Pricing
Pricing that scales with you
Start free with up to 5 assets and scale per asset as you grow, enterprise-grade security operations without hiring a SOC team.
First 5 assets free · No credit card required
Compare plans
Every plan, feature by feature.
Higher tiers include everything below them. Need something custom?
Talk to our team.
| Features | Free $0 Up to 5 assets | Most popular Startup $15–$675 /month · 6–50 assets | Business Let's talk Custom | Enterprise / MSSP Custom Volume-based |
|---|---|---|---|---|
| Assets & Coverage | ||||
| Protected assets | Up to 5 | 6–50 | Custom | Unlimited |
| Asset monitoring | Basic | Full | Full | Full |
| Asset inventory & cloud sync (AWS/Azure/GCP/Hostinger) | – | |||
| 24/7 autonomous coverage | – | |||
| ingestions (Wazuh, Syslog, Google Workspace and more) | ||||
| Throughput | 2k | 5k | 10k | Unlimited |
| Detection & Investigation | ||||
| AI alert triage | ||||
| Autonomous investigation | ||||
| Threat-intel enrichment | ||||
| Detection rules | Limited | Standard | Advanced | Advanced |
| Incident correlation & attack chains | – | |||
| Investigation Cases (L2/L3 escalation) | – | |||
| AI Copilot | ||||
| Incident response | ||||
| Custom AI model selector | – | – | ||
| Response & Automation | ||||
| Automated containment (block-IP, isolate, power, disable-user) | – | |||
| Policy guardrail engine | – | |||
| SOAR support | – | AgentSOAR | + Shuffle | + Shuffle |
| Multi-channel notifications (Email, Slack, Telegram, PagerDuty and more) | All | All | All | |
| Reporting & Compliance | ||||
| AI incident reports | – | |||
| SOC activity reports (MTTD/MTTR/MTTA) | Weekly | All | All | All |
| Compliance reporting | – | – | ||
| Executive dashboards | – | – | ||
| Report export (HTML/PDF/Markdown) | – | |||
| Custom data retention | 7 days | 90 days | 1 year | Custom |
| Red Team, Exposure & Validation | ||||
| External vulnerability analysis | Free | Free | Free | Free |
| Continuous posture monitoring | – | Monthly | Weekly | Custom |
| Exposure verified deep / authorized assessment | – | – | – | |
| Red Team attack simulation (MITRE ATT&CK scenarios) | – | – | Basic | |
| Firehose SIEM load testing (EPS / MTTD percentiles) | – | – | – | |
| Integrations | ||||
| SIEM sources (Wazuh, splunk and more) | ||||
| Cloud sources (AWS, Azure, GCP, Hostinger) | ||||
| Identity/email (Google Workspace, Microsoft 365, more) | ||||
| Threat-intel providers (VirusTotal, AbuseIPDB, GreyNoise, OTX, MISP, etc.) | ||||
| Bring-your-own LLM & TI API keys | – | – | ||
| Custom / private integrations | – | – | ||
| Administration & Support | ||||
| Multi-user access | 1 | 5 | 50 | Unlimited |
| Google SSO login | ||||
| Role-based access control (RBAC) | – | Basic | Standard | Advanced |
| Enterprise SSO / advanced RBAC | – | – | – | |
| Multi-tenant management (MSSP) | – | – | – | |
| Audit logging | ||||
| Dedicated onboarding | – | – | ||
| On-premise deployment options | – | – | – | |
| Support | Community | Priority | SLA | |
Pricing FAQ