Skip to content

Plans & Pricing

Stay on your current Rails version – Continue receiving security updates for as long as you need them.

Startup
  • Rails 2.3 patches
  • Rails 3.2 patches
  • Rails 4.2 patches
  • Rails 5.2 patches
  • Rails 6.1 patches
  • Rack patches
  • 2 applications (info)
  • Payment by credit card (info)
180€
/ month
approx. $188 / month
Standard
  • Rails 2.3 patches
  • Rails 3.2 patches
  • Rails 4.2 patches
  • Rails 5.2 patches
  • Rails 6.1 patches
  • Rack patches
  • 8 applications (info)
  • Multiple payment options (info)
480€
/ month
approx. $495 / month
Enterprise
  • Rails 2.3 patches
  • Rails 3.2 patches
  • Rails 4.2 patches
  • Rails 5.2 patches
  • Rails 6.1 patches
  • Rack patches
  • 20 applications (info)
  • Multiple payment options (info)
  • Assistance for integration (info)
900€
/ month
approx. $930 / month

Free Rails 2.3 LTS community edition

In addition to our commercial plans, we offer a free community edition. The community edition provides security patches for Rails 2.3, but with some limitations:

  • Patches are made available 10 days after their release to paid subscribers.
  • Only supports Rails 2.3.
  • Gems cannot be retrieved from a Rubygems server; they must be pulled from a Git repository instead.
Custom version of Rails
Do you need support maintaining a custom version of Rails? Feel free to contact us.
Contact us

Frequently asked questions

A monolithic Rails app counts as a single application, regardless of on how many servers it runs, how many (sub-)domains it serves, or if there are staging or test environments. If instead of a monolithic app, multiple Rails apps are used in a service architecture, but look like a single service or product to the outside world, they still count as a single application.

Apps with different codebases powering separate services or products count as separate applications.

Agencies

An agency maintaining applications for several clients can use a single Rails LTS license, as long as the application limit is not exceeded.

If a client also has its own developers working on the application, a separate license is required.

Rails LTS is normally only ordered through our website and paid by credit card.

Some customers have additional requirements for procurement, such as

  • payment by bank transfer,
  • annual purchase orders,
  • annual statements of work,
  • invoices submitted on a procurement platform,
  • etc.

We support this (up to a reasonable level), but only for Standard or Enterprise plans.
Bank transfer is only available for annual payments.

When ordering you can select “bank transfer” as a payment method. If you cannot order directly through this website for other reasons, contact us instead.

Subscribers to the Enterprise plan will receive special support to ensure the successful integration of Rails LTS with complex Rails application setups.

In the past we have helped Enterprise customers with issues such as:

  • Use of Rails LTS with local gem mirrors
  • Issues with legacy versions of Rubygems or Bundler
  • Issues with conflicting gem dependencies or monkey patches
  • Support for large-scale deployments

We will assist your engineering team using email, Google Meet, or similar tools.

Plans and Pricing Service Level Agreement

All our paid plans guarantee swift response to vulnerabilities that have been disclosed on the Rails security list.

Highest-priority issues

This includes vulnerabilities that can be used to devastating effect, or are easy to exploit on a wide range of applications. Examples of this issue class are SQL injection or remote code execution.

We will begin investigating high-priority issues within 24 hours of disclosure and will produce a new release of Rails LTS as soon as commercially feasible.

Low-priority issues

This includes issues that are extremely difficult to exploit, or can only be exploited given very uncommon configurations.

Patches for low-priority issues will be produced beginning on the first business day after disclosure.

How we classify issues

Whether or not an issue qualifies as a "highest-priority issue" will be decided by us (makandra GmbH) on a case-by-case basis. We are very conservative in our judgement and prefer to err on the side of caution.

For some context, in the first year of Rails LTS our reaction times were consistently below 24 hours:


AdvisoryTime until Rails LTS patch
CVE-2013-449116.5 hours
CVE-2013-641416.5 hours
CVE-2013-641516.5 hours
CVE-2013-641616.5 hours
CVE-2013-641716.5 hours
CVE-2014-008016.0 hours
CVE-2014-008116.0 hours
CVE-2014-008216.0 hours
CVE-2014-013020.0 hours
CVE-2014-348222.5 hours
CVE-2014-348322.5 hours