Transparent Pricing

Choose the protection level that fits your organization. No hidden fees.

Core
$ 500 /month

Up to 25 endpoints — 24/7 monitoring for small offices

  • 24×7 monitoring of endpoints, email & firewall
  • AI-powered detection, human-reviewed escalations
  • Microsoft 365 or Google Workspace coverage
  • Email incident notifications with clear next steps
  • Auto-generated monthly threat report
  • Up and running in 1–2 days
  • Email support (business hours)
Get Started
Essential
$ 2,000 /month

Up to 10 log sources — perfect for small businesses & teams

  • 24×7 monitoring across all log sources
  • Alert triage and prioritization
  • Monthly executive threat report
  • Email & Slack incident notifications
  • Core MITRE ATT&CK coverage
  • Up to 10 log sources
  • Basic playbook automation
  • Email support (business hours)
Get Started
Elite
$ 6,000 /month

Up to 50 log sources — large organizations & enterprises

  • Everything in Advanced, plus:
  • Custom threat hunting campaigns
  • Compliance dashboards (SOC 2, HIPAA)
  • Dedicated security engineer
  • Tabletop exercise support
  • Vulnerability correlation
  • Up to 50 log sources
  • Custom integration development
  • Quarterly security reviews
  • Priority escalation path
  • On-site visits (as needed)
Contact Sales

Growing past 25 endpoints, or need custom detections, Slack alerts, or more log sources? That's Essential.

Add-Ons & Enhancements

Extend your MDR coverage with additional services

Extended Data Retention

Retain logs beyond standard 90 days for compliance or forensics.

+$500/month per TB

Vulnerability Management

Continuous scanning, prioritization, and remediation tracking.

+$15/endpoint/month

Tabletop Exercises

Guided incident response simulations for your team.

$2,500/session

Compliance Mapping

Custom reports aligned to SOC 2, HIPAA, PCI-DSS, or NIST.

+$1,000/month

Phishing Simulation

Monthly campaigns to test and train your users.

+$500/month

Premium Support

Dedicated Slack channel and priority response for all tiers.

+$750/month

Frequently Asked Questions

What's the difference between Core and Essential?

Core monitors a fixed set of sources — endpoints, email, and firewall — with our standard detection library, fully automated reporting, and email support. Essential adds up to 10 log sources of any type, tuned detections, and a two-week guided onboarding. If you have servers, an EHR system, or more than 25 endpoints, you want Essential.

Is Core still monitored by humans?

Yes. Our AI platform triages every alert at machine speed; anything that needs action is reviewed and escalated by our analysts, 24/7.

Can you work with our existing MSP?

Absolutely. We integrate seamlessly with your current IT provider. Your MSP continues to handle patching, endpoint management, and help desk, while we focus on threat detection, investigation, and response. We coordinate through shared ticketing and clear communication channels.

Do you require a specific EDR platform?

We strongly recommend endpoint detection and response (EDR), but we're platform-agnostic. We support Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne, and others. If you don't have EDR, we can help you choose and deploy the right solution.

What SIEM or log platform do you use?

We use industry-standard SIEM platforms including Splunk and modern data lake architectures. You don't need to manage or license these tools—they're included in our service. We handle all configuration, tuning, and maintenance.

How fast is onboarding?

Core clients are typically up and running in 1-2 days. On Essential and above, most clients achieve initial visibility within week 1, and we deliver your first tuned threat report and 24/7 monitoring by week 2. Complex environments may take 3-4 weeks for full coverage, but basic protection starts immediately.

Do you offer incident response (DFIR)?

Yes. All tiers include first-response and containment during an active incident. For deep forensic investigation, malware analysis, or extended remediation, we offer DFIR services that are scoped separately based on complexity.

What if we exceed the log source count?

Prices assume typical SMB telemetry volumes. If you exceed the tier limits, we'll work with you on custom pricing. Log sources include firewalls, domain controllers, servers, cloud tenants (M365, Google), EHR systems, VPN concentrators, and similar devices. Core is the exception — it isn't counted in log sources. It covers a fixed menu instead: one EDR tenant, Microsoft 365 or Google Workspace, and one firewall.

Is there a contract commitment?

We offer both annual contracts (with discounts) and month-to-month agreements. Annual contracts receive 15% savings and priority onboarding. Month-to-month requires 30-day notice for cancellation.

What regions do you support?

Our 24/7 SOC operates globally. We support organizations in North America, Europe, and APAC. For data residency requirements (GDPR, etc.), we can accommodate regional log storage and comply with local regulations.

Ready to get started?

Book a free consultation to discuss your security needs and find the right tier for your organization.

Book a Free Consultation