Skip to content
Pricing

A verdict arrives explained, with the evidence attached, so nobody spends an afternoon pivoting across five tabs on every single IOC.

Plans

Pick your segment; the meter follows.

Every plan shares the same API surface and signal taxonomy; no feature gating. Self-service plans differ in monthly requests, users and support. MSSP and Enterprise are sized by unique domains and quoted to contract.

Pooled unique domains per tenant, partner terms, quoted to contract.

MSSP

Quoted by Unique Domain

Multi-tenant scoring with per-customer audit logs.

  • One pool across your tenants, not one plan per tenant
  • Within a single tenant, repeat lookups are free and re-scored on every call
  • Org-level master key with ring-fenced data per tenant
Plan details and how the pool works
Three tenants, one pool: each tenant's unique domains count once a month and the pool is their sum.
  • Each tenant's unique domains count once a calendar month; the pool is the sum of those counts
  • Replay and drift tracking cost nothing extra: a domain already in the pool stays counted once
  • X-Customer-Id on the master key separates data, audit logs and exports per tenant
  • Tenant-scoped quotas with usage alerts, so one tenant cannot spend another's headroom
  • Partner terms and the live pool sit in the partner portal
Metered by
Quoted by unique domain
Throughput
Contract-scoped
AI assistant
Included; token pool quoted separately
SLA
Contact sales
Support
4h response

Pricing depends on tenant count, region, and integration scope. We size and quote together.

How the meters work

Two meters, all in plain sight.

Self-service meters requests

1 request = 1 verdict

1 request to POST /verdict = 1 verdict; the bulk endpoint counts each IOC in the batch (500 = 500). Repeats count again. No bulk discount.

MeterPer request

MSSP & Enterprise meter unique domains

1 domain = 1 count / month

A domain counts once per calendar month however often your stack asks. Repeats are free and re-scored against the latest evidence; replay and drift tracking cost nothing extra.

MeterPer unique domain
Built for MSSP / MDR

Multi-tenant scoring, standardized decision language.

An MSSP's biggest operational risk is inconsistency. Same IOC, same verdict across customers via deterministic core; explainable Q&A drops analyst onboarding cost; per-tenant logs for audit. Quota is one pool: each tenant's unique domains count once a month, and the pool is the sum of those per-tenant counts.

Learning curve drops

Signal → evidence → Q&A arrives ready; analysts learn to apply decisions, not 'read the data'.

OnboardingEvidence arrives explained

Decision standardized

Same input → same verdict, system-bound not person-bound. Tenant A and Tenant B share the same 'high risk' threshold.

ConsistencySame input, same verdict

Audit-ready by default

Master key + X-Customer-Id + per-tenant log + per-tenant report; MSSP can show customers the evidence chain directly.

AuditPer-tenant evidence chain
Frequently asked

Two meters, one API: the mechanics.

What counts as one request on a self-service plan?Metering

1 IOC sent to POST /verdict = 1 request. The bulk endpoint counts each IOC inside the batch (bulk of 500 = 500 requests). Same rate as a single request; no bulk discount. MSSP and Enterprise do not meter requests at all: they are quoted by unique domain.

What does "quoted by unique domain" mean?Metering

MSSP and Enterprise contracts count distinct domains per calendar month, not requests. If your SIEM, SOAR and EDR ask about the same domain a hundred times it counts once, and every repeat is re-scored free. No list price: we size the band on a one-time full-traffic snapshot.

How is the MSSP pool counted across tenants?MSSP pool

Per tenant, then summed. Each tenant has its own monthly unique-domain window and the pool is the total of those counts. There is no org-wide dedup, because both value (per-tenant Blind Spot Analysis) and billing live at the tenant level.

What happens when I exceed my quota or band?Quota

Self-service: nothing is billed on top, there is no overage rate. Usage alerts fire well before the ceiling, and the Free plan stops at its cap and resets on the 1st (UTC). MSSP and Enterprise: the unique-domain band is an annual commitment, trued up at renewal, never auto-invoiced.

Can I run a continuous feed or my DNS / proxy logs through the API?Fair use

Not on a self-service plan. Feed triage and log-pipeline enrichment run into millions of requests a month, past the Business ceiling and outside fair use. That workload is Enterprise scope, quoted by unique domain: one domain counts once a month however many log lines mention it.

Do duplicate queries cost me twice?Metering

On self-service plans, yes: every request that reaches our server counts, even for the same IOC (the client SDK has a session cache). MSSP and Enterprise meter unique domains instead: one domain counts once per calendar month, and each repeat is re-scored at no extra cost.

Why usage-based, not per-seat?Pricing model

Per-seat punishes scale. SOC analysts run thousands of queries; usage-based pricing ties cost to what you actually do. Self-service meters requests, MSSP and Enterprise meter unique domains; neither meters headcount, and API keys or automation accounts never cost a seat.

Is there an annual plan or an annual discount?Billing

Self-service billing is monthly only, with no prepay tier and no annual lock-in. MSSP and Enterprise contracts are annual unique-domain bands, where multi-year or committed volume terms are negotiated with sales.

Can I upgrade or downgrade mid-cycle?Billing

Self-service: yes, from the portal. Upgrade is prorated and you start using the new quota immediately; downgrade applies at the next billing cycle. The Free plan stays available even if you cancel a paid subscription. Contract bands move at renewal, or earlier by agreement.

Self-service plans are billed monthly in USD, excluding VAT, with no overage line. MSSP and Enterprise are quoted by unique domain; volume bands and terms are set in your contract.

First verdict in 5 minutes.

Get an API key, send your first IOC, plug the response into SOAR/SIEM. The free monthly quota requires no credit card. Running an MSSP or a large environment? Talk to sales for a unique-domain quote.

Talk to sales (MSSP / Enterprise)