Priced on what we discover, not on how many people look at it
Charging a security team per seat discourages exactly the collaboration you want. Plans are priced on assets under management, and two of the three include unlimited users.
- Read-only discovery, no agent required
- Full export through the API, no export fee
- Regional data residency selection
- A four-week proof of value before you commit
Surface
For a security team that needs an inventory it can trust before anything else.
- Continuous discovery across domains, cloud and APIs
- Ownership resolution and the change ledger
- Findings with evidence and remediation guidance
- Two cloud accounts, one identity provider
- Slack, Teams and webhook routing
- Technical findings export
- Assets
- Up to 5,000
- Users
- 15
- History
- 12 months
- Support
- Email, next business day
Operations
Most adoptedFor teams running an exposure programme that engineering is expected to act on.
- Everything in Surface
- Attack path modelling with choke point ranking
- Threat intelligence matched to your own surface
- Identity risk graph, human and machine
- Jira, ServiceNow and Linear with two-way SLA sync
- Executive posture brief and trend pack
- Unlimited cloud accounts and identity providers
- Assets
- Up to 40,000
- Users
- Unlimited
- History
- 36 months
- Support
- Shared channel, 4-hour response
Programme
For regulated groups running several subsidiaries under one security function.
- Everything in Operations
- Multi-tenant grouping with per-subsidiary scoping
- Data residency selection and customer-managed keys
- SAML SSO, SCIM provisioning and custom roles
- Detection & response with path-weighted alerting
- Named security architect and quarterly programme review
- Assurance pack tailored to your audit scope
- Assets
- Unlimited
- Users
- Unlimited
- History
- Configurable
- Support
- 24×7 with response commitments
Compare every plan
| Capability | Surface | Operations | Programme |
|---|---|---|---|
| Discovery | |||
| Domain, DNS and certificate discovery | |||
| Cloud account discovery | 2 accounts | Unlimited | Unlimited |
| API and shadow endpoint discovery | |||
| Endpoint and OT discovery | |||
| Ownership resolution | |||
| Analysis | |||
| Findings with evidence | |||
| Attack path modelling | |||
| Choke point ranking | |||
| Identity risk graph | |||
| Threat intelligence matching | |||
| Path-weighted detection | |||
| Operations | |||
| Ticketing integration | One-way | Two-way SLA sync | Two-way SLA sync |
| SIEM streaming | |||
| Remediation SLAs by team | |||
| Accepted risk register | |||
| Governance | |||
| SAML SSO | |||
| SCIM provisioning | |||
| Data residency selection | |||
| Customer-managed keys | |||
| Quarterly programme review | |||
Four weeks, one written readout, no obligation
Connect one cloud account, your DNS and your identity provider. We run discovery, model paths, and finish with a document that says what was found, what it would take to fix, and what we could not see.
Start a proof of value- Week 1Connect and discover
Read-only roles in one cloud account, DNS and identity. The first sweep usually completes within a day.
- Week 2Resolve ownership
A workshop per business unit. Most teams confirm 60% of owners in a single session.
- Week 3Model paths
Crown jewels are labelled, paths are computed, and choke points are ranked with your platform leads.
- Week 4Read out
A written document, not a slide deck. Findings, paths, choke points, effort estimates and our blind spots.
Asked on nearly every procurement call
One asset is one discovered entity: a hostname, a cloud resource, an API route group, an identity, an endpoint or a third-party service. Sub-resources of a counted asset are free. Assets that have been decommissioned stop counting the day they stop resolving.
Nothing breaks and nothing is hidden. You keep working, and the overage appears on the next invoice at the same per-asset rate as your plan. If discovery finds a large estate you did not expect, tell us and we will re-scope rather than bill a surprise.
No. Discovery and posture evaluation run on read-only roles. Write access is only ever requested for optional remediation actions, and those are off by default and scoped per action.
Yes. A four-week proof of value connects one cloud account, your DNS and your identity provider, and finishes with a written readout of what was found and what it would take to fix. There is no obligation at the end of it.
No. Plans are priced on assets under management. Operations and Programme include unlimited users, because charging a security team per seat discourages exactly the collaboration you want.
Surface and Operations are annual with monthly billing available at a 20% premium. Programme agreements are annual or multi-year. All plans include a 30-day notice period for scope reduction at renewal.
Not sure which plan fits?
Tell us roughly how many cloud accounts and domains you run and we will size it honestly, including telling you when the smaller plan is enough.
Illustrative product data. Nothing on this site performs a live scan.