Transparent pricing

Pick the level that fits

Four tiers. No setup fees. No per-seat overage. Cancel anytime. Annual prepay saves two months on Guard and Shield.

Watch

Stay informed

Free monitoring proof — we're watching.

Free

No card required

  • Monthly auto-delivered briefing
  • 3 AI explanations per month
  • Basic security score

Shield

Stay defended

Best for firms with up to ~25 employees.

$499 / month

or $4,990 / year (two months free)

  • Everything in Guard, plus:
  • Real-time email threat scanning + auto-quarantine
  • Continuous M365 monitoring (5-min cadence)
  • M365 auto-remediation
  • Vendor risk monitoring
  • Remediation tracking workflow
  • Quarterly 60-min video review
  • Beam AI copilot
  • Urgent advisory emails
  • Best-effort same-business-day response

Custom

Multi-office & 25+

For firms with multiple offices or larger headcount.

Let's talk

Quoted on scope

  • Everything in Shield
  • Multi-entity aggregation
  • Scoped compliance work (WISP, IR plan, risk assessment)
  • Incident response engagements available as add-on
  • Named operator escalation path

Side by side

What's in each tier

Every row corresponds to a real capability gate in our platform — not a marketing checkbox. If it's listed here, it's something we measurably do.

Capability Watch Guard Shield Custom
Briefings & reports
Threat briefingMonthly · autoWeekly · operator-reviewedWeekly · operator-reviewedWeekly · operator-reviewed
Monthly board-ready PDF
Quarterly external scan (19 modules)
Quarterly video review call60 min60 min
Monitoring
Microsoft 365 / Google posture syncDailyEvery 5 minutesEvery 5 minutes
M365 auto-remediation
Real-time email threat scanning
Urgent advisory emails
Dark web & vendors
Dark web findings in briefings
Plaintext credential reveal
Vendor risk monitoring
Workflow & AI
Direct operator messaging
Remediation tracking
AI explanations3 / month5 / day200 / day200 / day
Beam AI copilot
Response
Operator response windowBest effortSame business dayNamed operator
Incident response engagementsAdd-onAdd-on

Incident response (containment, forensics, recovery) is contracted separately — ad-hoc rate or per-incident retainer. We do that work; we don't bake worst-case cost into seat pricing.

Common questions

Before you sign up

  • A 60-minute call where we look at your environment together — Microsoft 365 settings, dark web exposure, basic perimeter — and tell you what's actually risky and what isn't. You get a written report within 48 hours. No card, no obligation. About a third of firms we walk through this don't need us yet — we'll tell you so.
  • Yes. Monthly plans cancel at the end of the current billing month. Annual prepay isn't refundable mid-term, but we won't auto-renew you and you keep access until the period ends.
  • No setup fee. No per-seat overage. The published monthly price is what you pay. The only thing not bundled is incident response work, which is quoted per engagement.
  • Yes — as a separately-contracted engagement, anchored by GCIH-certified experience. Available either ad-hoc (hourly) or as an annual retainer. It's intentionally not bundled into seat pricing; IR is high-variance work and bundling it would force everyone to overpay for the average year that doesn't include an incident.
  • Yes. Written Information Security Plans, incident response playbooks, tabletop exercises, and risk assessments are scoped engagements — most commonly under our Custom tier, or as standalone projects for Guard / Shield customers when they're due.
  • Guard is the briefing-and-monitoring tier — we watch your environment, pull dark web exposure, scan your perimeter quarterly, and send you a weekly operator-reviewed briefing plus a monthly board PDF. Shield adds the things that require continuous human attention: real-time email threat scanning with auto-quarantine, 5-minute M365 monitoring, auto-remediation, vendor risk, a remediation tracking workflow, the AI copilot, urgent advisory emails, and a same-business-day response window. If your inbox or M365 environment is mission-critical, Shield.
  • Ohio. We're a US-only operation — no offshore SOC, no overseas tier-one. Every briefing, every email verdict, and every operator action is performed by a person on our team.
  • We can sign a Business Associate Agreement for Shield and Custom engagements. If you handle PHI and need a BAA in place, mention that on your first call — we'll walk through the sub-processor chain with you before you sign.

Not sure which fits?

Book a free 60-minute health check

We'll look at your environment together and tell you the truth — including if you don't actually need us yet.

Book the call