Heads up This site is currently under heavy development.
// PLANS

Compare plans

Every issue and every chart here is free to read, with no account. A plan buys delivery and depth — the day's releases in your inbox, narrowed to the tools you actually run, and the signals the public charts hold back: who is slipping, what keeps breaking, and where the market is moving. See what subscribers get →

One account, both sites: sign in with the same email on The Cyber Toolchain — no second account to set up. A paid plan covers both sites only with the cross-site add-on below; free reading needs nothing extra.

SeriesWhat it isWhenOn the siteIn your inbox
Tailthe daily release firehose+ documentation changes and more examplesEvery weekdayusually by 7:30am ET (11:30 UTC)Every issuefree, no account
Greponly the tools you run+ same as above, but filteredWhen your tools shipwith the daily — usually by 7:30am ET (11:30 UTC)Not published hereemail only
Headthe week's top picksFridaysusually by 1pm ET (17:00 UTC)Every issuefree, no accountFreeno card
Diffwhat vendors changed and didn't announceWednesdaysusually by 12:30pm ET (16:30 UTC)One samplethe rest arrives by email
Uniqhow vendors reposition themselvesMonthlyNot published hereemail only
Prices in
Billed by Paddle in your country's currency where we price in one, and in US dollars everywhere else. Local tax is added at checkout.
// BEHIND EVERY PLAN
  • 174 tools tracked, open-source and commercial
  • ~70 releases an issue, bug-fix noise dropped
  • 10 categories to narrow it down to

Every plan reads the same pipeline. What changes is how much of it reaches you.

Free
$0
No card. Unsubscribe in one click.
Stay in touch weekly.
Subscribe free or on Substack →

Not recommended — Head only, as plain posts.

Practitioner
$10/mo
or $100/yr save 17%
Stay current on the tools you run.
Subscribe Subscribe annually
Researcher
From $20/mo
or $200/yr save 17%
Work the whole corpus, not just the issues.
Subscribe Subscribe annually
Business
$1,000/mo
Company email address required. Starts at five seats.
Keep pace with a whole category.
What arrives in your inbox
Head — the week's top picks Fridays. The week's top picks, each with why it matters. Five picks.
Head at ten picks instead of five The same week judged to the same bar, five more tools deep. Switch it on from your account.
Tail — every release Every weekday, across the whole watchlist.
Grep — only the tools you monitor Arrives on the days your tools ship, and stays quiet otherwise.
Grep Monthly and Quarterly Reports One report per tool you’ve named individually, across every Grep — every release from the period, cadence trends, and breaking changes and deprecations called out up top. Switch either cadence on from your account.
Diff — documentation and API changes Wednesdays. What vendors changed in their docs and APIs without announcing it — a new endpoint, a renamed parameter, a field being retired, caught when the reference updates, not when your integration breaks.
Uniq — how vendors reposition themselves Coming soon Monthly. The category a vendor claims, the buyer they name, the plan names and prices on their pricing page — and the language the whole market is picking up or dropping, counted across the cohort rather than one page at a time.
Additional context and signals A delivered issue carries more than the web edition: the capabilities vendors shipped without announcing them, deeper worked examples, and the signals we pick up between releases.
What you control
Greps Each Grep is its own newsletter — its own list, its own subject line, its own email. One for the stack you run, one for the vendors you are evaluating, one to forward to your team. 1 5 Unlimited
Monitor specific tools Pick from the full watchlist; you only hear when those ship.
Monitor whole categories Cloud security, detection engineering, appsec, and the rest.
Narrow the daily to categories Take the daily without taking the whole watchlist — cloud, detection, appsec, or whichever few you work in.
How many tools you can track Unlimited Unlimited Unlimited
The changed text itself Documentation and API changes arrive with the before-and-after, not a description of it — the exact line a vendor edited, and the endpoint, parameter, or field that moved with it.
For teams
Seats Business starts at five seats; more are added on request. 1 1 1 From 5
Shared watchlists One list the whole team follows, changed in one place.
We build your watchlist with you We work out which vendors belong on it, and anything missing gets tracked first.
Build on it
API and MCP access Coming soon Query the toolchain from your own scripts, dashboards and agents — the same data behind the issues, filtered the same way. Unmetered: point your own assistant at it and ask as much as you like. Unlimited Unlimited
Answers across the whole corpus Coming soon Ask a question and get an answer drawn from every release, doc change and tool we’ve tracked, instead of reading issue by issue. 500 / month Unlimited
Charts and graphs published nowhere else
The signals the public charts hold back Who documents what they ship and who does not. Whose platform goes down, and how often. Which categories are accelerating and which have stalled. What each tool keeps breaking, how concentrated the damage is, and whose fixes do not hold. The public charts show the shape; a plan tells you who. See one of the redacted charts →
New findings the moment they surface Coming soon A category quietly consolidating, a vendor that has stopped shipping, a capability three tools added in the same month — sent when we find it, not held back for a quarterly report.
Hiring signals — where each vendor is investing Open roles across every tracked vendor whose job board we can read, by product area, function and region — the earliest public signal of where a company is going. Refreshed weekly.
Free for everyone, no account
Read every Tail and Head issue on the site The web edition covers the releases. Delivered issues add the context and signals around them.
The full tools directory and analytics Every chart is readable with no account — every score, bar and figure, and the methodology to re-derive them. Researcher and Business add the analytics and signals published nowhere else.
RSS — combined, per series, per category, per tool

Why so much of this is free

People defending an organization should know what their tools can actually do, and most of that never reaches them. So the issues, the tools directory and the charts stay open here, to anyone, with no account.

Subscriptions fund that work, and they buy back your attention. Instead of watching a hundred vendors, you get the day's releases that matter to your stack, the changes vendors shipped without telling anyone, and a straight answer to the questions a buyer actually asks: who is slipping, what keeps breaking, and where the market is moving. See a real issue before you pay.

What counts as a release

A release only appears if it ships something new. Bug-fix-only releases are dropped, and what's left is cut down to the new capability plus the instructions to try it — with any screenshots the release itself published.

How the filtering works

Pick tools, categories, or both — they add together, so "Nuclei plus everything in container-security" is one watchlist. Grep then only reaches you on days something on that list actually ships, rather than arriving empty.

Changing or cancelling

Change plan or cancel whenever you like, from a link in any issue. Annual billing is two months cheaper than monthly and can be cancelled the same way.

Who the Researcher plan is for

Anyone whose question is bigger than one issue — analysts, founders, product teams sizing a market. It opens the corpus itself: query it from your own scripts and agents, read the exact text of a documentation or API change rather than a summary, and get the findings and charts we draw out of the whole archive as they surface.

Why a vendor plan exists

It's the same pipeline pointed at a different question. A practitioner asks "what did the tools I run just ship"; a product team asks "what did the whole category just ship." The second question is a team's, not one person's — so Business carries everything in Researcher across five seats, plus a shared watchlist we build with you.

Only the free tier is open today — read the latest issue or see what subscribers get.

my-toolchain — 0 tools
paste an install list to detect your tools

A brew list, a Brewfile, requirements.txt, a Dockerfile — or just the product names, free-form. Nothing leaves your browser.

    browse all tools →