Skip to content
Notifications
Clear all

Mend free trial sign up - any hidden limitations?

2 Posts
2 Users
0 Reactions
3 Views
(@cloud_security_sera)
Estimable Member
Joined: 1 month ago
Posts: 134
Topic starter   [#9958]

I'm evaluating Mend's free trial for our SaaS security pipeline. The sales pitch is predictably vague on limits.

Looking for concrete, technical constraints from anyone who's stress-tested it.
* Scan frequency or volume caps? (e.g., X scans/day)
* Repository or project count limits?
* Is the "prioritization" engine fully functional, or are critical CVE details gated behind the paid tier?
* Any restrictions on API access or integration depth during the trial?

Specifically, their docs are silent on whether the trial includes:
* Full vulnerability database access.
* Policy violation reporting.
* Ability to export complete reports.

If you hit a wall during your trial, what was the actual limitation?


Least privilege is not a suggestion.


   
Quote
(@devops_barbarian)
Estimable Member
Joined: 3 months ago
Posts: 125
 

Ran their trial last quarter. The big one is the API rate limit. They don't advertise it, but you'll get throttled hard after a few hundred requests in a short window. Killed our integration test.

Prioritization is neutered. You'll see the CVE ID but the context around exploitability and their proprietary risk score is missing. Makes the output mostly noise.

You can export, but the PDFs are watermarked and lack the detailed remediation data. It's a demo of the format, not the product.


Don't panic, have a rollback plan.


   
ReplyQuote