|
1 | 1 | --- |
2 | | -title: "See all products" |
| 2 | +title: "Feature comparison" |
3 | 3 | date: 2021-02-02T20:46:29+01:00 |
4 | 4 | draft: false |
5 | 5 | type: docs |
6 | 6 | weight: 1 |
7 | 7 | --- |
| 8 | + |
| 9 | +**DefectDojo Open-Source** is a powerful, free vulnerability management platform with core importing, deduplication, basic dashboards, API access, and essential reporting — ideal for smaller teams or those wanting to self-host and extend the tool using community resources. |
| 10 | + |
| 11 | +**DefectDojo Pro** builds on that foundation with enterprise-oriented features such as advanced dashboards and reporting, automation and scripting via rules engine, connectors to many security tools, optimized import workflows, unified SOC & AppSec support, improved UI/UX, AI integration, enhanced security (SSO/MFA), and premium support options. |
| 12 | + |
| 13 | +| Feature / Capability | DefectDojo Open-Source | DefectDojo Pro | |
| 14 | +|---------------------|------------------------|----------------| |
| 15 | +| Core vulnerability management | ✔️ Import, track, and manage findings from 200+ security tools | ✔️ Everything in open-source, optimized for scale | |
| 16 | +| Finding deduplication | ✔️ Standard deduplication | ✔️ Advanced, configurable deduplication | |
| 17 | +| REST API | ✔️ Full REST API | ✔️ Full REST API | |
| 18 | +| Authentication & access control | ✔️ Local auth and basic RBAC | ✔️ SSO (SAML/OAuth), MFA, advanced RBAC | |
| 19 | +| User interface | ✔️ Community UI | ✔️ Modern Pro UI with performance improvements | |
| 20 | +| Dashboards & reporting | ✔️ Basic dashboards and reports | ✔️ Advanced, customizable dashboards and executive reporting | |
| 21 | +| Automation & workflows | ❌ Not included | ✔️ Rules Engine and automated workflows | |
| 22 | +| Import enhancements | ❌ Standard imports only | ✔️ Background imports, Smart Upload, Universal Parser, CLI uploads | |
| 23 | +| Tool integrations | ❌ Manual/API-driven | ✔️ Built-in **API Connectors** for popular AppSec and cloud tools | |
| 24 | +| Jira integration | ✔️ Included | ✔️ Included | |
| 25 | +| Project management integrations | ❌ Not included | ✔️ integrate with **Azure Devops**, **GitHub**, **GitLab** and **ServiceNow** | |
| 26 | +| Finding enhancements | ❌ Not included | ✔️ Automatic KEV, EPSS scoring and Ransomware tracking | |
| 27 | +| SOC & AppSec unification | ❌ AppSec-focused only | ✔️ Unified AppSec and SOC findings | |
| 28 | +| AI & next-generation features | ❌ Not included | ✔️ AI-assisted workflows, reporting and MCP support | |
| 29 | +| Support | Community support (GitHub, Slack, forums) | Commercial support with SLAs | |
| 30 | +| Hosting options | Self-hosted | Self-hosted or cloud-hosted | |
0 commit comments