Compare plans
Every issue and every chart here is free to read, with no account. A plan buys delivery and depth — the day's releases in your inbox, narrowed to the tools you actually run, and the signals the public charts hold back: who is slipping, what keeps breaking, and where the market is moving. See what subscribers get →
One account, both sites: sign in with the same email on The Cyber Toolchain — no second account to set up. A paid plan covers both sites only with the cross-site add-on below; free reading needs nothing extra.
| Series | What it is | When | On the site | In your inbox |
|---|---|---|---|---|
| Tail | the daily release firehose+ documentation changes and more examples | Every weekdayusually by 7:30am ET (11:30 UTC) | Every issuefree, no account | On a planfrom $10/mo |
| Grep | only the tools you run+ same as above, but filtered | When your tools shipwith the daily — usually by 7:30am ET (11:30 UTC) | Not published hereemail only | On a planfrom $10/mo |
| Head | the week's top picks | Fridaysusually by 1pm ET (17:00 UTC) | Every issuefree, no account | Freeno card |
| Diff | what vendors changed and didn't announce | Wednesdaysusually by 12:30pm ET (16:30 UTC) | One samplethe rest arrives by email | On a planfrom $10/mo |
| Uniq | how vendors reposition themselves | Monthly | Not published hereemail only | On a planfrom $20/mo |
| // BEHIND EVERY PLAN
Every plan reads the same pipeline. What changes is how much of it reaches you. | Free $0 A$0 €0 £0 No card. Unsubscribe in one click. Stay in touch weekly. | Practitioner $10/mo A$16/mo €10/mo £8/mo
or $100/yr
save 17%
or A$160/yr
save 17%
or €100/yr
save 17%
or £80/yr
save 17% Stay current on the tools you run. | Researcher From $20/mo From A$30/mo From €20/mo From £16/mo
or $200/yr
save 17%
or A$300/yr
save 17%
or €200/yr
save 17%
or £160/yr
save 17% Work the whole corpus, not just the issues. | Business $1,000/mo A$1,500/mo €950/mo £800/mo Company email address required. Starts at five seats. Keep pace with a whole category. |
|---|---|---|---|---|
| What arrives in your inbox | ||||
| Head — the week's top picks Fridays. The week's top picks, each with why it matters. Five picks. | ✓ | ✓ | ✓ | ✓ |
| Head at ten picks instead of five The same week judged to the same bar, five more tools deep. Switch it on from your account. | — | ✓ | ✓ | ✓ |
| Tail — every release Every weekday, across the whole watchlist. | — | ✓ | ✓ | ✓ |
| Grep — only the tools you monitor Arrives on the days your tools ship, and stays quiet otherwise. | — | ✓ | ✓ | ✓ |
| Grep Monthly and Quarterly Reports One report per tool you’ve named individually, across every Grep — every release from the period, cadence trends, and breaking changes and deprecations called out up top. Switch either cadence on from your account. | — | ✓ | ✓ | ✓ |
| Diff — documentation and API changes Wednesdays. What vendors changed in their docs and APIs without announcing it — a new endpoint, a renamed parameter, a field being retired, caught when the reference updates, not when your integration breaks. | — | ✓ | ✓ | ✓ |
| Uniq — how vendors reposition themselves Coming soon Monthly. The category a vendor claims, the buyer they name, the plan names and prices on their pricing page — and the language the whole market is picking up or dropping, counted across the cohort rather than one page at a time. | — | — | ✓ | ✓ |
| Additional context and signals A delivered issue carries more than the web edition: the capabilities vendors shipped without announcing them, deeper worked examples, and the signals we pick up between releases. | — | ✓ | ✓ | ✓ |
| What you control | ||||
| Greps Each Grep is its own newsletter — its own list, its own subject line, its own email. One for the stack you run, one for the vendors you are evaluating, one to forward to your team. | — | 1 | 5 | Unlimited |
| Monitor specific tools Pick from the full watchlist; you only hear when those ship. | — | ✓ | ✓ | ✓ |
| Monitor whole categories Cloud security, detection engineering, appsec, and the rest. | — | ✓ | ✓ | ✓ |
| Narrow the daily to categories Take the daily without taking the whole watchlist — cloud, detection, appsec, or whichever few you work in. | — | ✓ | ✓ | ✓ |
| How many tools you can track | — | Unlimited | Unlimited | Unlimited |
| The changed text itself Documentation and API changes arrive with the before-and-after, not a description of it — the exact line a vendor edited, and the endpoint, parameter, or field that moved with it. | — | ✓ | ✓ | ✓ |
| For teams | ||||
