Report an Incident Become a Partner Careers Contact
Book a Demo
Core · Complete · Command

Three packages.
One operation behind all of them.

What you pay depends on the size and shape of what you are asking us to defend. This page is the honest version of how that works: what sits in each package, what moves the number, and what you get regardless of which one you land on.

Packages · managed serviceScoped
01Coreper incident
02Completeper user
03Commandper user
ALL24/7 manned SOC, senior sign-offincluded
SCOPEAgreed in writing before anything is pricedalways
Why there is no number on this page

We will not quote you
before we know what you run.

A rate card would be easier to publish and worse to buy from. The work scales with the estate, so a number set before anyone has looked at yours is either padded to cover the worst case or set low and corrected later.

Neither of those is a good way to start a relationship that involves us telling you bad news at three in the morning. So the scope gets agreed first, in writing, and the price follows from it.

What we can do in public is be specific about the things that move it. Everything below is a real variable rather than a hedge, and you can work out roughly where you sit before you ever speak to us.

What actually moves the number

Six things, in roughly the order they matter.

  1. 01

    Which package

    Core, Complete or Command. The biggest single factor, because it decides how much of the agent roster is on duty for you, whether threat hunting runs continuously or not at all, and — see below — whether you are metered per incident or per user.

  2. 02

    Per incident, or per user

    Core is metered per incident. Complete and Command are metered per user, so the bill moves with headcount rather than with how busy a month was. It is the difference between a variable line and a fixed one on your budget.

  3. 03

    How much of it reaches L2

    On Core, triage is what you are billed for and L2 investigation is charged on top when an incident needs a deeper look. So the number follows how many incidents genuinely warrant investigation, not how many arrive. On Complete and Command it does not apply — everything is inside the per-user price.

  4. 04

    The size and shape of your estate

    Coverage scales with what there is to cover. That is the difference between this and hiring: cost moves with the estate rather than in whole headcount.

  5. 05

    Your threat hunting allocation

    Hunting is not included on Core, runs continuously on Complete, and Command carries an extended allocation. Additional allocation can be bought on top of Complete or Command. It is the clearest step between the tiers.

  6. 06

    Human-led incident response

    On Complete it is available on time and materials. On Command a human response team is on standby with priority escalation, which is a standing cost rather than an event one.

The three packages

Where most people
end up landing.

The short version. The full comparison, agent by agent, is on the managed SOC page.

Package 01

Core

Per incidentYou pay for what your estate actually produces.

For teams that need alert volume handled properly, with the option to grow into a full SOC.

The two front-line agents and nothing else — L1 triage, and L2 investigation when an incident needs it. The rest of the roster starts at Complete.

Most popular Package 02

Complete

Per userYour bill moves with headcount, never with incident volume.

A full SOC. Every agent on duty, with threat hunting running continuously as part of the service.

The whole roster on duty, and threat hunting running continuously rather than when somebody has time.

Package 03

Command

Per userYour bill moves with headcount, never with incident volume.

For regulated and high-risk organisations that need deeper hunting and responders already on standby.

Everything in Complete, plus an extended hunting allocation and human responders already on standby.

See every agent, package by package

How each package is metered

One is priced per incident.
Two are priced per user.

There is no figure on this page, but there is no reason to be vague about the unit. Which one applies to you is decided by the package, and each is the honest unit for what that package does.

Per incident

Core

Core is two agents: L1 triage, and L2 investigation when an incident needs a deeper look. Triage is what you are billed for and investigation is charged on top, and our SOC is on hand around the clock to run both and to set the triage procedures up with you. It handles what your estate produces; it is not trying to change how much it produces.

The agents that drive volume down over a year — detection engineering, continuous hunting, automated containment — are not in the base package. So the count is a fair reading of your estate rather than a reading of how hard we have worked on it, and paying per incident means you pay for what actually happened. Nothing is charged for a quiet month.

Per user

CompleteCommand

Complete and Command are a full SOC, and a full SOC is measured by whether the number of incidents goes DOWN. Detection engineering tunes the noise out, hunting finds what did not alert, and the Response Agent contains what it can.

Meter that per incident and the unit you are billed on is the exact thing the service exists to reduce — which makes the supplier best paid in the months you are worst protected. Per user takes the count out of the commercial relationship completely. Your bill moves when your headcount moves and at no other time, so the number is known a year ahead and nobody on either side is watching the incident count for the wrong reason.

