Compare plans
What each tier includes
The full feature-by-feature breakdown. Every Pro domain includes everything in Basic, and every Command domain includes everything in Pro.
| Features |
Basic$35 / mo · per domain |
Pro$55 / mo · per domain |
Command$79 / mo · per domain |
| External Scanning & Monitoring |
| External security & attack-surface scanning | | | |
| Uptime, DNS & security-score monitoringScore trend + projection | | | |
| Brand-lookalike & typosquat monitoring | | | |
| Deep Scan — 4,178 CVE checksKEV/EPSS-ranked | | | |
| Open-port & shadow-IT monitoring | | | |
| Subdomain discovery & attack-surface growth alerts | | | |
| Certificate lifecycle monitoring | | | |
| Internal Agent & Endpoint |
| Internal agent (Windows / Linux / macOS) + Universal Connector | | | |
| Container & IaC scanningTerraform / CloudFormation + container image CVEs | | | |
| Cloud & SaaS Posture |
| Cloud posture — AWS, Azure & Google Cloud | | | |
| Microsoft 365 / Entra & Google Workspace posture | | | |
| SaaS security posture (SSPM) | | | |
| OAuth-grant, shadow-SaaS & shadow-AI visibility | | | |
| Threat Detection & Response |
| Threat intelligenceIOC matching, retro-hunt & adversary profiling | | | |
| Public-repo secret scanning | | | |
| Detection-rule library & threat-hunt queries | | | |
| Canary tokens & decoys | | | |
| SOC triage queue, case management & on-call escalation | | | |
| Attack-path analysis | | | |
| SIEM export | | | |
| Incident Response & Offensive Security |
| Incident war room | | | |
| Tabletop exercises & lessons-learned register | | | |
| Incident-response plan builder | | | |
| IR retainer & breach-notification engine | | | |
| Penetration-test & OSINT reconnaissance reports | | | |
| Safe exploitability validation & re-test scheduling | | | |
| Breach & attack simulation + authorized password-spray | | | |
| Identity & Access |
| Access reviews, offboarding verification & non-human identities | | | |
| Conditional-access simulator & JIT-access gap analysis | | | |
| Password-manager posture | | | |
| Data Governance & Crypto |
| Sensitivity-label, retention & ROPA posture | | | |
| External-sharing map & insider-risk cases | | | |
| Secrets-sprawl & private-PKI discovery | | | |
| Supply-chain trust & post-quantum readiness | | | |
| Human Risk |
| Phishing, vishing & smishing simulations | | | |
| Awareness training, tracking & just-in-time coaching | | | |
| Human risk scoring | | | |
| Compliance & Evidence |
| Compliance mapping — 10 frameworks (read-only) | | | |
| Auto-attestation integrationsLMS / HRIS / IdP / backup | | | |
| Client onboarding security baseline | | | |
| Questionnaire auto-answer & PCI-DSS SAQ workflow | | | |
| Website privacy & tracker scan | | | |
| Vendor risk auto-assessment, third-party scans & Nth-party mapping | | | |
| Audit-ready compliance report PDFs — 10 frameworks | | | |
| Evidence Vault (1-year retention) | | | |
| M&A cyber-diligence report | | | |
| Reporting & Client Deliverables |
| Patch-posture, attack-surface & executive-digest reports | | | |
| Quarterly Business Review generator | | | |
| vCISO report & AI risk register | | | |
| Board pack PDF | | | |
| Statement-of-work generator & ROI dashboard | | | |
| vCISO & Governance |
| Security maturity model & budget planner | | | |
| vCISO service-level tracking & security committee | | | |
| Zero-trust & segmentation readiness | | | |
| OT/ICS, vendor & physical-security advisories | | | |
| Peer & portfolio benchmarking | | | |
| Client SLA tracking & escalations | | | |
| AI & Automation |
| Help & docs AI assistant | | | |
| AI Remediation Playbook | | | |
| AI-usage policy & AI app-security assessments | | | |
| AI-agent inventory & deepfake/BEC readiness | | | |
| Active Defense — approval-gated remediation | | | |
| Client Portal & White-Label |
| Client portal | | | |
| White-label brandingYour logo on portals + PDFs | | | |
| Client security bot & request portal | | | |
| Security gamification & client-success signals | | | |
| Integrations & Platform |
| PSA & RMM integrationsHaloPSA · Autotask · Syncro · Atera · NinjaOne | | | |
| REST API, write API & developer portal | | | |
| Webhooks, automation connector, template marketplace & detection exchange | | | |
| Team seats (Admin / Technician / Analyst) | | | |
| Enterprise SSO / SCIM | | | |
| Priority support | | | |
Tiers are set per domain — mix Basic, Pro and Command across your portfolio and each domain unlocks its own tier's features.