Choose the protection level that fits your organization. No hidden fees.
Up to 25 endpoints — 24/7 monitoring for small offices
Up to 10 log sources — perfect for small businesses & teams
For cloud-first or regulated organizations needing deeper coverage
Up to 50 log sources — large organizations & enterprises
Growing past 25 endpoints, or need custom detections, Slack alerts, or more log sources? That's Essential.
Extend your MDR coverage with additional services
Retain logs beyond standard 90 days for compliance or forensics.
+$500/month per TB
Continuous scanning, prioritization, and remediation tracking.
+$15/endpoint/month
Guided incident response simulations for your team.
$2,500/session
Custom reports aligned to SOC 2, HIPAA, PCI-DSS, or NIST.
+$1,000/month
Monthly campaigns to test and train your users.
+$500/month
Dedicated Slack channel and priority response for all tiers.
+$750/month
Core monitors a fixed set of sources — endpoints, email, and firewall — with our standard detection library, fully automated reporting, and email support. Essential adds up to 10 log sources of any type, tuned detections, and a two-week guided onboarding. If you have servers, an EHR system, or more than 25 endpoints, you want Essential.
Yes. Our AI platform triages every alert at machine speed; anything that needs action is reviewed and escalated by our analysts, 24/7.
Absolutely. We integrate seamlessly with your current IT provider. Your MSP continues to handle patching, endpoint management, and help desk, while we focus on threat detection, investigation, and response. We coordinate through shared ticketing and clear communication channels.
We strongly recommend endpoint detection and response (EDR), but we're platform-agnostic. We support Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne, and others. If you don't have EDR, we can help you choose and deploy the right solution.
We use industry-standard SIEM platforms including Splunk and modern data lake architectures. You don't need to manage or license these tools—they're included in our service. We handle all configuration, tuning, and maintenance.
Core clients are typically up and running in 1-2 days. On Essential and above, most clients achieve initial visibility within week 1, and we deliver your first tuned threat report and 24/7 monitoring by week 2. Complex environments may take 3-4 weeks for full coverage, but basic protection starts immediately.
Yes. All tiers include first-response and containment during an active incident. For deep forensic investigation, malware analysis, or extended remediation, we offer DFIR services that are scoped separately based on complexity.
Prices assume typical SMB telemetry volumes. If you exceed the tier limits, we'll work with you on custom pricing. Log sources include firewalls, domain controllers, servers, cloud tenants (M365, Google), EHR systems, VPN concentrators, and similar devices. Core is the exception — it isn't counted in log sources. It covers a fixed menu instead: one EDR tenant, Microsoft 365 or Google Workspace, and one firewall.
We offer both annual contracts (with discounts) and month-to-month agreements. Annual contracts receive 15% savings and priority onboarding. Month-to-month requires 30-day notice for cancellation.
Our 24/7 SOC operates globally. We support organizations in North America, Europe, and APAC. For data residency requirements (GDPR, etc.), we can accommodate regional log storage and comply with local regulations.
Book a free consultation to discuss your security needs and find the right tier for your organization.
Book a Free Consultation