Neither is the better deal. They are the right unit for two different services, and the package you need decides which one you are on.

Regardless of tier

What you get
on every package.

None of this is an upgrade. It is the floor, and it is the same floor on Core as on Command.

24/7 manned SOC

Agents run continuously and our SOC is staffed by security professionals around the clock, every day of the year.

Mean Time to Verdict

We measure the whole chain — signal received to signed-off outcome — not just how fast a machine acknowledged an alert.

Senior analyst sign-off

Every customer-facing decision is reviewed and approved by an experienced human analyst before it reaches you.

A verdict, not a longer alert

Every incident closes with a structured outcome: malicious or benign, scope, root cause, impact, a confidence score and a recommended action.

Tenant isolation

Your data stays in your tenant. No cross-customer learning, enforced architecturally.

Named contacts

A named team you can reach, with defined escalation paths to human experts.

You set the autonomy

Per agent: fully autonomous, held for your approval, or autonomous above a threshold you set. High-impact containment is held for a human either way.

Your estate connected

Microsoft Sentinel is the only hard requirement. Connectors, parsers, analytical rules and playbooks for what you already run are built during onboarding, as part of the service.

How scoping works

Nothing is priced
before the scope is agreed.

The sequence is deliberately dull, and it is the same for everyone.

  1. 01

    A conversation about what you run

    What is in the estate, what is already monitored, what worries you about it, and where your team currently spends its week.

  2. 02

    Working out what it takes

    Which licences you need, which package fits, whether human-led incident response belongs in it, and whether you want more threat hunting than the package carries. That becomes the scope, in writing, and the price follows from it.

  3. 03

    A proof of concept, or a demo

    A POC runs against your own estate where the success criteria are agreed up front and there is intent to buy behind it. Where that is not the right step yet, we demo the platform against your own scenarios instead.

  4. 04

    Onboarding

    Either we take over your existing Microsoft Sentinel or we deploy a new instance with our base rule set. Connectors, parsers and analytical rules for what you already run are built here, as part of the service rather than as a change request. Anything bespoke is quoted as development first.

Nothing is deployed and nothing is priced before that scope is agreed in writing.

Questions

Pricing, answered.

Why is there no price on this page?

Because the work scales with the estate, and a number set before anyone has looked at yours is either padded for the worst case or set low and corrected later. The scope is agreed in writing first and the price follows from it. What moves the number is listed above.

What is the difference between the three packages?

Core is the two front-line agents and nothing else: L1 triage, with L2 investigation charged on top when an incident needs it. Complete puts the whole roster on duty with threat hunting running continuously. Command adds an extended hunting allocation and human responders on standby. The full agent-by-agent comparison is on the managed SOC page.

Is it priced per user or per incident?

Both, depending on the package. Core is metered per incident, because it handles what your estate produces rather than working to reduce it. Complete and Command are metered per user, because those packages include the detection engineering, hunting and automated containment that bring incident volume down over a year — and billing per incident would mean charging you most in the months you were least protected. On Complete and Command your bill moves with headcount and with nothing else.

Can we start on Core and move up?

Yes, and most do. Moving up is a change of package rather than a rebuild: the same platform is already running against your estate, and what changes is how much of the agent roster is on duty for you. Core is the two front-line agents; Complete puts the whole roster on, adds continuous threat hunting, and moves you to a per-user price.

What is included no matter which package we are on?

A 24/7 manned SOC, senior analyst sign-off on every customer-facing decision, tenant isolation, named contacts, the autonomy dial on whichever agents are on duty for you, and the connectors and tooling your estate needs. None of that is an upgrade. Which agents are on duty is what the package decides.

Is incident response included?

Automated containment through the Response Agent is included from Complete, inside limits you set. Human-led incident response is on time and materials on Complete, and on Command a human response team is on standby with priority escalation.

Are the connectors and tooling extra?

Connectors, parsers, analytical rules and playbooks for what you already run are built during onboarding as part of the managed service. They are not a separate data-engineering engagement and not a change request. Building you something new is a different thing: a custom tool, an integration into an internal system of your own, or a program written for your organisation is development work and may carry a development cost, scoped and quoted before anything starts.

Where to start

Tell us what you run
and we will scope it properly.

An hour with a SOC analyst, a demo against your own scenarios, and a scope in writing before anything is priced. No rate card, and no number invented to fill a slide.