LICENSEWARE

Thales Imperva licensing

This article is about how Imperva application security and data security products, which are part of the Thales group, are measured in subscription SKUs, based on the Imperva License definitions and rules document. It does not cover the Imperva EULA clauses, which could not be read in this pass, and does not replace the quote, order or agreement.

On This Page

Imperva licensing is the way Imperva products and services, now part of the Thales group, are quantified in an order.[2] Imperva states that a sales quotation specifies the products and services ordered and includes one or more SKUs that set out the Licensed Volume of each product or service, and it publishes a License definitions and rules (LDR) document that explains the terms used in SKUs.[1] Where the LDR does not clarify a term, Imperva asks the customer to contact it.[1] Imperva also states that it may, acting reasonably, determine the Licensed Volume from time to time using the LDR rules and other pragmatic guidelines it reasonably determines.[1] Catalog: guidance status.

Plans and editions

Imperva sells plans as term-based subscriptions that combine certain products and services, and the plan is named in the SKU.[1]

Plan family Description in the LDR Catalog row 
App Protect Core, Professional, Enterprise and 360 Term-based plans combining certain Products and Services; a summary of each plan’s functionality is on the Imperva plans page. App Protect Essentials is a legacy plan.[1] App Protect plans 
FlexProtect Term-based plans; some include a number of Tokens set in the SKU.[1] FlexProtect plans 
Data Security Fabric Term-based plan with functionality per instance that includes Data 360, Data Secure, Discover and Classify (structured or unstructured), Sonar Reporting Add On and Sonar Add On.[1] Data Security Fabric plans 
Data Core and Data Redaction Term-based plans combining the functionality described on Imperva plan pages.[1]  
Basic Managed DNS A limited DNS service of up to 10 zones and 20 million queries per month; Advanced Managed DNS is an add-on to an App Protect plan.[1]  

Metrics

Database Server

For data security products the central unit is the Database Server: physical or virtual hardware with fewer than 65 CPU cores (except for Data Secure and Data 360, whose Licensed Volume does not include CPU cores) that runs databases.[1] The count is the peak concurrent number of database server hosts monitored on any one day in a month, with the period starting on the day the base plan subscription began.[1] A server that is actively monitored or classified counts whether it is active or passive: a database in disaster recovery mode that is not monitored is excluded, but one in high availability with automatic failover that is monitored is included.[1] Servers with 65 or more cores are classed as Xlarge servers.[1] Catalog: Database Server, rules peak concurrent count, Xlarge servers.

Imperva gives worked examples in an appendix.[1]

Scenario Count under the LDR 
One MongoDB customer database across 50 servers, nothing else on them 50 Database Servers 
One server running Oracle, SQL Server and Sybase databases 1 Database Server 
Teradata across 50 compute nodes with five analytics databases 50 Database Servers, not 5 
10 servers of 24 cores, each running one Oracle instance 10 Database Servers 
One VMware host with five VMs, three running Oracle 3 Database Servers 

The last example means virtualisation does not reduce the count below the number of virtual machines with a monitored database.[1] For datasources, a SKU that names a number of datasource instances or nodes limits the right to that many, and where none is stated none is included and each must be licensed separately; each instance of a datasource counts as one irrespective of how many servers host it.[1] Combining interfaces to reduce or obscure the true number of Database Servers is not permitted, and Imperva may extrapolate to reflect the true number it reasonably determines.[1] Catalog: no combining of interfaces.

Other equivalencies apply. Certain datasource types count as more or less than one server licence under an Imperva table. For plans licensed per Database Server that include functionality otherwise licensed by Event, every 50 million events processed count as one Database Server.[1] Catalog: event equivalency.

Events, API Requests, Files and Redactions

An event is each command, query, login or logout processed by products that monitor databases or other data stores.[1] An API Request is each individual interaction with a protected application interface, so one request and response pairing results in more than one API Request, and API Security as a SaaS add-on and as software are separate, non-exchangeable products licensed by API Requests per month.[1] Data Redaction is licensed per Redaction: redacting the same file one thousand times counts as one thousand Redactions.[1] Discovery and classification plans have no limit on Database Servers or Files that can be discovered, but the number classified is subject to the Licensed Volume.[1] Catalog: Events and API Requests.

