Priced per endpoint. Nothing hidden.
Monitoring, response and reporting included in every plan. Volume discounts from 1,000 endpoints.
Essentials
24/7 eyes on every endpoint.
- 24/7 monitoring & triage
- EDR sensor included
- Monthly posture report
- P1 acknowledge in 15 min
Managed XDR
Endpoint, cloud and identity, one pod.
- Everything in Essentials
- Cloud + identity telemetry
- Active response & isolation
- Weekly threat hunting
- P1 acknowledge in 5 min
Enterprise SOC
A dedicated analyst pod.
- Everything in Managed XDR
- Named analysts & custom detections
- 40 h incident-response retainer
- On-site within 4 hours
- Quarterly purple-team exercise
What’s in each plan.
| Compare plans | Essentials | Managed XDR | Enterprise SOC |
|---|---|---|---|
| 24/7 monitoring & triage | ✓ | ✓ | ✓ |
| P1 acknowledge | 15 min | 5 min | 5 min |
| Cloud & identity telemetry | — | ✓ | ✓ |
| Active response & isolation | — | ✓ | ✓ |
| Threat hunting | — | Weekly | Continuous |
| IR retainer hours | — | 8 h | 40 h |
| Named analysts | — | — | ✓ |
| On-site response | — | 24 h | 4 h |
Billing and contracts.
Most customers are fully onboarded in 5 to 10 business days. Our sensor deploys through your existing device management, and we tune detections to your environment during the first two weeks.
No. We extend it. Your team keeps control and approvals; we cover nights, weekends and the 24/7 triage load so your people can focus on projects.
A named incident commander joins a bridge within your SLA, contains the threat with pre-approved actions, and keeps stakeholders updated on a fixed cadence until recovery.
Telemetry stays in the region you choose (EU, US or APAC), is encrypted at rest and in transit, and is never shared or used to train third-party models.
Yes. We integrate with the major EDR, cloud, identity and ticketing platforms, so you keep the investments you have already made.
Need a custom quote?
Multi-entity groups, MSPs and public sector get tailored pricing.