| Seats Business starts at five seats; more are added on request. | 1 | 1 | 1 | From 5 |
| Shared watchlists One list the whole team follows, changed in one place. | — | — | — | ✓ |
| We build your watchlist with you We work out which vendors belong on it, and anything missing gets tracked first. | — | — | — | ✓ |
| Build on it | ||||
| API and MCP access Coming soon Query the toolchain from your own scripts, dashboards and agents — the same data behind the issues, filtered the same way. Unmetered: point your own assistant at it and ask as much as you like. | — | — | Unlimited | Unlimited |
| Answers across the whole corpus Coming soon Ask a question and get an answer drawn from every release, doc change and tool we’ve tracked, instead of reading issue by issue. | — | — | 500 / month | Unlimited |
| Charts and graphs published nowhere else | ||||
| The signals the public charts hold back Who documents what they ship and who does not. Whose platform goes down, and how often. Which categories are accelerating and which have stalled. What each tool keeps breaking, how concentrated the damage is, and whose fixes do not hold. The public charts show the shape; a plan tells you who. See one of the redacted charts → | — | — | ✓ | ✓ |
| New findings the moment they surface Coming soon A category quietly consolidating, a vendor that has stopped shipping, a capability three tools added in the same month — sent when we find it, not held back for a quarterly report. | — | — | ✓ | ✓ |
| Hiring signals — where each vendor is investing Open roles across every tracked vendor whose job board we can read, by product area, function and region — the earliest public signal of where a company is going. Refreshed weekly. | — | — | ✓ | ✓ |
| Free for everyone, no account | ||||
| Read every Tail and Head issue on the site The web edition covers the releases. Delivered issues add the context and signals around them. | ✓ | ✓ | ✓ | ✓ |
| The full tools directory and analytics Every chart is readable with no account — every score, bar and figure, and the methodology to re-derive them. Researcher and Business add the analytics and signals published nowhere else. | ✓ | ✓ | ✓ | ✓ |
| RSS — combined, per series, per category, per tool | ✓ | ✓ | ✓ | ✓ |
Why so much of this is free
People defending an organization should know what their tools can actually do, and most of that never reaches them. So the issues, the tools directory and the charts stay open here, to anyone, with no account.
Subscriptions fund that work, and they buy back your attention. Instead of watching a hundred vendors, you get the day's releases that matter to your stack, the changes vendors shipped without telling anyone, and a straight answer to the questions a buyer actually asks: who is slipping, what keeps breaking, and where the market is moving. See a real issue before you pay.
What counts as a release
A release only appears if it ships something new. Bug-fix-only releases are dropped, and what's left is cut down to the new capability plus the instructions to try it — with any screenshots the release itself published.
How the filtering works
Pick tools, categories, or both — they add together, so "Nuclei plus everything in container-security" is one watchlist. Grep then only reaches you on days something on that list actually ships, rather than arriving empty.
Changing or cancelling
Change plan or cancel whenever you like, from a link in any issue. Annual billing is two months cheaper than monthly and can be cancelled the same way.
Who the Researcher plan is for
Anyone whose question is bigger than one issue — analysts, founders, product teams sizing a market. It opens the corpus itself: query it from your own scripts and agents, read the exact text of a documentation or API change rather than a summary, and get the findings and charts we draw out of the whole archive as they surface.
Why a vendor plan exists
It's the same pipeline pointed at a different question. A practitioner asks "what did the tools I run just ship"; a product team asks "what did the whole category just ship." The second question is a team's, not one person's — so Business carries everything in Researcher across five seats, plus a shared watchlist we build with you.
Only the free tier is open today — read the latest issue or see what subscribers get.
Add The Cyber Toolchain?
The Cyber Toolchain is a newsletter about new features in cybersecurity tools, tracked the same way this site tracks AI tools — same pipeline, a different watchlist. See it →