Pricing

Plans built around how a SOC actually buys.

Sized by investigation volume — not seats, not alert noise. Every plan includes read-only defaults, source-linked evidence, and a kill switch.

Team SOC
For internal teams running first-line triage.
$499
/mo starting
  • Investigation volume
    ~50K alerts/mo
  • Integration depth
    3 sources
  • Approval controls
    Single-analyst
  • Reporting
    Per-case + brief
Most popular
Growth SOC
For scaling teams correlating across the stack.
$1,499
/mo starting
  • Investigation volume
    ~500K alerts/mo
  • Integration depth
    10 sources
  • Approval controls
    Role-based + 2-person
  • Reporting
    Brief + customer notice
MSSP Operations
For multi-tenant providers serving many clients.
$2,999
/mo starting · per-tenant tiers
  • Investigation volume
    Per-tenant scale
  • Integration depth
    Per-client inventory
  • Approval controls
    Per-tenant policy
  • Reporting
    Branded client reports
Enterprise
Regulated, large-scale, dedicated security.
Custom
region-pinned available
  • Investigation volume
    Custom + region-pinned
  • Integration depth
    Unlimited + SDK
  • Approval controls
    Hardware-key bound
  • Reporting
    Regulator-grade pack
Included in every plan
Read-only by default
Source-linked evidence
Audit trail + export
Kill switch

Commercial terms may vary by alert volume, integration scope, retention requirements, support level, and onboarding requirements.

Custom volume?

Custom volume, region-pinned, or MSSP scale?

A SOCPilot engineer will scope the right plan for your environment in one call.

Talk to sales

Get a tailored quote.

Contact sales
Tell us about your team and we'll route you to the right person.
We respond within one business day. No newsletter spam.