection and anti-API abuse</li><li>Transactions authenticity and integrity verification</li><li>Device Risk Scoring</li><li>RASP advanced anti-bypass</li></ul></td><td>no</td><td>no</td><td>yes ✅</td><td>yes ✅</td></tr><tr><td><p><a href="https://app.gitbook.com/s/xFHPMAbn16uoDyOtoiaC/product/appicryptweb">AppiCrypt® for Web</a></p><ul><li>API protection and anti-API abuse</li><li>Transactions authenticity and integrity verification</li><li>Browser-based Apps protection using WebAssembly</li><li>Anti-bot and sesion hijacking</li><li>Anti-web scraping</li></ul></td><td>no</td><td>no</td><td>no</td><td>yes ✅</td></tr><tr><td><a data-footnote-ref href="#user-content-fn-8"><strong>Malware Detection</strong></a></td><td></td><td></td><td></td><td></td></tr><tr><td><p></p><ul><li>Detection of apps installed from untrusted stores or side-loaded</li><li>Detection of apps with suspicious permissions granted</li><li>Detection of risky apps</li><li>Detection of dangerous apps</li></ul></td><td>basic (<a href="broken-reference">freeMalwareDetection</a>)</td><td>no</td><td>advanced <a href="https://app.gitbook.com/s/xFHPMAbn16uoDyOtoiaC/product/malware-detection">Malware Detection</a> ✅</td><td>advanced <a href="https://app.gitbook.com/s/xFHPMAbn16uoDyOtoiaC/product/malware-detection">Malware Detection</a> ✅</td></tr><tr><td><a data-footnote-ref href="#user-content-fn-9"><strong>App Security Monitoring and Logging</strong></a></td><td></td><td></td><td></td><td></td></tr><tr><td>Threat events data collection</td><td>mandatory collection to Talsec services</td><td>mandatory collection to Talsec services</td><td>mandatory collection to Talsec services</td><td>optional and customizable logs destination ✅</td></tr><tr><td>App and threats data monitoring portal and Dashboard</td><td>limited functionality, no raw data access</td><td>full functionality with access to raw data search ✅</td><td>full functionality with access to raw data search ✅</td><td>full functionality with access to raw data search ✅</td></tr><tr><td>Self-care portal for the SDK configuration</td><td>no</td><td>yes ✅</td><td>yes ✅</td><td>yes ✅</td></tr><tr><td><a data-footnote-ref href="#user-content-fn-10"><strong>Support and Maintenance</strong></a></td><td></td><td></td><td></td><td></td></tr><tr><td>SLA and maintenance updates</td><td>not committed</td><td>yes ✅</td><td>yes ✅</td><td>yes (advanced variants) 🏆✅</td></tr><tr><td><a href="../terms-of-service/fair-usage-policy-fup"><strong>Fair Usage Policy</strong></a> <strong>- up to 100K Devices</strong></td><td></td><td></td><td></td><td></td></tr><tr><td>Total apps downloads limit</td><td>up to 100K Devices (premium upgrade required for more)</td><td>up to 10K</td><td>up to 10K</td><td>100K+ Devices 🚀</td></tr><tr><td>End-users' threats data collection and processing by Talsec</td><td>mandatory</td><td>mandatory</td><td>mandatory</td><td>optional and customizable logs destination ✅</td></tr><tr><td></td><td></td><td><a href="https://billing.talsec.app/subscribe/fa3bdfc849c29caa6433c690b1e73bbbe46b3ce66296f261a014a7821ce3dfea/S.L1"><strong>Subscribe</strong></a></td><td><a href="https://billing.talsec.app/subscribe/fa3bdfc849c29caa6433c690b1e73bbbc20acdea99041b50a4c7041e98514d64/S.L2L3"><strong>Subscribe</strong></a></td><td><a href="https://www.talsec.app/#price?utm_source=docs-portal"><strong>Get your price</strong> </a></td></tr></tbody></table>

***

For additional comparison details and information on planned features, please see the [next page](https://docs.talsec.app/freerasp/freerasp/features-and-pricing-plans/the-key-difference-freerasp-vs-rasp).

[^1]: Basic .freeRASP threats detection mechanisms allow developers to manage reactions on detected security issues. Active threats prevention and configurable reactions make .RASP+ more resilient to bypass techniques. It implies threats prevention vs detection only in .freeRASP (API callbacks that developers would need to obscure and implement). The reactions to threats (like killing the app) can be configured to be triggered from within .RASP+ SDK at a lower level of deeply obscured Native C code. Hence it is much harder to locate and bypass by reverse engineering than reaction maid in App logic code as in .freeRASP.

[^2]: .RASP+ binary SDK is built individually with binding to App-specific data (signing cert hash, package name, teamID , etc.). freeRASP SDK is entirely the same binary for all users i.e. "known for attackers". Practically the .freeRASP-protected app may be too weak to pass the professional pentesting because an experienced pentester will be capable of bypassing it.

[^3]: Rooting/Jailbreaking is a technique of acquiring privileged control over the operating system of an Android/iOS device. While most users root their devices to overcome the limitations put on the devices by the manufacturers, it also enables those with malicious intent to abuse privileged access and steal sensitive information. Many different attack vectors require privileged access to be performed. Tools such as Magisk or Shadow can hide privileged access and are often used by attackers.

[^4]: Man-in-the-middle attacks, risk of session hijacking and untrusted certificates forging

[^5]: Geofence and region lock bypasses, mocked GPS position

[^6]: Expired OTP or token reuse, trial period abuse

[^7]: Parallel Space detection, fake accounts detection, promo offer / referral bonus abuse

[^8]: Active protection against known malware, ongoing malware campaigns, counterfeit app clones, and other potentially risky apps is essential for the overall security posture.

[^9]: App security monitoring service is shared both for Android and iOS. App security monitoring service (i.e., reports and email alerts) for .freeRASP is provided by Talsec free of charge within FUP.

[^10]: Silver Support and maintenance for commercial plans with committed Reaction, Restoration and Resolution time.
