24/7/365 SOC — average triage time 4m 51s

Pricing

Published prices. No log-volume surprises.

Security spend that changes every month is impossible to defend to a board. We price per protected endpoint, include the licensing, and never charge extra because you had a bad week.

Monthly Annual Save 17% on annual

Signal

Continuous monitoring for organisations that have IT covered but no security eyes after hours.

$22 / endpoint / month

Billed monthly · 50-endpoint minimum · 60-day exit

Core

  • 24/7/365 SOC monitoring and triage
  • EDR licensing, deployment, and tuning included
  • Identity and Microsoft 365 / Google Workspace telemetry
  • 30-minute critical containment SLA
  • 90-day hot log retention, 1-year archive
  • Monthly metrics report
  • Compliance evidence library
  • Penetration testing

Sovereign

For organisations under examination pressure, defense contracts, or a board that wants a named security officer.

$71 / endpoint / month

Billed monthly · 150-endpoint minimum · 60-day exit

Everything in Sentinel, plus

  • Named vCISO with board and audit-committee attendance
  • Incident-response retainer with 60-minute engagement SLA
  • Unlimited frameworks in the evidence library
  • Two penetration tests per year, internal and external
  • Annual red-team or purple-team exercise
  • OT / ICS and medical-device segment monitoring
  • Examiner, auditor, and carrier support hours
  • Dedicated Slack / Teams channel with the analyst pod

Over 2,500 endpoints, multi-entity, or a holding company?

Enterprise agreements move to a committed-volume model with per-subsidiary tenancy, custom SLAs, dedicated analyst pods, and MSA redlines. Public-sector and cooperative purchasing vehicles are available.

Talk to us about enterprise

Line by line

Full plan comparison.

Everything below is in the standard agreement. If something you need is missing, it becomes an add-on with a published price rather than a mystery line item.

Feature comparison of the Signal, Sentinel, and Sovereign plans
Capability Signal Sentinel Sovereign
Detection & response
SOC coverage24/7/36524/7/365
Critical containment SLA30 minutes15 minutes
Endpoint EDR/XDR (licence included)
Identity & email telemetry
Cloud posture & workload telemetry
Network & firewall telemetry
OT / ICS & medical-device segments
Automated containment actionsIsolate hostFull action set
Threat huntingWeekly
Offensive testing
External penetration testAdd-on2 / year
Internal penetration testAdd-onIncluded
Web / API application testingAdd-on1 app included
Red / purple team exerciseAnnual
Free retest of findings (90 days)
Compliance & evidence
Continuous evidence libraryUnlimited
Gap assessment & control mappingAdd-onSemi-annual
Auditor / examiner support hours60 / year
Policy set authoring & maintenance
Cyber-insurance questionnaire support
Programme & reporting
Metrics reportMonthlyMonthly
Business reviewAnnualMonthly
Named vCISODedicated
Board / audit-committee attendance
Risk register maintenance
Security-awareness & phishing programmeAdd-on
Data, support & commercial
Hot log retention90 days1 year
Archive retention1 year7 years
Incident-response retainerAdd-onIncluded
Support channelPortal + phoneDedicated pod channel
Minimum endpoints50150
Contract term12 months12 months
Exit notice60 days60 days

Servers count as one endpoint. Cloud workloads are counted at 1:1 and user identities are included at up to 1.5× the endpoint count at no charge. Full definitions live in the service description attached to every quote.

Add-on services

Priced work, not open-ended consulting.

Every engagement below is fixed-fee against a written scope. Sentinel and Sovereign clients receive a 15% programme discount on all add-ons.

External penetration test

Perimeter, VPN, and public application testing with an attack narrative, remediation plan, and attestation letter. Free retest within 90 days.

from $9,500per engagement

Internal / assumed-breach test

What an attacker reaches after one workstation falls: lateral movement, privilege escalation, and domain-dominance paths.

from $12,800per engagement

Web / API application test

Authenticated OWASP-aligned testing with business-logic abuse cases, per application and per user role.

from $11,400per application

Incident-response retainer

60-minute engagement SLA, pre-signed contracts and NDAs, named forensic lead. Unused hours convert to proactive work at renewal.

from $1,450per month

CMMC Level 2 readiness

Scoping, SSP and POA&M authoring, enclave design, and pre-assessment against all 110 practices for defense suppliers.

from $18,000fixed fee

SOC 2 Type II programme

Readiness, control implementation, evidence automation, and auditor liaison through your observation window.

from $24,000first year

Executive tabletop exercise

A facilitated ransomware or wire-fraud scenario for leadership, with a written after-action report and plan revisions.

$4,800per exercise

Microsoft 365 / Entra hardening

Conditional access rebuild, legacy-auth removal, privileged-role review, and mailbox-rule abuse detection.

from $6,500fixed fee

Always included

The things other providers meter.

Security bills that spike during an incident punish you for the exact moment you need help most. Ours do not move.

  • Unlimited log ingestion. No per-gigabyte charge, ever. Send us everything.
  • Unlimited incidents. A month with forty escalations costs the same as a month with two.
  • Onboarding and tuning. Deployment, rule tuning, and the first 90 days of false-positive suppression are part of the price.
  • Licensing. EDR and log-platform licences are bundled unless you prefer to keep your own.
  • Data portability. Export your logs, detections, and configuration at any time in open formats.
  • Price protection. Rates are locked for the initial term and capped at CPI thereafter.

Worked example

240-endpoint credit union, Sentinel annual

Endpoints
240
Identities included
360
Rate
$34 / mo
Monthly
$8,160
Annual
$97,920
Pen test
Included

Replaces a typical stack of EDR licensing, a SIEM contract, an annual test, and roughly 1.5 security FTEs — before counting the after-hours coverage that headcount cannot provide.

Get a quote for your endpoint count

Pricing FAQ

Before you ask procurement.

Any device running our sensor: workstations, laptops, physical and virtual servers, and cloud VM instances. Mobile devices under MDM, network appliances, and user identities are not billed. Identities are included at up to 1.5 per endpoint, which covers nearly every organisation without adjustment.

No, for standard environments on annual terms. Environments requiring bespoke integration work — legacy SIEM migration, OT network taps, or more than five cloud tenants — carry a one-time scoped fee quoted before signature. It appears on the quote or it does not exist.

Yes, and it lowers your rate. We operate CrowdStrike, SentinelOne, Microsoft Defender for Endpoint, and several SIEM platforms under a bring-your-own-licence discount of $6–$11 per endpoint per month depending on the product. We will tell you honestly which option is cheaper for you.

We true up quarterly, and only upward beyond a 10% band — seasonal fluctuation does not generate an invoice. If you shrink permanently, tell us and we reduce the commitment at the next quarterly boundary rather than at renewal.

Yes. Registered 501(c)(3) organisations, K-12 districts, and municipalities under 25,000 residents receive 15% off list. We also hold cooperative purchasing agreements that let many public bodies buy without running a separate solicitation — ask and we will send the vehicle details.

Containment, investigation, and reporting for incidents detected by our monitoring are included in every plan — there is no per-incident fee. Deep forensic work outside the monitored estate (imaging a device we do not cover, expert testimony, or a full legal-hold exercise) draws on an IR retainer or is billed at $385 per hour with a written estimate first.

Next step

See what an attacker sees — in 30 minutes, at no cost.

We run passive reconnaissance against your public perimeter, map exposed services and leaked credentials, and walk your team through the findings. No agents to install, no obligation.

  • Findings report delivered in 3 business days
  • No sales engineer required to read it
  • Yours to keep, whether or not you hire us