Priced per monitored domain
One billing unit, stated up front: a monitored domain. Your own domains and your vendors' domains count the same way, so the number you budget against is a number you already know. Final figures depend on volume and contract length — the demo call ends with a written quote.
Essentials
For a single organisation that wants to see its own external attack surface, continuously.
- —All 12 OSINT modules on your own domain
- —Company Risk Score with the four weighted segments
- —Findings management (Open → Resolved → Accepted Risk)
- —Monthly re-scan cadence
- —Email support
Professional
For security teams that also carry third-party risk and need DORA/NIS2 evidence.
- —Everything in Essentials
- —Supply chain scoring for vendor domains
- —Conversational threat graph (actors, MITRE ATT&CK, CISA KEV)
- —DORA & NIS2 evidence exports
- —Continuous re-scan cadence and change alerts
- —Named contact and onboarding session
Enterprise
For groups, MSSPs and regulated entities running many domains under one roof.
- —Everything in Professional
- —Multi-tenant portfolio view and role-based access
- —SIEM, ticketing and webhook integrations
- —REST API access
- —Analyst-reviewed reporting and dispute SLA
- —Custom data retention and contractual terms
What counts as a monitored domain
A monitored domain is one registered apex domain kept under continuous analysis. Every subdomain, IP, certificate and service discovered under it is included — you are never charged for the size of your own attack surface.
Vendor domains tracked for supply chain scoring are counted as monitored domains on the same rate card. There is no per-user, per-seat or per-finding charge, and no separate fee for the threat graph chat within your plan.