Pricing

Pay for explanations, not for alerts.

The rule engine is free at every tier and never sends data anywhere. Paid tiers add stored investigations, the dashboard, more Claude explanations and support. Prices are pilot prices during 2026 and exclude VAT.

Free

0 €forever

Try it on real events, no account needed.

  • Rule engine: unlimited analyses
  • Claude explanation: 3 per day, up to 300 events each
  • Pseudonymization in the browser
  • Results stay in your browser
  • No dashboard, no history
Analyze now
Pilot pricing

Team

149 €per month, per organization

For one SOC team that wants cases, not alerts.

  • Everything in Free
  • Claude explanation: 50 per day, no size limit
  • Investigations stored, dashboard, case status
  • Incidents with verdicts per investigation
  • Up to 5 members, roles owner / analyst / viewer
  • Copy-as-report, KQL export
  • Email support, 1 business day
Create account
For service providers

MSSP

490 €per month

Many customers, one console, strict separation.

  • Everything in Team
  • Unlimited members, up to 10 customer tenants
  • Claude explanation: 200 per day across tenants
  • Per-tenant pseudonym mapping and reports
  • Priority support, 4 business hours
  • Onboarding session for your analysts
Talk to us

Self-hosted

On requestannual license

Your servers, your model, your data residency.

  • Runs on your VPS or on-prem
  • Bring your own Claude key or a local model
  • Unlimited tenants and analysts
  • Sigma rule import, custom rules
  • Support contract and updates
Talk to us

What counts as a Claude explanation?

One analysis where Claude writes the summary, weighs the evidence and proposes next steps. Rule-engine analyses never count.

Where do my logs go?

Users, devices and IP addresses are replaced in your browser before anything is sent. The pseudonymized events are stored for your tenant only (Team and above); the mapping back to real names stays inside your tenant.

Can we start without Claude?

Yes. Every tier works with the rule engine alone, and Self-hosted can run a local model instead of the Claude API.

How does the pilot work?

Create a Team account, run your own exports for two weeks, and tell us what the engine got wrong. Pilot customers keep the pilot price for twelve months.