Bandwidth, sites and requests per second

For cloud application security the units are bandwidth in Mbps or Gbps, measured in accordance with a calculation documented on docs.imperva.com; Covered Sites; and Peak requests per second (RPS).[1] A Covered Site is a web or private-network location that may have a unique SSL certificate or CNAME and that cannot be protected using an existing site and policy configuration; what qualifies depends on the product.[1] RPS is the aggregate peak HTTP requests per second over the previous 12 months as typically measured by the load balancers in front of the in-scope sites, and Imperva uses it to decide which RPS tier may be bought.[1] For App Protect Enterprise and App Protect 360, Advanced Bot Protection page views are deemed included up to 5 million per month for each 1 Mbps in the subscription.[1] Catalog: Bandwidth, Peak RPS, Covered Site, rule bot protection page views.

Tokens, users, masking and other units

FlexProtect plans can include Tokens, which the customer applies to protect databases, bandwidth, websites, page requests or Peak RPS, allocating them at its discretion provided the total in use does not exceed the Tokens purchased.[1] Data masking is licensed per terabyte of source production data masked, whatever the volume of post-masking data: Imperva’s example is 10 TB masked and replicated to three test databases, which is licensed as 10 TB, not 30 TB.[1] Users are individual access credentials, each of which must only be used by a single person.[1] Other units include appliances (Imperva-supplied hardware only, where the number of agents and scans varies by type), Million Service Units for mainframes, logical partitions for AS/400, and RASP applications, where multiple instances of the same application do not count but each microservice is a unique application.[1] Catalog: FlexProtect Token, Data masking terabyte, Users, rules token allocation, data masking, Users.

Term, overage and service limits

  • No roll-over. Where Licensed Volume is a monthly total there is no roll-over to the next month, and entitlements do not roll to the next year or subscription term.[1] Catalog: no roll-over.
  • Overages. Imperva refers readers to a SaaS Services Overages Policy and a Data Security Software Licensed Volume Policy on docs.imperva.com, which were not read here.[1]
  • Retained data. Some plans limit how long data collected by the product may be retained, for example one month or one year per monitored database server, and some SKUs provide unlimited retention.[1]
  • DDoS. A customer that has not subscribed to a DDoS protection product is not owed a DDoS service when attacked, and Imperva may at its discretion null-route, bypass or mitigate the traffic.[1] On-Demand DDoS diversion is capped at 72 hours per incident and 240 hours per monthly billing period, with traffic returned to the customer’s network within 48 hours of the attack ending.[1] Contingency DDoS plans are back-up services whose volume is limited by a matrix, and once exhausted the entitlement expires and a new one must be bought.[1] Catalog: On-Demand DDoS cap.

Programs

Imperva may permit a reasonable number of database servers for testing at one time, depending on the circumstances and the size of the customer’s total entitlement. To qualify, the server and software combination must be used solely for compatibility or functionality testing, not production, backup, recovery, high availability or disaster recovery, and resulting security or audit data must not be sent to a production environment.[1] Catalog: Testing Exemption, FlexProtect token allocation.

Contract and audit

Imperva’s LDR states that capitalised terms not defined in it have the meaning in the Imperva End User License Agreement, and the Thales Cyber Security Products End User Agreement applies where no signed agreement exists.[1][2] Catalog: End User Agreement applies absent a signed agreement. Audit and inspection rights, if any, sit in those agreements and were not read. For general practice see software license audit.

Practical notes for inventories

  • Record the Licensed Volume from the SKU on each quote, not from marketing plan names.
  • For databases, list each monitored host, the number of VMs with monitored databases and any disaster recovery hosts that are not monitored, then compare the peak day in each month.
  • For cloud applications, keep the bandwidth, Covered Site and Peak RPS history per account, and note that unused monthly volume does not carry over.

Out of scope

This article does not cover Imperva support and managed service guides, the professional services agreement, product feature differences between plans, or pricing, none of which Imperva publishes in the LDR.

References

  1. Imperva License definitions and rulesVersion 9 April 2025, 12 pages; the document states it is guidance and may not form part of a contract. Catalog: Imperva License definitions and rulesEffective 2025-04-09. Retrieved 2026-10-08.
  2. Thales Cyber Security Products End User AgreementLanding page; states Imperva, Inc. is part of the Thales group. Catalog: Thales Cyber Security Products End User AgreementRetrieved 2026-10-08.

See also

Catalog Rows Cited

12Rules3SKUs8Metrics2Programs

Esc